· Installation & Upgrading · Changelog · Report an issue
개요
· Installation & Upgrading · Changelog · Report an issue
README
Power Platform MCP Server
Docs: Overview · Installation & Upgrading · Changelog · Report an issue
An MCP (Model Context Protocol) server for Microsoft Power Platform — 228 tools spanning Power Automate flows, canvas app authoring, model-driven apps, SharePoint, Excel, Dataverse/Dynamics 365, Power Pages, and tenant administration. Build, run, diagnose, and govern automations in natural language.
How this became a Power Platform server. It started as a Power Automate MCP — cloud flows, and not much else. What broadened it was other people: issues filed by users who needed Dataverse and DLP tooling, a discussion thread that turned into the connections work, a reported admin-API breakage that led to the whole governance surface, and a lot of troubleshooting against real tenants where the interesting bugs only show up. Power Apps, Power Pages, desktop flows, and work queues each arrived because someone asked or something broke. The npm package is still
powerautomate-mcp— renaming it would break every existing install — but the scope is the platform now.
Works with any MCP-compatible AI client: Claude Desktop, Claude Code, VS Code Copilot, Cursor, Google Gemini CLI, and more.
Documentation Map
| Page | What you’ll find |
|---|---|
| README (this page) | Features · Quick Start · App Registration · CLI Reference · How It Works · All 228 Tools · Security · Architecture |
| Installation Guide | Choose your path · Easy Path · Fast Path · Connect your AI app · Updating · Troubleshooting · Glossary · Admin & enterprise |
| Changelog | Release history with per-version upgrade notes |
| Privacy Policy | What runs locally, what talks to Microsoft, what we collect (nothing) |
| Issues | Bug reports and feature requests — every one gets read |
Features
228 tools, 24 groups — everything at a glance (full list with descriptions: Available Tools):
| Setup & Authentication (1) | Core Flow Operations (15) | Testing & Debugging (10) |
| Planning & Help (5) | Connections & Custom Connectors (13) | Approvals (3) |
| Dataverse CRUD (7) | Dataverse Depth (queries, metadata, schema, bulk) (11) | SharePoint (11) |
| Excel (OneDrive) (2) | Power Apps (12) | Canvas App Authoring (Preview) (13) |
| Model-driven Apps (13) | Power Apps Administration (4) | Power Pages — Site Configuration (9) |
| Power Pages — Site Management (36) | Power Pages — PAC CLI (8) | Environment Administration (11) |
| DLP Policies (6) | Solutions ALM (8) | Managed Environments & Capacity (6) |
| Desktop Flows / RPA (13) | Work Queues (RPA orchestration) (8) | Billing & AI Builder (3) |
Beyond the tool count:
- Natural-language flow building — describe the automation;
plan_flowgathers the specifics,build_flowcreates it (even before its connections are configured), and pre-flight validation scores it against best practices (0–100) - Real diagnosis, not error dumps — failed runs are drilled to the failing step with the actual API error and a proposed fix
- Complete model-driven app lifecycle — create AppModules, add or remove components, validate, publish, and manage security-role access through documented Dataverse operations
- Canvas source authoring (preview) — create and edit supported
.pa.yamlsource, discover live controls/APIs/data sources, synchronize from Studio, and compile back through Microsoft’s official Canvas Authoring MCP server - Power Pages from content to hosting — edit Dataverse configuration, provision and poll websites, manage domains/certificates/WAF/security, and run supported
pac pagesdeployment workflows - Real Solution ALM — asynchronous solution export/import, component add/remove, clone, and publish-all operations use documented Dataverse actions instead of placeholders
- Sign in from the chat — the
sign_intool completes Microsoft device-code auth without a terminal; every action runs under your own work account - Everything annotated — all 228 tools declare read-only/destructive hints, so AI hosts can apply the right guardrails
- Cross-platform — Windows, macOS, and Linux
Install as a Claude Code plugin
If you use Claude Code, one command installs the server and ten guided skills (setup, build-flow, debug-flow, manage-connections, desktop-flows, work-queues, power-pages, dataverse, govern-tenant, report-issue):
/plugin marketplace add rcb0727/powerplatform-mcp-docs
/plugin install powerautomate-mcp@powerautomate-mcp
The plugin runs the server via npx, so there is nothing else to install. You
still run powerautomate-mcp --setup once to sign in — or use the in-chat
sign_in tool if you’d rather not open a terminal.
Quick Start
Three commands — run them in a terminal:
npm install -g powerautomate-mcp # 1. install
powerautomate-mcp --setup # 2. sign in + connect your AI app
powerautomate-mcp --doctor # 3. confirm everything works
The --setup wizard does it all: lets you choose a least-privilege permission set, creates the Entra app registration (or takes one you provide), signs you in, handles admin consent, picks your environment, and wires the server into your AI app for you — no hand-editing JSON. Then restart your app and ask it to build a flow.
Not very technical? Follow the step-by-step Easy Path with checkpoints.
| Want to… | Do this |
|---|---|
| Connect a specific app during setup | powerautomate-mcp --setup --client claude |
| Connect an app later (or a second one) | powerautomate-mcp --client cursor |
| Skip the global install | npx -y powerautomate-mcp@latest --setup (add --npx so your app uses npx too) |
| Configure your app by hand | Manual client configs |
Supported apps: Claude Desktop, Claude Code, Cursor, VS Code (Copilot), Gemini CLI, Windsurf, ChatGPT (via --http).
Microsoft Entra App Registration
The setup wizard (--setup) detects your situation and only asks when it can’t know: it looks for an existing setup, your organization’s org.json, or an app visible through an already-signed-in Azure CLI — and if nothing is found, asks exactly one question: paste your Client ID, or press Enter to create a new app registration. Creating (the IT/first-person path) signs into Azure, registers the app with only the permissions you pick, and grants org-wide admin consent when your account is allowed to.
New tenants work too (v0.13.0+): if your tenant has never used Power Platform, setup creates the missing first-party service principals and resolves the permission ids your tenant actually publishes — the old
AADSTS650052/AADSTS65006sign-in failures repair themselves on a re-run of--setup.
Who Needs to Do What?
| Role | Action |
|---|---|
| IT / first person at the org | Run --setup, press Enter to create the app, then --emit-org-config to hand the rollout to MDM |
| Someone with a Client ID from IT | Run --setup, paste it — it’s verified against Microsoft on the spot |
| Everyone else (org already deployed) | Nothing — with the org file on the machine, the first in-chat sign_in is the whole onboarding |
Rolling out to a team? See Mass deployment — IT sets up once, pushes
org.jsonmachine-wide, and users never see a wizard.PA_MCP_CLIENT_IDas an environment variable also works for host-managed installs.
Admin Consent
Consent is verified by doing, not asked about: the wizard attempts sign-in, and only if Microsoft reports the app isn’t approved (AADSTS65001) does the approval link appear. On the create path, tenant-wide consent is granted automatically when the signed-in Azure CLI account holds an admin role. Any of these Entra ID roles can approve: Global Administrator, Application Administrator, Cloud Application Administrator, or Privileged Role Administrator. If you don’t have one of these roles, share the URL with your admin:
https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=YOUR_CLIENT_ID
Manual Setup (Optional)
If you prefer to create the app registration manually:
-
Go to Azure Portal > Microsoft Entra ID > App registrations > New registration
-
Configure basic settings:
- Name:
Power Automate MCP - Supported account types: Accounts in any organizational directory (multi-tenant)
- Redirect URI: Select “Public client/native” and enter:
https://login.microsoftonline.com/common/oauth2/nativeclient
- Name:
-
After creation, go to Authentication and enable:
- Allow public client flows: Yes
-
Go to API permissions > Add a permission and add only the permissions for the tool surfaces you want to enable. The setup wizard offers presets for All tool surfaces, Power Automate only, Power Automate + connectors, Dataverse, Power Pages, and Custom.
API Permission Type Used For Power Automate (Flow Service) Flows.Read.AllDelegated Read flows Power Automate (Flow Service) Flows.Manage.AllDelegated Create/update/delete flows Power Automate (Flow Service) Activity.Read.AllDelegated Flow run history Power Automate (Flow Service) Approvals.Manage.AllDelegated Approval management Microsoft Graph User.Read,Sites.ReadWrite.All,Files.ReadWrite.AllDelegated Optional: SharePoint, OneDrive, and Excel helpers PowerApps Service UserDelegated Optional: connections, connector metadata, custom connectors, and Power Apps maker APIs BAP Admin API user_impersonationDelegated Optional: admin tools, Dataverse URL discovery, and Power Pages configuration Dynamics CRM user_impersonationDelegated Optional: Dataverse table/row CRUD and Power Pages configuration Power Platform API delegated permission Delegated Optional: Power Pages site management (Tier 2 — see note below) Least privilege: Power Automate-only setups need only the Flow Service permissions. Skipped feature scopes are saved in
features.enabled, hidden from the advertised MCP tool list, and skipped by--doctor/--validate.Dataverse and admin tools require the BAP Admin API delegated permission (appId
0e0bf3cc-3078-4fd4-9ef3-cb6dc0245b10). Without it, the server cannot resolve the real Dataverse org URL and falls back to a guessed*.crm.dynamics.comhostname that often fails DNS.Power Pages site-management tools (Tier 2) call
https://api.powerplatform.comand need the “Power Platform API” delegated permission (appId8578e004-a5c6-46e7-913e-12f58912df43). It is not added by the automatic--setupapp creation because that API exposes only feature-scoped permissions and the auto-creator can’t safely guess the scope. Add it manually here if you want Tier 2; the Power Pages config tools (Dataverse) work without it. After adding, re-run--setup— the wizard reports whether the Power Platform API authorized. -
Click Grant admin consent for [Your Tenant] (requires Global Admin, Application Admin, Cloud Application Admin, or Privileged Role Admin)
CLI Reference
powerautomate-mcp [options]
| Flag | Description |
|---|---|
--setup, -s |
Run the interactive setup wizard (signs in + connects your AI app) |
--login |
Sign in again using your existing setup — no wizard (expired tokens, MFA/policy changes) |
--doctor |
Check your setup and print exactly what to fix, then exit |
--validate |
Verify config, auth, and API connectivity then exit |
--client |
Wire an AI app’s config to this server, then exit (claude, claude-code, codex/chatgpt, cursor, vscode, gemini, windsurf) |
--emit-org-config |
Print an org.json from your working setup for IT to push machine-wide — coworkers’ setup finds the app automatically (Mass deployment) |
--npx |
With --setup/--client, configure the app to run via npx (no global install) |
--update |
Check for updates and install the latest version |
--version, -v |
Print version and exit |
--http |
Start with Streamable HTTP transport |
--port |
Port for HTTP transport (default: 3000) |
--env |
Override the default environment (alias or GUID) |
--config |
Use an alternate config file |
--debug |
Enable debug-level logging |
--help, -h |
Show help message |
Environment Variables:
| Variable | Description |
|---|---|
PA_MCP_CLIENT_ID |
Microsoft Entra app client ID (overrides config file; with PA_MCP_ENVIRONMENT_ID, bootstraps a full config when no config.json exists — lets a host application supply configuration without a config file) |
PA_MCP_TENANT_ID |
Microsoft Entra tenant ID or domain (overrides config file) |
PA_MCP_ENVIRONMENT_ID |
Power Platform environment ID for the env-var config bootstrap |
PA_MCP_ENVIRONMENT_REGION |
Azure region for the bootstrapped environment (default unitedstates) |
PA_MCP_ORG_CONFIG |
Explicit path to an organization org.json (default locations: %ProgramData%\powerautomate-mcp\, /Library/Application Support/powerautomate-mcp/, /etc/powerautomate-mcp/). With an environmentId pinned, the server boots from it with no per-user config at all |
PA_CONFIG_PATH |
Custom path to config.json |
PA_MCP_HTTP_TOKEN |
With --http: require Authorization: Bearer on every MCP request. Protects the HTTP endpoint itself (the tools run with your signed-in account) — required whenever the server is exposed beyond your own machine. See Installation → ChatGPT |
How It Works
Canvas source authoring (preview)
Canvas source authoring uses Microsoft’s official prerelease Canvas Authoring MCP as an isolated child process. Install the .NET 10 SDK, open an existing blank or editable canvas app in Power Apps Studio, enable Settings → Updates → Coauthoring, and keep that Studio tab open. Then call connect_canvas_authoring with the Studio Designer URL before using discovery, sync, or compile tools.
The AI assistant creates or edits App.pa.yaml and one .pa.yaml file per screen, using live control/API/data-source metadata and compile_canvas_source for supported validation and live synchronization. Compilation changes the open draft, so it requires confirm=true. sync_canvas_source can overwrite local source and also requires confirmation. The preview does not provision the initial cloud app shell, add Studio data connections, save, or publish; those remain Power Apps Studio steps. See Microsoft’s external-tools preview guide and Power Apps YAML reference.
More Example Prompts
↑ Back to top
Available Tools (228 total)
Desktop flows are operated here, not authored here. Microsoft exposes no API for creating or editing a desktop flow’s definition — it is Robin script with companion binary records, and their own recovery guidance is to paste it into the Power Automate for desktop designer by hand. Author in the designer; use these tools to run, monitor, diagnose, and orchestrate. Moving an authored flow between environments is supported via
export_solution/import_solution.
Available Tools (228 total)
Every tool the server exposes, grouped by service. All 228 are listed here.
Security
This server implements defense-in-depth security hardened through 3 rounds of penetration testing:
- Secure Token Storage: DPAPI (Windows), Keychain (macOS), libsecret on Linux when available, with a 0o600 file-cache fallback when it is not
- SSRF Prevention: Comprehensive private host detection covering IPv4, IPv6, IPv6-mapped/compatible IPv4, octal/hex/decimal notation, ULA, link-local ranges, domain allowlists
- OData Injection Protection: Tautology detection across all comparison operators, parenthesized forms, arithmetic/function-based bypasses, Unicode NFC normalization, ASCII-only enforcement
- Path Traversal Prevention: NFKC Unicode normalization, bidi control character stripping, zero-width character removal, null byte rejection, URL double-encoding defense
- Input Validation: GUID validation on all IDs, field list validation, environment ID format checks, SharePoint hostname allowlist
- Injection Prevention: Power Automate expression injection blocking (
@{/}@), command injection prevention (execFileoverexec), prototype pollution defense - Error Sanitization: Recursive sensitive key redaction (tokens, passwords, secrets), PII removal, stack trace suppression
- Log Redaction: Deep wildcard Pino redaction for auth headers, tokens, API keys
- HTTP Transport Security: Localhost-only binding, session-based Streamable HTTP, timing-safe API key comparison
- Resource Limits: 2MB input size limit, 20-level depth limit, 50MB JSON response limit, 100MB binary download limit
- Config Hardening: File permissions (0o600), symlink rejection, world-readable warnings
- Auth Safety: Token refresh mutex, MSAL PII filtering, MSAL verbose/trace suppression, silent-only mode in server
↑ Back to top
Architecture
AI Client powerautomate-mcp
(Claude, VS Code, |
Cursor, Gemini) ├── Power Automate Flow Management API
├── Power Apps API (canvas/model-driven apps)
├── Power Platform Admin API (environments, DLP, capacity)
├── Microsoft Graph API (SharePoint, OneDrive, Excel)
├── Dataverse Web API (tables, rows, solutions)
├── MSAL Auth (browser popup / device code)
├── SQLite Schema Cache (400+ connectors)
└── Secure Token Storage (OS keychain)
License
Community License 1.0 — free to use, study, modify, and share, including at work. One rule: it stays free. Selling or monetizing the software (or forks of it) is not permitted, and every copy carries the same terms. Versions published before this change remain MIT.
A Note of Thanks
Thank you for using this project — it is truly appreciated. Every install, bug report, and suggestion makes this a better tool, and I’m committed to fixing any issue that arises so we have the best Power Automate MCP server possible. If something isn’t working for you, please open an issue. I read every one, and a solid reproduction gets a fast fix.
Support
For issues and feature requests, please open an issue in this repository. Upgrading? See Updating safely and the Changelog.
설치
This server does not publish a one-line install command.
Open the repository installation guide