To download a SharePoint file with Microsoft Graph, request its driveItem content endpoint, authenticate the Graph request with an access token, and follow the redirect to the file’s temporary preauthenticated download URL. In a browser, avoid sending the Graph bearer token to that redirected URL: request the @microsoft.graph.downloadUrl metadata property first, then fetch that URL directly to avoid the documented CORS-preflight problem.
What the download endpoint does
Microsoft Graph exposes SharePoint documents as driveItem resources. The /content operation downloads the primary content stream for an item; it does not download arbitrary drive items such as folders. Microsoft’s endpoint documentation puts it plainly: “Only driveItem objects with the file property can be downloaded.” See the Microsoft Graph v1.0 download-content endpoint.
A typical request is:
GET https://graph.microsoft.com/v1.0/sites/{siteId}/drive/items/{itemId}/content
Authorization: Bearer {access_token}
The response is normally 302 Found, with a Location header containing a short-lived, preauthenticated URL for the bytes. Many HTTP libraries follow this redirect automatically. If your client does not, make a second request to the URL in Location. The temporary URL does not require the Graph Authorization header and may expire within minutes, so use it promptly. The same download URL can be exposed as @microsoft.graph.downloadUrl in item metadata.
The examples below use the Graph v1.0 REST API. Route availability and permissions differ by access model; use the least-privileged permission appropriate to your app and file.
Recommended Free Tools
#1 Best Overall
- Instant Copilot. Unlock new possibilities with the dedicated Copilot key, which gives you instant access to experiences that can enhance your productivity¹.
- Enhance your experience With the new microphone mute key and snipping key
- Full keyboard experience. Features a full mechanical keyset, backlit keys, and a large trackpad for precise navigation and control. Optimal key spacing allows fast, fluid typing.
- Slim and compact Performs like a traditional, full-size keyboard.
- Clicks in place instantly Use in combination with the Surface Pro (11th Edition), Pro 9 and Pro 8* kickstand for a perfect laptop experience anywhere.
Choose a route and locate the file
Use the route that matches what your application already knows. You can address a file by drive and item ID, site and item ID, the signed-in user’s drive, or a supported path. Microsoft documents these route families on the content endpoint page.
| What you know | Route pattern |
|---|---|
| Drive ID and item ID | /drives/{drive-id}/items/{item-id}/content |
| Site ID and item ID in the site’s default drive | /sites/{siteId}/drive/items/{item-id}/content |
| Signed-in user and item ID | /me/drive/items/{item-id}/content |
| Path relative to the signed-in user’s drive root | /me/drive/root:/{item-path}:/content |
| Shared item | Use the documented shared-item route for the sharing link and item, as described by Microsoft’s content endpoint documentation. |
If you have a site and a path but not the item ID, retrieve the driveItem by path first. If you have an ID, retrieve metadata by ID. The metadata endpoint documents both patterns and the properties returned: Get a driveItem.
Retrieve an item by path
For a file under a known drive root, use a path-addressed metadata request, URL-encoding path characters as required by the URL. For example:
GET https://graph.microsoft.com/v1.0/drives/{drive-id}/root:/Shared%20Documents/Reports/Q3.xlsx
Authorization: Bearer {access_token}
Read the returned id and use that item ID in the content request. Do not confuse a display name with a stable identifier if your workflow already has the item ID.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- Surface Pro Type Cover has a new improved design with slightly spread out keys for a more familiar and efficient typing experience that feels like a traditional laptop
- The two button trackpad is now larger for precision control and navigation
- The keyboard is sturdy with enhanced magnetic stability along the fold so you can adjust it to the right angle and work on your lap, on the plane, or at your desk. Since it's designed just for Surface, Surface Pro Type Cover easily clicks into place to go from tablet to laptop instantly
- Protects and shields the screen from bumps and scratches
Set up permissions and authentication
Register or configure an application in Microsoft Entra ID, obtain an access token for Microsoft Graph, and grant only the permission that fits the way the app accesses files. The endpoint’s documented least-privileged options include delegated work-or-school access with Files.Read and application access with Files.Read.All. The full permission table also distinguishes delegated personal-account permissions and higher-privilege alternatives; check the endpoint page for the account type and permission actually supported by your scenario.
- Delegated access: use when an app acts on behalf of a signed-in user. The available files are constrained by the user’s access and the delegated scopes granted to the app.
- Application access: use when a service runs without a signed-in user. Application permissions can reach files beyond one user’s context, so grant and administratively consent only the necessary access.
- SharePoint Embedded: this has additional
FileStorageContainer.Selectedand container-type permission requirements. Follow the specific requirements in Microsoft’s download endpoint permissions table.
Send the bearer token to Microsoft Graph. Do not hard-code a client secret or access token into a distributed browser application, and do not log tokens or preauthenticated download URLs where others could reuse them.
Download a file from a server or script
For a backend or command-line script, request the /content endpoint and save the response body. The following cURL command follows redirects and writes the resulting file. Replace the site and item IDs and provide a valid token in your shell environment:
export GRAPH_TOKEN='YOUR_ACCESS_TOKEN'
curl -L
-H "Authorization: Bearer $GRAPH_TOKEN"
"https://graph.microsoft.com/v1.0/sites/{siteId}/drive/items/{itemId}/content"
-o downloaded-file
-L tells cURL to follow the 302 redirect. The initial request needs the bearer token; the preauthenticated destination does not. The output filename is yours to choose because the command explicitly sets it with -o.
Rank #3
- Instant Copilot. Unlock new possibilities with the dedicated Copilot key, which gives you instant access to experiences that can enhance your productivity¹.
- Enhance your experience With the new microphone mute key and snipping key
- Full keyboard experience. Features a full mechanical keyset, backlit keys, and a large trackpad for precise navigation and control. Optimal key spacing allows fast, fluid typing.
- Slim and compact Performs like a traditional, full-size keyboard.
- Clicks in place instantly Use in combination with the Surface Pro (11th Edition), Pro 9 and Pro 8* kickstand for a perfect laptop experience anywhere.
Handle the redirect explicitly
If your HTTP client does not follow redirects, disable automatic redirects for the Graph call, read the Location header from the 302 response, then issue a separate GET to that URL without the Graph Authorization header. Treat that destination as a temporary bearer-like secret: it grants access to the file until it expires, so avoid persisting or sharing it.
Download in browser JavaScript without the CORS trap
A browser request that adds an Authorization header to Graph may trigger a CORS preflight. Microsoft’s guidance is to request the item’s @microsoft.graph.downloadUrl metadata property from Graph, then fetch the returned URL directly. That second request goes to the preauthenticated URL rather than sending the Graph authorization header cross-origin. See Microsoft’s browser guidance for downloading content.
const graphBase = 'https://graph.microsoft.com/v1.0';
const itemPath = '/sites/SITE_ID/drive/items/ITEM_ID';
const token = 'ACCESS_TOKEN';
const metadataResponse = await fetch(
`${graphBase}${itemPath}?$select=id,name,@microsoft.graph.downloadUrl`,
{ headers: { Authorization: `Bearer ${token}` } }
);
if (!metadataResponse.ok) {
throw new Error(`Graph metadata failed: ${metadataResponse.status}`);
}
const item = await metadataResponse.json();
if (!item['@microsoft.graph.downloadUrl']) {
throw new Error('Graph did not return a download URL');
}
// Do not attach the Graph bearer token to this request.
const fileResponse = await fetch(item['@microsoft.graph.downloadUrl']);
if (!fileResponse.ok) {
throw new Error(`File download failed: ${fileResponse.status}`);
}
const blob = await fileResponse.blob();
const link = document.createElement('a');
link.href = URL.createObjectURL(blob);
link.download = item.name || 'download';
document.body.appendChild(link);
link.click();
link.remove();
URL.revokeObjectURL(link.href);
This example is for a browser context that is allowed to call Graph and the returned download host. Handle token acquisition and renewal through your app’s authentication flow rather than placing a long-lived token in source code. For large files, avoid loading the entire response into a JavaScript Blob if your runtime offers a streaming download path.
Resume or download only part of a file
For a partial transfer, send the Range header to the preauthenticated download URL, not to Graph’s /content endpoint. Microsoft documents that a supported range returns 206 Partial Content; if the requested range cannot be generated, the service may ignore Range and return the full body with 200 OK. See Microsoft’s range-request guidance.
Rank #4
- [Expand Your Possibilities] – Instantly turn Surface Pro[1] into a full laptop with the Surface Pro Keyboard, giving you more ways to work, create, and stay productive anywhere.
- [Comfortable, Precise Typing] – Designed for Surface Pro 12”, this premium keyboard offers a responsive, laptop-like typing experience so you can work comfortably on the go.
- [Flexible Hinge for Any Angle] – The new dynamic hinge flexes a full 360°, letting you type, draw, or stream from virtually any position.
- [Stable on Lap or Desk] – A web-style internal structure adds support and balance, keeping your keyboard steady whether you're at a desk or on your lap.
- [Premium Feel, Built-in Convenience] – Includes a backlit keyboard and large precision touchpad for effortless typing, navigation, and control — day or night.
curl -H 'Range: bytes=0-1048575'
'PREAUTHENTICATED_DOWNLOAD_URL'
-o first-megabyte
Check the status and response headers before appending data to a partial local file. Append only a valid partial response for the expected byte range; if the server returns a full-body 200, replace or separately save the file rather than treating that body as the requested segment.
Common errors and fixes
- 401 Unauthorized: the Graph token is missing, expired, issued for the wrong resource, or not sent on the Graph request. Acquire a fresh Microsoft Graph token and send it to Graph, not to the preauthenticated URL.
- 403 Forbidden: the signed-in user may not have file access, the app may lack the needed delegated or application permission, or admin consent may be missing. Confirm access and the endpoint’s permission table rather than reflexively adding a broad permission.
- 404 Not Found: verify the site, drive, and item IDs, or check path syntax and URL encoding. Retrieve metadata first to establish that the resolved item exists and is a file.
- Folder or non-file item:
/contentis for adriveItemwith afileproperty. Resolve the file inside the folder and request that item instead. - Browser CORS error: avoid the Graph-to-redirect flow with an Authorization header in the browser. Fetch metadata including
@microsoft.graph.downloadUrl, then request that URL directly without the Graph token. - Expired download link: the preauthenticated URL is temporary. Request fresh metadata or make a new
/contentrequest and use the new URL promptly. - Unexpected full file during a range request: the service may ignore a range it cannot generate and return 200 with the full body. Inspect status and range-related headers before resuming or concatenating.
Performance, reliability, and format conversion
The simple /content flow is usually the right choice when the goal is to obtain the original file bytes. Avoid an extra metadata call on server-side clients that can safely follow the redirect; in browser code, the metadata call is useful for CORS. For large transfers, stream response data to disk or a storage destination instead of buffering the entire file in memory. If a transfer is interrupted, a new temporary URL may be needed, and partial-transfer logic must account for a possible 200 full response.
Downloading is distinct from converting. Microsoft documents a separate format-conversion operation and notes that not every file can be converted to every format. Use conversion only when you explicitly need another representation; it is not a replacement for the default original-content download path. See the content endpoint documentation and Microsoft’s format-conversion documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Or skip the browser setup
If your goal is a visual capture of a SharePoint page rather than the underlying document bytes, ScreenshotNeo is a website screenshot API and MCP server from Yorker Media; it is not a Microsoft Graph file downloader. One GET can return an image or PDF, with options for full-page capture, a selected element, custom viewport, and PDF output. Cookie banners, popups, and chat widgets can be removed before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server lets AI agents use screenshot tools.
Free tools Windows power users keep installed
One-click scans. No signup required.
For API setup and parameters, see the ScreenshotNeo documentation. cURL example:
Best Value
- EXCLUSIVE sophisticated look design for Microsoft Surface Pro 7 Plus (2021) / Surface Pro 7 (2019) / Surface Pro 6 (2018) / Surface Pro 5th Gen (2017) / Surface Pro 4 / Surface Pro 3 12.3 inch tablet. ** PLEASE MAKE SURE YOUR SURFACE PRO VERSION BEFORE MAKE PURCHASE !! NOT fit for Pro 2, not fit Pro 8, not fit Pro 9 **
- RESPONSIVE TRACKPAD - Built-in with a responsive trackpad, scrolling & multi-touch gesture, conveniently using like a mouse, navigate and control your tablet precisely, gives you the touch screen experience, without having to take your hands off the keyboard.
- MAGNETIC removable attach or detach, The keyboard is sturdy with enhanced magnetic stability along the fold so you can adjust it to the right angle and work on your lap, on the plane, or at your desk. When you don't need to use the keyboard, you can always detach it from the surface pro and easily switch between surface pro tablet and laptop.(NOT CHARGING VIA MAGNET ATTACH, CHARGE WITH USB CABLE INCLUDED).
- SLIM and LIGHTWEIGHT - Compact size and light weight allows easily be carried and packed in backpack, message bag or case. Comfortable, quiet typing with sturdy ergonomic design could make your hands feel more comfortable when typing, reducing the burden of your hands. Auto-sleep for scientific power saving and extended battery life.
- 7-COLOR BACKLIT - Special 7 colors elegant LED backlights. Ideal for typing freely even in low light conditions or at night.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
It includes 1,000 screenshots a month free with no card; paid plans start at $5 for 3,000. Sign up for the free plan.
Frequently asked questions
Can I download a SharePoint file by its path instead of its ID?
Yes. Microsoft documents path-addressed driveItem routes, including /me/drive/root:/{item-path}:/content. Use a path that is valid for the relevant drive and encode URL characters correctly.
Does the temporary download URL need my Graph access token?
No. The URL is preauthenticated. Do not attach the Graph bearer token to the URL request, and use the URL promptly because it can expire.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Can I use Microsoft Graph to convert a file while downloading it?
Conversion is a separate operation, and Microsoft says not all files can be converted to all formats. Use the original content endpoint unless you specifically require a supported converted format.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

