Support OAuth2 (XOAUTH2) for SMTP authentication (Microsoft 365 / Exchange Online)
Problem Statement
Summary
Kaneo currently supports SMTP authentication only via username/password
(SMTP_USER / SMTP_PASSWORD). This makes it increasingly difficult to use
Microsoft 365 / Exchange Online as the mail provider.
Example error when sending a workspace invitation via smtp.office365.com:587:
Error sending workspace invitation email Error: Invalid login:
535 5.7.3 Authentication unsuccessful
code: 'EAUTH', responseCode: 535, command: 'AUTH LOGIN'
Proposed Solution
Kaneo already uses Nodemailer, which supports OAuth2 (XOAUTH2) for SMTP out
of the box. Exposing this via environment variables would solve the problem
without new dependencies. For example:
SMTP_AUTH_TYPE=oauth2 # default: login (current behavior)
SMTP_OAUTH_CLIENT_ID=
SMTP_OAUTH_CLIENT_SECRET=
SMTP_OAUTH_TENANT_ID= # Microsoft Entra ID tenant
SMTP_OAUTH_REFRESH_TOKEN= # optional, for delegated flow
For Microsoft 365, the client credentials flow (app registration with theSMTP.SendAsApp permission plus a service principal granted access to the
mailbox) would be the most practical option for a server-side app, since no
interactive user login is required.
Alternative Solutions
An alternative would be an optional Microsoft Graph API mail transport
(/users/{id}/sendMail).
Relevant Context
Does this feature align with Kaneo's focus on simplicity?
I realize this adds configuration surface, so a minimal version might be
preferable: fully opt-in, no UI changes, and the default behavior stays
exactly as it is today.
Originally requested by @pdirksen on 2026-09-26. Original GitHub request #1806.
@pdirksen, I've been trying to get smtp up and running too. Have you tried a High Volume Email (HVE)?
I've not connected it to Kaneo because I'm still getting errors validating the SMTP with https://smtp-test.com/ but your proposal would certainly work. The error I'm getting is saying that the AUTH PLAIN is not a recognized authentication type, but it does authenticate.
PS. HVE's can only email internally so the email addresses have to be in M365.
Original GitHub comment
I found the article this morning of Microsoft deprecating the Basic Auth for SMTP in favor of the OAUTH2.
https://techcommunity.microsoft.com/blog/exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835
Original GitHub comment