Azure DevOps

Connect the remote Azure DevOps MCP server (https://mcp.dev.azure.com/{organization}) so agents can read repositories, pull requests, wikis and work items. Each person connects their own Microsoft account, so Azure DevOps permissions apply per user.

The server signs in with Microsoft Entra ID only. Entra has no dynamic client registration, so connections go through an app registration. By default that is inference.sh's own multi-tenant app: your Microsoft admin approves inference.sh once for your tenant, and after that everyone just connects.


Before you start

  • Your Azure DevOps organization is connected to a Microsoft Entra tenant (Organization settings → Microsoft Entra). Standalone Microsoft account (MSA) organizations aren't supported by the remote server.
  • Someone with Application Administrator, Cloud Application Administrator or Global Administrator in that tenant does the approval step.
  • On inference.sh, a workspace admin adds the server. For an org, an org admin works on the org's own workspace.

1. Add the server (inference.sh admin)

  1. Open MCPs → add server.
  2. Server URL: https://mcp.dev.azure.com/{organization}, e.g. https://mcp.dev.azure.com/contoso. Who can see it: the workspace.
  3. Open the server's edit dialog → headers → use recommended (offered from the server directory's entry). See Recommended headers.

2. Approve inference.sh for your tenant (Microsoft admin, once)

  1. Check that the Azure DevOps MCP enterprise application exists in your tenant: Microsoft Entra admin center → Enterprise applications → Application type All applications → search 2a72489c-aab2-4b65-b93a-a91edccf33b8. If it's missing, create it once:

    bash
    1az login --tenant <your-tenant-id> --allow-no-subscriptions2az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8
  2. On inference.sh, open the server's connect dialog and copy the admin consent link. Send it to the Microsoft admin.

  3. The admin opens the link, signs in with their admin account, reviews the permissions (Azure DevOps MCP, delegated; sign you in and maintain access) and selects Accept.

  4. The admin lands on an inference.sh page saying the app is approved for the organization. Nothing is connected by this step.

The consent screen shows the app's publisher. Entra lets only admins approve multi-tenant apps from unverified publishers, so this step is an admin step either way.


3. Connect (every member)

  1. MCPs → the Azure DevOps server → connect.
  2. The dialog says the server signs in through inference.sh's OAuth app. Select connect.
  3. Confirm the cross-domain notice: the server authenticates via login.microsoftonline.com.
  4. Sign in with your work account. You're back on inference.sh with the server connected and its tools listed.

The connection is yours (user scope). Agents run tools as you, limited by your Azure DevOps permissions and the server's headers. Tokens refresh by themselves.


The remote server filters its tools by request headers. They're set on the server once by an admin and sent on every request, for everyone connecting through the workspace.

HeaderValueEffect
X-MCP-Toolsetsrepos,wiki,witOnly repository/pull request, wiki and work item tools. Other values: pipelines, work, testplan, advsec, elm, all
X-MCP-ReadonlytrueRead-only tools only: no pull request, comment, work item or wiki writes

Don't combine X-MCP-Toolsets with X-MCP-Tools (individual tools). Headers are configuration, visible to anyone who can see the server: never put a secret in one. Authorization, Cookie, Mcp-* and other transport headers can't be set.

After changing headers, reconnect or refresh the server's tools so the tool list matches.


Advanced: use your own app registration

Use this when your tenant doesn't allow third-party multi-tenant apps, or you want the app, its permissions and its secret under your own control. Your app then serves your org or workspace instead of inference.sh's.

In Microsoft Entra (admin)

  1. Microsoft Entra admin center → App registrations → New registration.

    • Name: e.g. inference.sh – Azure DevOps MCP.
    • Supported account types: Accounts in this organizational directory only (single tenant).
  2. Authentication → Add a platform → Web. Redirect URI:

    code
    1https://app.inference.sh/settings/secrets/oauth/mcp

    It must be a Web platform URI, not single-page application or mobile/desktop. Leave Allow public client flows off.

  3. Certificates & secrets → Client secrets → New client secret. Copy the Value (shown once), not the secret ID.

  4. API permissions → Add a permission → APIs my organization uses → search Azure DevOps MCP or 2a72489c-aab2-4b65-b93a-a91edccf33b8 → Delegated permissions. Pick only what the agents need; read permissions are enough with X-MCP-Readonly: true. Add permissions.

  5. Grant admin consent for {your tenant}.

  6. From Overview, copy the Application (client) ID and the Directory (tenant) ID.

If the Azure DevOps MCP API doesn't show up in step 4, create its enterprise application first (step 2.1 above).

In inference.sh

  1. As an org admin on the org's own workspace (the app then serves every workspace in the org), or as a workspace admin (that workspace only): MCPs → the server → connect.
  2. Select use your own OAuth app (or, when no app exists yet, the form opens by itself).
  3. Enter the application (client) id as client id, the client secret and the directory (tenant) id. Save app.

Members then connect as in step 3. Your app takes precedence over inference.sh's: a workspace's app first, then its org's, then inference.sh's.

Before the client secret expires, create a new one in Entra and enter it in the same form; blank fields keep their stored values. A new secret keeps existing connections working; a different client id means members reconnect. An app can't be removed while connections still use it.


What inference.sh requests

Authorization serverMicrosoft Entra ID, from the server's protected-resource metadata (https://login.microsoftonline.com/organizations/v2.0)
Endpointslogin.microsoftonline.com/organizations/oauth2/v2.0/… for a multi-tenant app; login.microsoftonline.com/{tenant}/oauth2/v2.0/… when your own app has a tenant id
Scopeshttps://mcp.dev.azure.com/.default offline_access: the delegated permissions consented for the app, plus a refresh token
FlowAuthorization code with PKCE, confidential client (client secret)
Redirect URIhttps://app.inference.sh/settings/secrets/oauth/mcp

Troubleshooting

ErrorMeaningFix
"your Microsoft admin needs to approve…" (AADSTS65001, AADSTS90094)The tenant hasn't approved the appSend the admin consent link from the connect dialog to a Microsoft admin
"your Microsoft tenant has no service principal for https://mcp.dev.azure.com yet" (AADSTS650052)No service principal for the API in the tenantRun the command the page shows, az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8, then approve again
AADSTS50011The app doesn't list the redirect URIAdd https://app.inference.sh/settings/secrets/oauth/mcp as a Web redirect URI
AADSTS7000215 / AADSTS7000222Wrong or expired client secretCreate a new secret and update the app on inference.sh
AADSTS50194 / AADSTS700016A single-tenant app used without its tenantEnter the directory (tenant) id in the app form
AADSTS50105You aren't assigned to the appAn admin assigns you, or turns off "assignment required" on the enterprise app
Connected, but no dataYour Azure DevOps permissionsCheck project membership and access level; the server can't see more than you can

Conditional Access applies as it does for Azure DevOps. If your tenant restricts sign-in by location, allow the remote server's IP addresses 20.125.155.22 and 40.74.28.81.


Next

we use cookies

we use cookies to ensure you get the best experience on our website. for more information on how we use cookies, please see our cookie policy.

by clicking "accept", you agree to our use of cookies.
learn more.