SharePoint
A SharePoint Online tenant that answers Microsoft Graph's sites, drives, lists and pages, SharePoint's classic _api REST and SOAP reads for the official client libraries, plus an MCP server.
Vendor reference: https://learn.microsoft.com/en-us/sharepoint/dev/sp-add-ins/get-to-know-the-sharepoint-rest-service ↗. Machine-readable: compat/sharepoint.json.
Surfaces
| Kind | Path | Notes |
|---|---|---|
| REST | /v1.0 | Microsoft Graph sites, drives, driveItems, lists, list items, pages, permissions, delta and subscriptions; $batch |
| REST | /_api | SharePoint REST (also /sites/{name}/_api) for webs, lists, items, files, folders, search, comments and likes; $batch |
| OAuth | /{tenant}/oauth2/v2.0/token | client credentials with Graph and SharePoint scopes, Sites.Selected site grants |
| MCP | /mcp | Streamable HTTP |
API versions: Microsoft Graph v1.0, SharePoint REST (`_api`)
Supported
- Office365-REST-Python-Client and PnPjs request shapes against
_api, includingGetByTitle,GetById,GetItemByIdand/sites/{name}/_apiaddressing - Comments, replies and
@mention{n}mentions on list items and pages, comment and item likes,likedByInformation,Reputation.SetLike,SetCommentsDisabledand the page'sshowComments - Drive and list delta with resumable tokens, and change-notification subscriptions with the validation handshake
- Refusals in each surface's own envelope (
accessDenied,-2147024891, System.UnauthorizedAccessException,itemNotFound) - A day1 estate and a day2 incremental that only appends to it
- The REST change log (
getChanges,RenderListDataAsStream), chunkedstartUpload/continueUpload/finishUpload, recycle-bin restore andSP.MoveCopyUtil.* - Role-inheritance and role-assignment writes, role definitions, field and view creation,
webs/add, navigation, regional settings and site features over_api - Graph follow and
followedSites, special folders, media facets,getActivitiesByIntervalactivity stats, the term store, sensitivity labels,$countandsites/getByPath
Not supported
- Document sets, content-type hubs, retention labels, and Graph content-type create/update/delete
- SOAP writes (
Lists.asmxwrites,Webs.asmx,Copy.asmx) and Excel workbook comments
Known differences and test guidance
| Scenario | Difference from SharePoint | In your tests |
|---|---|---|
| Site group membership | Membership is derived from the site's grants and served read-only; adding a member through _api is refused. | Grant access through site permissions instead of group membership. |
| Comment entities in Office365-REST-Python-Client | The client keys a Comment on Id while the service sends id, as SharePoint Online does, so a comment read from a collection is not addressable as is. | Address a fetched comment as Comments({id}) before calling like() or delete_object(). |
Fault injection
| Key | What the client sees |
|---|---|
throttle | 429 with Retry-After, the way SharePoint Online throttles |
Applies to every system
- The hosted data plane is read-only: a write is refused with
403 writes_disabled. A SOQL, GraphQL or searchPOSTis a read and is answered. - Faults are injected through
POST /_admin/faultson a simulator you run yourself;POST /_admin/faults/resetclears them. - Rate limits do not happen on their own unless a page says so. Use fault injection to exercise a client's backoff.
- Distributions come from aggregated metadata sketches of data Eon backs up; no customer records; all Era data is simulated.