---
title: OneDrive integration (file browser + cloud storage)
---

# OneDrive integration (file browser + cloud storage)

## What it is

### What it is

Omniscio's OneDrive integration is a **channel-adapter** that provides a sidebar file browser for Microsoft OneDrive. Users can browse, upload, create folders, rename, delete, move, copy, search, and share files directly from Omniscio. The integration uses Microsoft Graph API v1.0 with OAuth2 + PKCE authentication via the Microsoft Identity Platform consumer endpoint.

## Where to find it

The **OneDrive** entry in the sidebar once connected, and **Settings → OneDrive** to connect it in the first place.

## How it behaves

### How to use it

1. **Enable OneDrive.** Settings > **OneDrive** > toggle on `onedriveEnabled`.
2. **Enter your Microsoft Client ID.** Paste your Azure App Registration application (client) ID into the **Microsoft Client ID** field. Create one at portal.azure.com with a "Mobile and desktop" redirect URI set to `http://127.0.0.1:19520/onedrive/callback`. The client ID is encrypted at rest via `safeStorage`.
3. **Connect Microsoft account.** Click **Connect** in OneDrive settings. A browser window opens for Microsoft OAuth2 consent (Files.ReadWrite.All scope). Omniscio catches the redirect on a loopback server, encrypts the refresh token via `safeStorage`, and stores it.
4. **Browse files.** Click the OneDrive entry in the sidebar. The file browser shows folders and files with breadcrumb navigation, sorting, and pagination.
5. **File operations.** Right-click or use inline controls to upload, create folders, rename, delete, move, copy, share (creates anonymous view links), or open files in the browser.
6. **Search.** Use the search bar in the OneDrive header to search files by name.

## For agents

### How it works

Microsoft OAuth2 + PKCE lives in [/src/main/services/onedrive/onedrive-auth-service.ts](/src/main/services/onedrive/onedrive-auth-service.ts) — loopback redirect on port 19520, S256 PKCE challenge, encrypted refresh token. The Microsoft client ID is user-provided via Settings (stored as `microsoftClientId` in `AppSettings`, encrypted at rest via `ENCRYPTED_APP_SETTINGS_KEYS`). The API service is [/src/main/services/onedrive/onedrive-api-service.ts](/src/main/services/onedrive/onedrive-api-service.ts): wraps Microsoft Graph v1.0 REST endpoints with automatic 401 retry and 429 rate-limit handling. IPC handlers: [/src/main/ipc/onedrive-handlers.ts](/src/main/ipc/onedrive-handlers.ts) (17 channels, auto-discovered via glob). The channel adapter is [/src/main/services/channels/onedrive-adapter.ts](/src/main/services/channels/onedrive-adapter.ts) for sidebar/inbox integration. Frontend: Zustand store at [/src/renderer/src/stores/onedrive-store.ts](/src/renderer/src/stores/onedrive-store.ts), file browser components under [/src/renderer/src/features/onedrive/](/src/renderer/src/features/onedrive/). Settings flags: `onedriveEnabled` + `microsoftClientId` in channels settings.

## Related

### Related

- [INDEX.md](INDEX.md) — full library index
- [drive-integration.md](drive-integration.md) — Google Drive integration (similar cloud storage, different provider)

