Teams Meetings
اجتماعات Teams
What this page is, and what it holds.
This page covers Teams Meetings. It carries a source warning and takes about 5 minutes to read. Open the channel to yourself first with an allowlist. An open channel means anyone can message your agent.
Set up the Microsoft Teams meeting summary pipeline with Microsoft Graph webhooks
Outcomes taken from this page, not a template.
- Understand what بوابة المراسلة is and when you need it.
- Run
hermes teams-pipeline subscribeandhermes gateway runand understand what happens next. - Read the table and take only the row that applies to you.
- Set
MSGRAPH_TENANT_IDin the right place.
Exactly as they appear in Hermes.
hermes teams-pipeline subscribehermes gateway runhermes gateway setuphermes teams-pipeline validatehermes plugins enable teams_pipelinehermes teams-pipeline maintain-subscriptions
MSGRAPH_TENANT_IDMSGRAPH_CLIENT_IDMSGRAPH_CLIENT_SECRETMSGRAPH_WEBHOOK_ENABLEDMSGRAPH_WEBHOOK_PORTMSGRAPH_WEBHOOK_CLIENT_STATEMSGRAPH_WEBHOOK_ACCEPTED_RESOURCESMSGRAPH_WEBHOOK_HOST
Jump to the part you need.
- 01What This Feature Does
- 02Prerequisites
- 03Step 1: Add Microsoft Graph Credentials
- 04Step 2: Enable the Graph Webhook Listener
- 05Step 3: Configure Teams Delivery and Pipeline Behavior
- 06Teams Delivery Modes
- 07Step 4: Start the Gateway
- 08Step 5: Create Graph Subscriptions
- 09Validation
- 10Troubleshooting
- 11Related Docs
Nothing summarised away.
The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.
Use the Teams meeting pipeline when you want Hermes to ingest Microsoft Graph meeting events, fetch transcripts first, fall back to recordings plus STT when needed, and deliver a structured summary to downstream sinks.
Prerequisites: see Microsoft Teams for the underlying bot/credential setup.
Run hermes gateway setup and pick Teams Meetings for a guided walk-through.This page focuses on setup and enablement:
- Graph credentials
- webhook listener configuration
- Teams delivery modes
- pipeline config shape
For day-2 operations, go-live checks, and the operator worksheet, use the dedicated guide: Operate the Teams Meeting Pipeline.
What This Feature Does
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes plugins enable teams_pipeline.
The pipeline:
- receives Microsoft Graph webhook events
- resolves the meeting and prefers transcript artifacts first
- falls back to recording download plus STT when no usable transcript is available
- stores durable job state and sink records locally
- can write summaries to Notion, Linear, and Microsoft Teams
Operator actions stay in the CLI (the teams-pipeline subcommand is registered by the teams_pipeline plugin — enable it via hermes plugins enable teams_pipeline or set plugins.enabled: [teams_pipeline] in config.yaml):
hermes teams-pipeline validate
hermes teams-pipeline list
hermes teams-pipeline maintain-subscriptionsPrerequisites
Explains the idea itself. Read it slowly; the later sections build on it.
Before enabling the meetings pipeline, make sure you have:
- a working Hermes install
- the existing Microsoft Teams bot setup if you want Teams outbound delivery
- Microsoft Graph application credentials with the permissions required for the meeting resources you plan to subscribe to
- a public HTTPS URL that Microsoft Graph can call for webhook delivery
ffmpeginstalled if you want recording-plus-STT fallback
Step 1: Add Microsoft Graph Credentials
Ordered, practical steps. Run one and confirm it worked before moving on.
Add Graph app-only credentials to ~/.hermes/.env:
MSGRAPH_TENANT_ID=<tenant-id>
MSGRAPH_CLIENT_ID=<client-id>
MSGRAPH_CLIENT_SECRET=<client-secret>These credentials are used by:
- the Graph client foundation
- subscription maintenance commands
- meeting resolution and artifact fetches
- Graph-based Teams outbound delivery when you do not provide a dedicated Teams access token
Step 2: Enable the Graph Webhook Listener
Ordered, practical steps. Run one and confirm it worked before moving on.
The webhook listener is a gateway platform named msgraph_webhook. At minimum, enable it and set a client state value:
MSGRAPH_WEBHOOK_ENABLED=true
MSGRAPH_WEBHOOK_PORT=8646
MSGRAPH_WEBHOOK_CLIENT_STATE=<random-shared-secret>
MSGRAPH_WEBHOOK_ACCEPTED_RESOURCES=communications/onlineMeetingsThe bind host is read from the platform's extra.host in config.yaml (there is no MSGRAPH_WEBHOOK_HOST env var — see the webhook listener reference).
The listener exposes:
/msgraph/webhookfor Graph notifications/healthfor a simple health check
You need to route your public HTTPS endpoint to that listener. For example, if your public domain is https://ops.example.com, your Graph notification URL would typically be:
https://ops.example.com/msgraph/webhookStep 3: Configure Teams Delivery and Pipeline Behavior
Ordered, practical steps. Run one and confirm it worked before moving on.
The meeting pipeline reads its runtime config from the existing teams platform entry. Pipeline-specific knobs live under teams.extra.meeting_pipeline. Teams outbound delivery stays on the normal Teams platform config surface.
Example ~/.hermes/config.yaml:
platforms:
msgraph_webhook:
enabled: true
extra:
host: 127.0.0.1
port: 8646
client_state: "replace-me"
accepted_resources:
- "communications/onlineMeetings"
teams:
enabled: true
extra:
client_id: "your-teams-client-id"
client_secret: "your-teams-client-secret"
tenant_id: "your-teams-tenant-id"
# outbound summary delivery
delivery_mode: "graph" # or incoming_webhook
team_id: "team-id"
channel_id: "channel-id"
# incoming_webhook_url: "https://..."
meeting_pipeline:
transcript_min_chars: 80
transcript_required: false
transcription_fallback: true
ffmpeg_extract_audio: true
notion:
enabled: false
linear:
enabled: falseIf you bind the listener to a non-loopback host such as 0.0.0.0, you must also set allowed_source_cidrs to Microsoft's webhook egress ranges. Loopback binds (127.0.0.1 / ::1) are the intended dev-tunnel and local reverse-proxy setup.
Teams Delivery Modes
Settings you configure once. Change one at a time so you can see what each does.
The pipeline supports two Teams summary-delivery modes inside the existing Teams plugin.
incomingwebhook
Use this when you want a simple webhook post into Teams without channel-message creation through Graph.
Required config:
platforms:
teams:
enabled: true
extra:
delivery_mode: "incoming_webhook"
incoming_webhook_url: "https://..."graph
Use this when you want Hermes to post the summary through Microsoft Graph into a Teams chat or channel.
Supported targets:
chat_idteam_id+channel_idteam_id+home_channelfallback for the existing Teams platform
Example:
platforms:
teams:
enabled: true
extra:
delivery_mode: "graph"
team_id: "team-id"
channel_id: "channel-id"Step 4: Start the Gateway
Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes gateway run.
Start Hermes normally after updating config:
hermes gateway runOr, if you run Hermes in Docker, start the gateway the same way you already do for your deployment.
Check the listener:
curl http://localhost:8646/healthStep 5: Create Graph Subscriptions
Carries a warning. Read it before running anything here. Commands here: hermes teams-pipeline subscribe, hermes teams-pipeline maintain-subscriptions. The upstream warning appears below.
Use the plugin CLI to create and inspect subscriptions.
Examples:
hermes teams-pipeline subscribe \
--resource communications/onlineMeetings/getAllTranscripts \
--notification-url https://ops.example.com/msgraph/webhook \
--client-state "$MSGRAPH_WEBHOOK_CLIENT_STATE"
hermes teams-pipeline subscribe \
--resource communications/onlineMeetings/getAllRecordings \
--notification-url https://ops.example.com/msgraph/webhook \
--client-state "$MSGRAPH_WEBHOOK_CLIENT_STATE"For subscription maintenance and day-2 operator flows, continue with the guide: Operate the Teams Meeting Pipeline.
Validation
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes teams-pipeline validate.
Run the built-in validation snapshot:
hermes teams-pipeline validateUseful companion checks:
hermes teams-pipeline token-health
hermes teams-pipeline subscriptionsTroubleshooting
A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.
| Problem | What to check |
|---|---|
| Graph webhook validation fails | Confirm the public URL is correct and reachable, and that Graph is calling the exact /msgraph/webhook path |
Jobs do not appear in hermes teams-pipeline list | Confirm msgraph_webhook is enabled and that subscriptions point at the right notification URL |
| Transcript-first never succeeds | Check Graph permissions for transcript resources and whether the transcript artifact exists for that meeting |
| Recording fallback fails | Confirm ffmpeg is installed and the Graph app can access recording artifacts |
| Teams summary delivery fails | Re-check delivery_mode, target IDs, and Teams auth config |
5 questions answered by this page alone.
Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.