← All requests
0

Support OAuth2 (XOAUTH2) for SMTP authentication (Microsoft 365 / Exchange Online)

Openpdirksen (GitHub) · · edited

Problem Statement

Summary

Kaneo currently supports SMTP authentication only via username/password
(SMTP_USER / SMTP_PASSWORD). This makes it increasingly difficult to use
Microsoft 365 / Exchange Online as the mail provider.

Example error when sending a workspace invitation via smtp.office365.com:587:

Error sending workspace invitation email Error: Invalid login:
535 5.7.3 Authentication unsuccessful
code: 'EAUTH', responseCode: 535, command: 'AUTH LOGIN'

Proposed Solution

Kaneo already uses Nodemailer, which supports OAuth2 (XOAUTH2) for SMTP out
of the box. Exposing this via environment variables would solve the problem
without new dependencies. For example:

SMTP_AUTH_TYPE=oauth2            # default: login (current behavior)
SMTP_OAUTH_CLIENT_ID=
SMTP_OAUTH_CLIENT_SECRET=
SMTP_OAUTH_TENANT_ID=            # Microsoft Entra ID tenant
SMTP_OAUTH_REFRESH_TOKEN=        # optional, for delegated flow

For Microsoft 365, the client credentials flow (app registration with the
SMTP.SendAsApp permission plus a service principal granted access to the
mailbox) would be the most practical option for a server-side app, since no
interactive user login is required.

Alternative Solutions

An alternative would be an optional Microsoft Graph API mail transport
(/users/{id}/sendMail).

Relevant Context

Does this feature align with Kaneo's focus on simplicity?

I realize this adds configuration surface, so a minimal version might be
preferable: fully opt-in, no UI changes, and the default behavior stays
exactly as it is today.


Originally requested by @pdirksen on 2026-09-26. Original GitHub request #1806.

Issue #1806

Discussion 2

mcpistachio (GitHub)edited

@pdirksen, I've been trying to get smtp up and running too. Have you tried a High Volume Email (HVE)?

I've not connected it to Kaneo because I'm still getting errors validating the SMTP with https://smtp-test.com/ but your proposal would certainly work. The error I'm getting is saying that the AUTH PLAIN is not a recognized authentication type, but it does authenticate.

PS. HVE's can only email internally so the email addresses have to be in M365.

Original GitHub comment

Sign in to comment.

Keyboard shortcuts

Anywhere

Go to requests
gh
Go to changelog
gc
Go to notifications
gn
Next or previous page
norp
Leave a text field or close a menu
Esc
Show this list
?

Requests

Move to the next or previous request
jork
Open the selected request
oorEnter
Vote on the selected request
v
Search
/
New request
c

Request

Vote
v
Write a comment
c
Edit
e