Skip to main content
ABBYY FlexiCapture 12 lets you automatically import and process document images from your email via the Microsoft Graph Mail API. To do this, create an image import profile. For more information, see Image import profiles. ABBYY FlexiCapture uses an application called FlexiCapture 12 Graph Mail Import to access your email. To finish setting up your import profile, log in to your Microsoft account and grant the following permissions to the FlexiCapture 12 Graph Mail Import application:
  • Maintain access to data you have given it access to
  • Sign you in and read your profile
  • Read your mail
  • Read and write access to your mail
  • Read and write mail you can access
The permission identifiers are: For more information about permissions, visit the official Microsoft website.
You cannot change the email import application or modify the permissions granted to it.
Depending on your security settings, one of the following happens on your first authorization attempt:
  • Access is granted.
  • The administrator must grant permission before you can access your mail. For more information, see the official Microsoft website.

OAuth 2.0 authorization

To set up image import via the Microsoft Graph Mail API, you must complete OAuth 2.0 authorization. For more information about the authorization process, see the official Microsoft website and section 4.1 of the OAuth 2.0 Framework. After authorization, you are automatically directed to https://go.abbyy.com/oauth2redirect, which then redirects you to https://127.0.0.1. If authorization is successful, return to the authorization wizard and continue setting up the import profile. Redirection to https://go.abbyy.com/oauth2redirect is required to use the HTTPS protocol. For more information, see the official Microsoft website. This step is completely safe. Data collection is disabled at https://go.abbyy.com/oauth2redirect, and no other actions are performed.
Sometimes, after confirmation of authorization is received, authentication is denied with the error Flow failed. Failure info/error: Connect to token endpoint failed. For more information, see Microsoft Graph API connection error.
During the import, the primary refresh token is replaced with secondary access and refresh tokens, which are used for authorization and to access your email via the Microsoft Graph Mail API. Administrator permissions are not required, because access is provided only to a specific user or mailbox.
By default, the refresh token required to use the Microsoft Graph Mail API expires after 90 days of inactivity, and you must re-authenticate to obtain a new token. An Active Directory administrator can configure the token lifetime. For more information, see the Microsoft documentation on configurable token lifetimes.
When you set up an import profile on the Project Setup Station, the computer where the Project Setup Station is open establishes the connection to the mailbox. For automatic import tasks, Processing Station computers establish the connection.