MCP server for Microsoft Dataverse and Power Platform integration, supporting OAuth 2.0 on-behalf-of (OBO) flows and client credentials authentication
This Dataverse/Power Platform MCP server provides 15 tools with reasonable structure but significant gaps in consistency and completeness. Tool naming follows verb_noun conventions appropriately (dataverse_entity_create, flow_trigger, etc.). However, parameter descriptions are highly inconsistent, some tools have rich, actionable descriptions while others are minimal. Schema definitions are present but many lack proper type constraints (enums for valid values, min/max for numerics). Error handling exists but does not consistently guide recovery. Output schemas are not explicitly documented in the source code. The server handles sensitive OAuth credentials correctly via environment variables, avoiding parameter leakage. Overall, this is solidly average with notable opportunities for improvement to reach production-grade quality.
List Power Platform environments (BAP - Business Application Platform)
Create multiple entity records in Dataverse in a single batch operation
Invoke a custom action in Dataverse
Create a new entity record in Dataverse
Delete an entity record from Dataverse
Query and list entity records from Dataverse with filtering and pagination
Retrieve metadata for a Dataverse entity including columns and relationships
Output schemas not documented. Tool responses are returned as JSON blobs via toJsonResponse() and toErrorResponse() but the structure of data fields returned is never specified. LLMs cannot predict downstream data availability.
Missing enum constraints. Parameters like 'orderby' and 'filter' accept free-form OData strings with no validation hints. No description of valid syntax, examples of filter expressions, or error recovery guidance when LLM constructs invalid OData.
No pagination documentation or limits enforced. dataverse_entity_list accepts 'top' parameter but no min/max constraints, no guidance on result size limits, and no default limit documented. Large result sets risk context window exhaustion.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Read an entity record from Dataverse by ID
Update an entity record in Dataverse
Retrieve a global option set definition from Dataverse
Execute an advanced OData query against Dataverse
Retrieve relationship metadata for Dataverse entities
Validate Dataverse connectivity and return user identifier
List cloud flows in a Power Automate environment
Trigger a cloud flow in Power Automate
Destructive operations (dataverse_entity_delete, flow_trigger) lack confirmation/dry-run step. No pattern to prevent accidental deletions or workflow triggering. Agents can irreversibly destroy data without explicit recovery path.
Error responses not actionable. Generic HTTP status codes (404, 400) thrown without guidance on what to do next. No suggestions for alternative tools or recovery steps when user/resource not found.
Parameter 'data' (in create/update tools) accepts arbitrary object with no schema validation. No specification of required fields, allowed field names, or type constraints. LLMs cannot predict valid payloads.
Missing type specificity in parameters. 'table' and 'logicalName' require Dataverse naming conventions (e.g., publisher prefix) but descriptions do not mention case sensitivity, allowed characters, or format. Normalizers exist in code but constraints not exposed to LLM.
OAuth secret injection is correct (environment variables), but description/instructions for setup are not included in tool definitions. Callers must understand Bearer token flow and 'on-behalf-of' grant type manually.