Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Microsoft Graph’s driveItem content endpoint with ?format=pdf. Send an authenticated GET request, handle the documented 302 Found response, and download the PDF from the temporary URL in the Location header. The source file must be in a format Microsoft Graph supports, and your token must be authorized for the drive, site, or library that contains it.

What the conversion request does

Microsoft Graph treats this as a content-download operation. The normal /content route returns the original bytes; adding format=pdf asks Graph for a converted rendition:

GET /me/drive/items/{item-id}/content?format=pdf

The same pattern can be addressed through a specific drive, SharePoint site, or a path under the drive root. The resource is a driveItem, so first identify the item and confirm that the account or application can read it.

Before you call the API

Confirm the storage context

Graph file operations apply to OneDrive, OneDrive for Business, and SharePoint document libraries. Choose the route matching your context:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • /me/drive/items/{item-id}/content?format=pdf for the signed-in user’s drive.
  • A drive-based route when you already know the drive ID.
  • A site, document-library, or root-path route when the file is stored in SharePoint.

Item IDs are generally safer than paths because paths require URL encoding and can change when a file is moved or renamed. Path addressing is useful when your application receives a stable, human-readable location instead.

Check the source extension

Conversion is not universal. Microsoft’s supported-source table includes common Office formats such as DOC, DOCX, PPT, PPTX, XLS, and XLSX, plus formats including HTML, EPUB, ODT, RTF, TIFF, and several email or message formats. Check the current table for the exact extension you accept. Microsoft explicitly warns: “Not all files can be converted into all formats.” A file type absent from that table may fail rather than produce a best-effort PDF.

Use the least-privileged permission

Access model Least-privileged permission listed for conversion Important qualification
Delegated, work or school account Files.Read The signed-in user must also have access to the item.
Delegated, personal Microsoft account Files.Read Actual access still depends on the account and item.
Application permission Files.ReadWrite.All Use only when an app-only design is required; tenant consent and resource access still apply.
SharePoint Embedded FileStorageContainer.Selected plus applicable container-type permissions These container requirements are additional to the relevant Graph permissions.

The v1.0 reference lists availability in the Global, US Government L4, US Government L5 (DoD), and China operated by 21Vianet national cloud deployments. Verify the endpoint and permission behavior for the cloud in which your tenant operates.

How the HTTP flow works

  1. Acquire an access token for Microsoft Graph with a scope or application permission that can read the item.
  2. Send GET to the item’s /content?format=pdf endpoint with Authorization: Bearer <token>.
  3. Expect 302 Found. Read the Location response header.
  4. Follow that preauthenticated URL promptly and save the response body as a PDF.

The follow-up URL is temporary, normally lasting only a few minutes. Do not queue it for later processing, expose it to users unnecessarily, or add your Graph Authorization header to that download request; Microsoft documents that the preauthenticated URL does not need one.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Runnable examples

cURL

curl -L 
  -H "Authorization: Bearer $GRAPH_TOKEN" 
  "https://graph.microsoft.com/v1.0/me/drive/items/$ITEM_ID/content?format=pdf" 
  -o converted.pdf

-L follows the redirect automatically. For a service that needs to inspect headers or control the second request, omit -L, capture Location, then issue a separate unauthenticated GET to that URL.

Python

import os
import requests

TOKEN = os.environ["GRAPH_TOKEN"]
ITEM_ID = os.environ["ITEM_ID"]
endpoint = (
    "https://graph.microsoft.com/v1.0/me/drive/items/"
    f"{ITEM_ID}/content"
)

r = requests.get(
    endpoint,
    params={"format": "pdf"},
    headers={"Authorization": f"Bearer {TOKEN}"},
    allow_redirects=False,
    timeout=90,
)
r.raise_for_status()

if r.status_code != 302:
    raise RuntimeError(f"Expected 302, received {r.status_code}")

location = r.headers.get("Location")
if not location:
    raise RuntimeError("Graph returned 302 without a Location header")

pdf = requests.get(location, timeout=90)
pdf.raise_for_status()
with open("converted.pdf", "wb") as f:
    f.write(pdf.content)

If your HTTP client follows redirects by default, disable that behavior when you need to verify the Graph response, then make the second request without the bearer token.

Node.js

const token = process.env.GRAPH_TOKEN;
const itemId = process.env.ITEM_ID;
const endpoint = new URL(
  `https://graph.microsoft.com/v1.0/me/drive/items/${encodeURIComponent(itemId)}/content`
);
endpoint.searchParams.set('format', 'pdf');

const graph = await fetch(endpoint, {
  headers: { Authorization: `Bearer ${token}` },
  redirect: 'manual'
});

if (graph.status !== 302) {
  throw new Error(`Expected 302, received ${graph.status}`);
}
const location = graph.headers.get('location');
if (!location) throw new Error('Missing Location header');

const file = await fetch(location);
if (!file.ok) throw new Error(`Download failed: ${file.status}`);
const bytes = Buffer.from(await file.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('converted.pdf', bytes));

Choosing an item route

Item ID

An ID-based request is the most direct form and avoids path-escaping problems:

GET https://graph.microsoft.com/v1.0/me/drive/items/{item-id}/content?format=pdf

Use this when a previous Graph query, upload response, or database record already contains the driveItem ID.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
4K 16MP Document Camera, Word PDF Conversion, Ultra HD Webcam for Live Streaming, Remote Teaching, Web Conferencing, for OS X Windows OBS Android, Multi Angle Adjustment
  • [High Resolution Imaging] Equipped with a 16MP CMOS sensor capturing ultra high definition 4K UHD images at 3840x3104 resolution and 30 , this document camera delivers real time detail clarity without delays. Its excellent noise reduction and color reproduction perform reliably in dim lighting, while the full auto focus system ensures instant sharpness for documents, textbooks, or live demonstrations across teaching, office, and streaming scenarios.
  • [Flexible Multi Angle Adjustment] Featuring a sturdy support frame with 5 precisely adjustable angle positions, this USB document webcam adapts effortlessly to diverse needs. Rotate smoothly for overhead views during virtual classes, product showcases, or barcode scanning, providing stable positioning for web conferencing, distance learning, and content creation without cumbersome repositioning.
  • [Efficient Document Conversion] Streamline workflows by instantly converting physical documents into digital formats like Word or PDF using compatible software. This teaching document camera simplifies ID card and barcode scanning tasks, eliminating manual data entry while maintaining high speed transmission for professional presentations, lesson planning, and remote collaboration in educational or business environments.
  • [Seamless Plug And Play Setup] Connect directly via USB interface to 7/8/10, OS X, or devices without drivers or complex installation. Third party software like OBS automatically recognizes the camera, enabling immediate use for live streaming, video calls, or recording. The Type C power supply ensures stable operation across temperatures from -25°C to 60°C.
  • [Professional Live Streaming Tool] Elevate broadcast quality by dynamically adjusting camera angles to highlight product details, demonstration steps, or handwritten notes during live sessions. Its compact portable design and consistent 4K output add credibility to teaching content, sales pitches, or remote training, making it ideal for educators, presenters, and content creators seeking reliable visual engagement.

Drive, site, or path addressing

For shared drives and SharePoint libraries, substitute the appropriate drive or site route documented for that resource. Path requests must encode spaces, #, ?, and other reserved characters correctly. Resolve the path to a driveItem first if you need predictable retry behavior.

Conversion versus downloading the original

Request Result Use it when
/content Original file bytes and original media type You need to preserve the source document.
/content?format=pdf PDF rendition, returned through a redirect You need a PDF for viewing, printing, or downstream processing.

Do not assume the permissions documented for original-content download and conversion are interchangeable, especially for application access. Check the permission table for the exact operation you deploy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

401 Unauthorized

The token is missing, expired, issued for the wrong audience, or sent incorrectly. Request a Microsoft Graph token, send it as Authorization: Bearer, and verify the tenant and account used to obtain it.

403 Forbidden

The app may lack consent, the user may not have access to the library, or an application-only policy may block the resource. Confirm the least-privileged permission, administrator consent where required, SharePoint permissions, and any SharePoint Embedded container permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

404 Not Found

Check the drive, site, and item ID together. An ID from one drive cannot be used against another. For path routes, verify URL encoding and the exact folder hierarchy.

A response is 200 instead of 302

Your HTTP library may have followed the redirect automatically. Inspect the final response URL and content type, or disable automatic redirects to observe Graph’s documented intermediate response.

302 has no usable download

Use the Location value immediately and do not attach the Graph bearer token to the preauthenticated request. A delayed or reused URL may have expired; repeat the conversion request to obtain a fresh one.

Unsupported file or conversion failure

Compare the source extension with Microsoft’s current supported-source table. A successful upload or ordinary download does not prove that PDF conversion is supported. If the format is unsupported, convert it with a format-specific service or application before uploading a PDF.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
TEXT TO PDF CONVERTER - Conversion of any Text to a PDF Document
  • TEXT TO PDF CONVERTER
  • Conversion of any Text to a PDF Document

Large files, retries, and reliability

No universal latency, file-size success rate, or fidelity guarantee is published for this endpoint. Design for variable conversion time: use a generous client timeout, retry transient 5xx responses with bounded exponential backoff, and never retry a stale preauthenticated URL. Log the Graph status, request correlation information, source item ID, and conversion attempt without logging access tokens or signed download URLs.

Operational and security checklist

  • Request only the permission model your deployment needs.
  • Keep access tokens in a secret store and out of URLs and logs.
  • Stream large PDF responses to disk or object storage instead of retaining unnecessary copies in memory.
  • Validate the downloaded content type and, where appropriate, inspect the PDF signature before handing it to downstream systems.
  • Treat the temporary download URL as a secret until it expires.
  • Record whether the source was converted or the original was downloaded so downstream users do not confuse the two.

Or skip the browser setup

If what you actually need is a screenshot or PDF of a public webpage—not a Microsoft Graph driveItem conversion—ScreenshotNeo provides a single HTTP call. It accepts cookie and consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP server gives Claude, Cursor, and other MCP clients take_screenshot, get_page_info, and capture_pdf tools.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for options such as full-page capture, element selectors, device and retina settings, PDF page ranges, custom JavaScript, authentication headers, cookies, geolocation, blocking rules, caching, signed links, asynchronous webhooks, and bulk capture. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

Frequently Asked Questions

Can Microsoft Graph convert any file to PDF?

No. Conversion depends on the source extension; consult Microsoft’s current supported-source table before promising PDF output.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do I send my Graph bearer token to the redirect URL?

No. The documented preauthenticated download URL is followed without an Authorization header.

Can I reuse the Location URL later?

No. It is temporary and should be downloaded promptly; request a new conversion URL when it expires.

Is this endpoint the same as downloading the original file?

No. Ordinary /content returns the source bytes, while /content?format=pdf requests a PDF rendition.

The Bottom Line

For a supported driveItem, call /content?format=pdf, follow Graph’s short-lived 302 download URL without the bearer token, and grant only the permission required by your delegated or application access model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.