AppOptions Class
Configuration options for the Teams App.
Constructor
AppOptions()
Attributes
api_client_settings
API client settings used for overriding.
api_client_settings: ApiClientSettings | None
application_id_uri
Application ID URI from the Azure portal. Used for user authentication. Matches webApplicationInfo.resource in the app manifest.
application_id_uri: str | None
client
HTTP client or client options used to make API requests. Accepts a Client instance or ClientOptions. The app always injects its own User-Agent header.
client: Client | ClientOptions | None
client_id
The client ID of the app registration.
client_id: str | None
client_secret
The client secret. If provided with client_id, uses ClientCredentials auth.
client_secret: str | None
cloud
Cloud environment for sovereign cloud support. Accepts a CloudEnvironment instance or uses CLOUD environment variable. Valid env var values: "Public", "USGov", "USGovDoD", "China". Defaults to PUBLIC (commercial cloud).
cloud: CloudEnvironment | None
dangerously_allow_unauthenticated_requests
Whether to accept incoming requests without JWT validation. Defaults to the DANGEROUSLY_ALLOW_UNAUTHENTICATED_REQUESTS environment variable, or False.
dangerously_allow_unauthenticated_requests: bool | None
default_connection_name
The OAuth connection name to use for authentication. Defaults to 'graph'.
Deprecated since version Names: a single connection for the whole app, which does not generalize
past one. Register each connection with app.add_oauth_flow(name) and
hold on to the returned OAuthFlow instead. Still honoured as the
default for the deprecated ctx.sign_in / ctx.sign_out /
ctx.get_user_token surface.
default_connection_name: str | None
fetch_user_token
Whether to eagerly look up the user's OAuth token on every inbound activity.
The token is used to compute ctx.is_signed_in and ctx.user_token, and to authenticate
ctx.user_graph (which is always constructed regardless of this setting).
When left unset, this is auto-detected: enabled only when an OAuth connection is
explicitly configured via default_connection_name, so apps that never use user OAuth
do not pay for a wasted token request on every turn.
Set explicitly to True or False to override the auto-detection.
fetch_user_token: bool | None
http_server_adapter
Custom HTTP server adapter. Defaults to FastAPIAdapter if not provided.
http_server_adapter: HttpServerAdapter | None
managed_identity_client_id
The managed identity client ID for user-assigned managed identity. Set to "system" for system-assigned managed identity (triggers Federated Identity Credentials). If set to a different client ID than client_id, triggers Federated Identity Credentials with user-assigned MI. If not set or equals client_id, uses direct managed identity (no federation).
managed_identity_client_id: str | None
messaging_endpoint
URL path for the Teams messaging endpoint. Defaults to '/api/messages'.
messaging_endpoint: str | None
service_url
Base Service URL for BotBackend. Uses environment variable SERVICE_URL if not provided and defaults to https://smba.trafficmanager.net/teams
service_url: str | None
skip_auth
Deprecated. Use dangerously_allow_unauthenticated_requests instead.
skip_auth: bool | None
state
Per-turn state opt-in. Off by default (None/False).
state=True enables state on the app's shared storage (in-memory by
default). Pass a StateOptions to configure the
key prefix or a dedicated Storage backend. When enabled, handlers
read/write ctx.state.conversation and ctx.state.user; when off,
ctx.state is None.
Omitting this option leaves the decision open: registering an OAuth flow with
add_oauth_flow then enables state automatically, because connection-less
signin/verifyState and signin/failure callbacks need durable pending
attribution to reach the right flow. Pass state=False to opt out
explicitly — an explicit value is never overridden.
state: bool | StateOptions | None
telemetry
Telemetry configuration. Agent365 baggage is enabled by default; pass False to disable it.
telemetry: AppTelemetryOptions | None
tenant_id
The tenant ID. Required for single-tenant apps.
tenant_id: str | None
token
Custom token provider function. If provided with client_id (no client_secret), uses TokenCredentials.
token: Callable[[str | list[str], str | None], str | TokenProtocol | None | Awaitable[str | TokenProtocol | None]] | TokenProviderProtocol | None
plugins
plugins: List[PluginBase] | None
storage
storage: Storage[str, Any] | None