Connect the remote Azure DevOps MCP server (https://mcp.dev.azure.com/{organization}) so agents can read repositories, pull requests, wikis and work items. Each person connects their own Microsoft account, so Azure DevOps permissions apply per user.
The server signs in with Microsoft Entra ID only. Entra has no dynamic client registration, so connections go through an app registration. By default that is inference.sh's own multi-tenant app: your Microsoft admin approves inference.sh once for your tenant, and after that everyone just connects.
Before you start
- Your Azure DevOps organization is connected to a Microsoft Entra tenant (Organization settings → Microsoft Entra). Standalone Microsoft account (MSA) organizations aren't supported by the remote server.
- Someone with Application Administrator, Cloud Application Administrator or Global Administrator in that tenant does the approval step.
- On inference.sh, a workspace admin adds the server. For an org, an org admin works on the org's own workspace.
1. Add the server (inference.sh admin)
- Open MCPs → add server.
- Server URL:
https://mcp.dev.azure.com/{organization}, e.g.https://mcp.dev.azure.com/contoso. Who can see it: the workspace. - Open the server's edit dialog → headers → use recommended (offered from the server directory's entry). See Recommended headers.
2. Approve inference.sh for your tenant (Microsoft admin, once)
-
Check that the Azure DevOps MCP enterprise application exists in your tenant: Microsoft Entra admin center → Enterprise applications → Application type All applications → search
2a72489c-aab2-4b65-b93a-a91edccf33b8. If it's missing, create it once:bash1az login --tenant <your-tenant-id> --allow-no-subscriptions2az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8 -
On inference.sh, open the server's connect dialog and copy the admin consent link. Send it to the Microsoft admin.
-
The admin opens the link, signs in with their admin account, reviews the permissions (Azure DevOps MCP, delegated; sign you in and maintain access) and selects Accept.
-
The admin lands on an inference.sh page saying the app is approved for the organization. Nothing is connected by this step.
The consent screen shows the app's publisher. Entra lets only admins approve multi-tenant apps from unverified publishers, so this step is an admin step either way.
3. Connect (every member)
- MCPs → the Azure DevOps server → connect.
- The dialog says the server signs in through inference.sh's OAuth app. Select connect.
- Confirm the cross-domain notice: the server authenticates via
login.microsoftonline.com. - Sign in with your work account. You're back on inference.sh with the server connected and its tools listed.
The connection is yours (user scope). Agents run tools as you, limited by your Azure DevOps permissions and the server's headers. Tokens refresh by themselves.
Recommended headers
The remote server filters its tools by request headers. They're set on the server once by an admin and sent on every request, for everyone connecting through the workspace.
| Header | Value | Effect |
|---|---|---|
X-MCP-Toolsets | repos,wiki,wit | Only repository/pull request, wiki and work item tools. Other values: pipelines, work, testplan, advsec, elm, all |
X-MCP-Readonly | true | Read-only tools only: no pull request, comment, work item or wiki writes |
Don't combine X-MCP-Toolsets with X-MCP-Tools (individual tools). Headers are configuration, visible to anyone who can see the server: never put a secret in one. Authorization, Cookie, Mcp-* and other transport headers can't be set.
After changing headers, reconnect or refresh the server's tools so the tool list matches.
Advanced: use your own app registration
Use this when your tenant doesn't allow third-party multi-tenant apps, or you want the app, its permissions and its secret under your own control. Your app then serves your org or workspace instead of inference.sh's.
In Microsoft Entra (admin)
-
Microsoft Entra admin center → App registrations → New registration.
- Name: e.g.
inference.sh – Azure DevOps MCP. - Supported account types: Accounts in this organizational directory only (single tenant).
- Name: e.g.
-
Authentication → Add a platform → Web. Redirect URI:
code1https://app.inference.sh/settings/secrets/oauth/mcpIt must be a Web platform URI, not single-page application or mobile/desktop. Leave Allow public client flows off.
-
Certificates & secrets → Client secrets → New client secret. Copy the Value (shown once), not the secret ID.
-
API permissions → Add a permission → APIs my organization uses → search Azure DevOps MCP or
2a72489c-aab2-4b65-b93a-a91edccf33b8→ Delegated permissions. Pick only what the agents need; read permissions are enough withX-MCP-Readonly: true. Add permissions. -
Grant admin consent for {your tenant}.
-
From Overview, copy the Application (client) ID and the Directory (tenant) ID.
If the Azure DevOps MCP API doesn't show up in step 4, create its enterprise application first (step 2.1 above).
In inference.sh
- As an org admin on the org's own workspace (the app then serves every workspace in the org), or as a workspace admin (that workspace only): MCPs → the server → connect.
- Select use your own OAuth app (or, when no app exists yet, the form opens by itself).
- Enter the application (client) id as client id, the client secret and the directory (tenant) id. Save app.
Members then connect as in step 3. Your app takes precedence over inference.sh's: a workspace's app first, then its org's, then inference.sh's.
Before the client secret expires, create a new one in Entra and enter it in the same form; blank fields keep their stored values. A new secret keeps existing connections working; a different client id means members reconnect. An app can't be removed while connections still use it.
What inference.sh requests
| Authorization server | Microsoft Entra ID, from the server's protected-resource metadata (https://login.microsoftonline.com/organizations/v2.0) |
| Endpoints | login.microsoftonline.com/organizations/oauth2/v2.0/… for a multi-tenant app; login.microsoftonline.com/{tenant}/oauth2/v2.0/… when your own app has a tenant id |
| Scopes | https://mcp.dev.azure.com/.default offline_access: the delegated permissions consented for the app, plus a refresh token |
| Flow | Authorization code with PKCE, confidential client (client secret) |
| Redirect URI | https://app.inference.sh/settings/secrets/oauth/mcp |
Troubleshooting
| Error | Meaning | Fix |
|---|---|---|
"your Microsoft admin needs to approve…" (AADSTS65001, AADSTS90094) | The tenant hasn't approved the app | Send the admin consent link from the connect dialog to a Microsoft admin |
"your Microsoft tenant has no service principal for https://mcp.dev.azure.com yet" (AADSTS650052) | No service principal for the API in the tenant | Run the command the page shows, az ad sp create --id 2a72489c-aab2-4b65-b93a-a91edccf33b8, then approve again |
AADSTS50011 | The app doesn't list the redirect URI | Add https://app.inference.sh/settings/secrets/oauth/mcp as a Web redirect URI |
AADSTS7000215 / AADSTS7000222 | Wrong or expired client secret | Create a new secret and update the app on inference.sh |
AADSTS50194 / AADSTS700016 | A single-tenant app used without its tenant | Enter the directory (tenant) id in the app form |
AADSTS50105 | You aren't assigned to the app | An admin assigns you, or turns off "assignment required" on the enterprise app |
| Connected, but no data | Your Azure DevOps permissions | Check project membership and access level; the server can't see more than you can |
Conditional Access applies as it does for Azure DevOps. If your tenant restricts sign-in by location, allow the remote server's IP addresses 20.125.155.22 and 40.74.28.81.
Next
- Browsing & Connecting — other connectors
- Agent Tools — give an agent the Azure DevOps tools