RP

rcb0727/powerplatform-mcp-docs

Developer tools
86 stars 0 forks Качество 70 Тренд 70

· Installation & Upgrading · Changelog · Report an issue

Обзор

· Installation & Upgrading · Changelog · Report an issue

README

Power Platform MCP Server

Docs: Overview · Installation & Upgrading · Changelog · Report an issue

An MCP (Model Context Protocol) server for Microsoft Power Platform — 228 tools spanning Power Automate flows, canvas app authoring, model-driven apps, SharePoint, Excel, Dataverse/Dynamics 365, Power Pages, and tenant administration. Build, run, diagnose, and govern automations in natural language.

How this became a Power Platform server. It started as a Power Automate MCP — cloud flows, and not much else. What broadened it was other people: issues filed by users who needed Dataverse and DLP tooling, a discussion thread that turned into the connections work, a reported admin-API breakage that led to the whole governance surface, and a lot of troubleshooting against real tenants where the interesting bugs only show up. Power Apps, Power Pages, desktop flows, and work queues each arrived because someone asked or something broke. The npm package is still powerautomate-mcp — renaming it would break every existing install — but the scope is the platform now.

Works with any MCP-compatible AI client: Claude Desktop, Claude Code, VS Code Copilot, Cursor, Google Gemini CLI, and more.

Documentation Map

Page What you’ll find
README (this page) Features · Quick Start · App Registration · CLI Reference · How It Works · All 228 Tools · Security · Architecture
Installation Guide Choose your path · Easy Path · Fast Path · Connect your AI app · Updating · Troubleshooting · Glossary · Admin & enterprise
Changelog Release history with per-version upgrade notes
Privacy Policy What runs locally, what talks to Microsoft, what we collect (nothing)
Issues Bug reports and feature requests — every one gets read

Features

228 tools, 24 groups — everything at a glance (full list with descriptions: Available Tools):

Setup & Authentication (1) Core Flow Operations (15) Testing & Debugging (10)
Planning & Help (5) Connections & Custom Connectors (13) Approvals (3)
Dataverse CRUD (7) Dataverse Depth (queries, metadata, schema, bulk) (11) SharePoint (11)
Excel (OneDrive) (2) Power Apps (12) Canvas App Authoring (Preview) (13)
Model-driven Apps (13) Power Apps Administration (4) Power Pages — Site Configuration (9)
Power Pages — Site Management (36) Power Pages — PAC CLI (8) Environment Administration (11)
DLP Policies (6) Solutions ALM (8) Managed Environments & Capacity (6)
Desktop Flows / RPA (13) Work Queues (RPA orchestration) (8) Billing & AI Builder (3)

Beyond the tool count:

  • Natural-language flow building — describe the automation; plan_flow gathers the specifics, build_flow creates it (even before its connections are configured), and pre-flight validation scores it against best practices (0–100)
  • Real diagnosis, not error dumps — failed runs are drilled to the failing step with the actual API error and a proposed fix
  • Complete model-driven app lifecycle — create AppModules, add or remove components, validate, publish, and manage security-role access through documented Dataverse operations
  • Canvas source authoring (preview) — create and edit supported .pa.yaml source, discover live controls/APIs/data sources, synchronize from Studio, and compile back through Microsoft’s official Canvas Authoring MCP server
  • Power Pages from content to hosting — edit Dataverse configuration, provision and poll websites, manage domains/certificates/WAF/security, and run supported pac pages deployment workflows
  • Real Solution ALM — asynchronous solution export/import, component add/remove, clone, and publish-all operations use documented Dataverse actions instead of placeholders
  • Sign in from the chat — the sign_in tool completes Microsoft device-code auth without a terminal; every action runs under your own work account
  • Everything annotated — all 228 tools declare read-only/destructive hints, so AI hosts can apply the right guardrails
  • Cross-platform — Windows, macOS, and Linux

Install as a Claude Code plugin

If you use Claude Code, one command installs the server and ten guided skills (setup, build-flow, debug-flow, manage-connections, desktop-flows, work-queues, power-pages, dataverse, govern-tenant, report-issue):

/plugin marketplace add rcb0727/powerplatform-mcp-docs
/plugin install powerautomate-mcp@powerautomate-mcp

The plugin runs the server via npx, so there is nothing else to install. You still run powerautomate-mcp --setup once to sign in — or use the in-chat sign_in tool if you’d rather not open a terminal.

Quick Start

Three commands — run them in a terminal:

npm install -g powerautomate-mcp   # 1. install
powerautomate-mcp --setup          # 2. sign in + connect your AI app
powerautomate-mcp --doctor         # 3. confirm everything works

The --setup wizard does it all: lets you choose a least-privilege permission set, creates the Entra app registration (or takes one you provide), signs you in, handles admin consent, picks your environment, and wires the server into your AI app for you — no hand-editing JSON. Then restart your app and ask it to build a flow.

Not very technical? Follow the step-by-step Easy Path with checkpoints.

Want to… Do this
Connect a specific app during setup powerautomate-mcp --setup --client claude
Connect an app later (or a second one) powerautomate-mcp --client cursor
Skip the global install npx -y powerautomate-mcp@latest --setup (add --npx so your app uses npx too)
Configure your app by hand Manual client configs

Supported apps: Claude Desktop, Claude Code, Cursor, VS Code (Copilot), Gemini CLI, Windsurf, ChatGPT (via --http).


Microsoft Entra App Registration

The setup wizard (--setup) detects your situation and only asks when it can’t know: it looks for an existing setup, your organization’s org.json, or an app visible through an already-signed-in Azure CLI — and if nothing is found, asks exactly one question: paste your Client ID, or press Enter to create a new app registration. Creating (the IT/first-person path) signs into Azure, registers the app with only the permissions you pick, and grants org-wide admin consent when your account is allowed to.

New tenants work too (v0.13.0+): if your tenant has never used Power Platform, setup creates the missing first-party service principals and resolves the permission ids your tenant actually publishes — the old AADSTS650052 / AADSTS65006 sign-in failures repair themselves on a re-run of --setup.

Who Needs to Do What?

Role Action
IT / first person at the org Run --setup, press Enter to create the app, then --emit-org-config to hand the rollout to MDM
Someone with a Client ID from IT Run --setup, paste it — it’s verified against Microsoft on the spot
Everyone else (org already deployed) Nothing — with the org file on the machine, the first in-chat sign_in is the whole onboarding

Rolling out to a team? See Mass deployment — IT sets up once, pushes org.json machine-wide, and users never see a wizard. PA_MCP_CLIENT_ID as an environment variable also works for host-managed installs.

Consent is verified by doing, not asked about: the wizard attempts sign-in, and only if Microsoft reports the app isn’t approved (AADSTS65001) does the approval link appear. On the create path, tenant-wide consent is granted automatically when the signed-in Azure CLI account holds an admin role. Any of these Entra ID roles can approve: Global Administrator, Application Administrator, Cloud Application Administrator, or Privileged Role Administrator. If you don’t have one of these roles, share the URL with your admin:

https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=YOUR_CLIENT_ID

Manual Setup (Optional)

If you prefer to create the app registration manually:

  1. Go to Azure Portal > Microsoft Entra ID > App registrations > New registration

  2. Configure basic settings:

    • Name: Power Automate MCP
    • Supported account types: Accounts in any organizational directory (multi-tenant)
    • Redirect URI: Select “Public client/native” and enter:
      https://login.microsoftonline.com/common/oauth2/nativeclient
      
  3. After creation, go to Authentication and enable:

    • Allow public client flows: Yes
  4. Go to API permissions > Add a permission and add only the permissions for the tool surfaces you want to enable. The setup wizard offers presets for All tool surfaces, Power Automate only, Power Automate + connectors, Dataverse, Power Pages, and Custom.

    API Permission Type Used For
    Power Automate (Flow Service) Flows.Read.All Delegated Read flows
    Power Automate (Flow Service) Flows.Manage.All Delegated Create/update/delete flows
    Power Automate (Flow Service) Activity.Read.All Delegated Flow run history
    Power Automate (Flow Service) Approvals.Manage.All Delegated Approval management
    Microsoft Graph User.Read, Sites.ReadWrite.All, Files.ReadWrite.All Delegated Optional: SharePoint, OneDrive, and Excel helpers
    PowerApps Service User Delegated Optional: connections, connector metadata, custom connectors, and Power Apps maker APIs
    BAP Admin API user_impersonation Delegated Optional: admin tools, Dataverse URL discovery, and Power Pages configuration
    Dynamics CRM user_impersonation Delegated Optional: Dataverse table/row CRUD and Power Pages configuration
    Power Platform API delegated permission Delegated Optional: Power Pages site management (Tier 2 — see note below)

    Least privilege: Power Automate-only setups need only the Flow Service permissions. Skipped feature scopes are saved in features.enabled, hidden from the advertised MCP tool list, and skipped by --doctor / --validate.

    Dataverse and admin tools require the BAP Admin API delegated permission (appId 0e0bf3cc-3078-4fd4-9ef3-cb6dc0245b10). Without it, the server cannot resolve the real Dataverse org URL and falls back to a guessed *.crm.dynamics.com hostname that often fails DNS.

    Power Pages site-management tools (Tier 2) call https://api.powerplatform.com and need the “Power Platform API” delegated permission (appId 8578e004-a5c6-46e7-913e-12f58912df43). It is not added by the automatic --setup app creation because that API exposes only feature-scoped permissions and the auto-creator can’t safely guess the scope. Add it manually here if you want Tier 2; the Power Pages config tools (Dataverse) work without it. After adding, re-run --setup — the wizard reports whether the Power Platform API authorized.

  5. Click Grant admin consent for [Your Tenant] (requires Global Admin, Application Admin, Cloud Application Admin, or Privileged Role Admin)


CLI Reference

powerautomate-mcp [options]
Flag Description
--setup, -s Run the interactive setup wizard (signs in + connects your AI app)
--login Sign in again using your existing setup — no wizard (expired tokens, MFA/policy changes)
--doctor Check your setup and print exactly what to fix, then exit
--validate Verify config, auth, and API connectivity then exit
--client Wire an AI app’s config to this server, then exit (claude, claude-code, codex/chatgpt, cursor, vscode, gemini, windsurf)
--emit-org-config Print an org.json from your working setup for IT to push machine-wide — coworkers’ setup finds the app automatically (Mass deployment)
--npx With --setup/--client, configure the app to run via npx (no global install)
--update Check for updates and install the latest version
--version, -v Print version and exit
--http Start with Streamable HTTP transport
--port Port for HTTP transport (default: 3000)
--env Override the default environment (alias or GUID)
--config Use an alternate config file
--debug Enable debug-level logging
--help, -h Show help message

Environment Variables:

Variable Description
PA_MCP_CLIENT_ID Microsoft Entra app client ID (overrides config file; with PA_MCP_ENVIRONMENT_ID, bootstraps a full config when no config.json exists — lets a host application supply configuration without a config file)
PA_MCP_TENANT_ID Microsoft Entra tenant ID or domain (overrides config file)
PA_MCP_ENVIRONMENT_ID Power Platform environment ID for the env-var config bootstrap
PA_MCP_ENVIRONMENT_REGION Azure region for the bootstrapped environment (default unitedstates)
PA_MCP_ORG_CONFIG Explicit path to an organization org.json (default locations: %ProgramData%\powerautomate-mcp\, /Library/Application Support/powerautomate-mcp/, /etc/powerautomate-mcp/). With an environmentId pinned, the server boots from it with no per-user config at all
PA_CONFIG_PATH Custom path to config.json
PA_MCP_HTTP_TOKEN With --http: require Authorization: Bearer on every MCP request. Protects the HTTP endpoint itself (the tools run with your signed-in account) — required whenever the server is exposed beyond your own machine. See Installation → ChatGPT

How It Works


Canvas source authoring (preview)

Canvas source authoring uses Microsoft’s official prerelease Canvas Authoring MCP as an isolated child process. Install the .NET 10 SDK, open an existing blank or editable canvas app in Power Apps Studio, enable Settings → Updates → Coauthoring, and keep that Studio tab open. Then call connect_canvas_authoring with the Studio Designer URL before using discovery, sync, or compile tools.

The AI assistant creates or edits App.pa.yaml and one .pa.yaml file per screen, using live control/API/data-source metadata and compile_canvas_source for supported validation and live synchronization. Compilation changes the open draft, so it requires confirm=true. sync_canvas_source can overwrite local source and also requires confirmation. The preview does not provision the initial cloud app shell, add Studio data connections, save, or publish; those remain Power Apps Studio steps. See Microsoft’s external-tools preview guide and Power Apps YAML reference.

More Example Prompts

↑ Back to top


Available Tools (228 total)

Desktop flows are operated here, not authored here. Microsoft exposes no API for creating or editing a desktop flow’s definition — it is Robin script with companion binary records, and their own recovery guidance is to paste it into the Power Automate for desktop designer by hand. Author in the designer; use these tools to run, monitor, diagnose, and orchestrate. Moving an authored flow between environments is supported via export_solution / import_solution.

Available Tools (228 total)

Every tool the server exposes, grouped by service. All 228 are listed here.

Security

This server implements defense-in-depth security hardened through 3 rounds of penetration testing:

  • Secure Token Storage: DPAPI (Windows), Keychain (macOS), libsecret on Linux when available, with a 0o600 file-cache fallback when it is not
  • SSRF Prevention: Comprehensive private host detection covering IPv4, IPv6, IPv6-mapped/compatible IPv4, octal/hex/decimal notation, ULA, link-local ranges, domain allowlists
  • OData Injection Protection: Tautology detection across all comparison operators, parenthesized forms, arithmetic/function-based bypasses, Unicode NFC normalization, ASCII-only enforcement
  • Path Traversal Prevention: NFKC Unicode normalization, bidi control character stripping, zero-width character removal, null byte rejection, URL double-encoding defense
  • Input Validation: GUID validation on all IDs, field list validation, environment ID format checks, SharePoint hostname allowlist
  • Injection Prevention: Power Automate expression injection blocking (@{/}@), command injection prevention (execFile over exec), prototype pollution defense
  • Error Sanitization: Recursive sensitive key redaction (tokens, passwords, secrets), PII removal, stack trace suppression
  • Log Redaction: Deep wildcard Pino redaction for auth headers, tokens, API keys
  • HTTP Transport Security: Localhost-only binding, session-based Streamable HTTP, timing-safe API key comparison
  • Resource Limits: 2MB input size limit, 20-level depth limit, 50MB JSON response limit, 100MB binary download limit
  • Config Hardening: File permissions (0o600), symlink rejection, world-readable warnings
  • Auth Safety: Token refresh mutex, MSAL PII filtering, MSAL verbose/trace suppression, silent-only mode in server

↑ Back to top

Architecture

AI Client  powerautomate-mcp
(Claude, VS Code,               |
 Cursor, Gemini)                 ├── Power Automate Flow Management API
                                 ├── Power Apps API (canvas/model-driven apps)
                                 ├── Power Platform Admin API (environments, DLP, capacity)
                                 ├── Microsoft Graph API (SharePoint, OneDrive, Excel)
                                 ├── Dataverse Web API (tables, rows, solutions)
                                 ├── MSAL Auth (browser popup / device code)
                                 ├── SQLite Schema Cache (400+ connectors)
                                 └── Secure Token Storage (OS keychain)

License

Community License 1.0 — free to use, study, modify, and share, including at work. One rule: it stays free. Selling or monetizing the software (or forks of it) is not permitted, and every copy carries the same terms. Versions published before this change remain MIT.

A Note of Thanks

Thank you for using this project — it is truly appreciated. Every install, bug report, and suggestion makes this a better tool, and I’m committed to fixing any issue that arises so we have the best Power Automate MCP server possible. If something isn’t working for you, please open an issue. I read every one, and a solid reproduction gets a fast fix.

Support

For issues and feature requests, please open an issue in this repository. Upgrading? See Updating safely and the Changelog.

View this README on GitHub

Установка

This server does not publish a one-line install command.

Open the repository installation guide