npm @dockndevai/mcp-azurestdioMITupdated 9d ago
A Model Context Protocol server for Azure (via the Azure Resource Manager API — the programmatic layer behind the Azure Portal). It lets an MCP-capable client (Claude Desktop, Claude Code, Cursor, Codex, …) inventory and operate Azure resources — with a governance layer that keeps an AI agent inside safe boundaries.
¿Qué puedes hacer con mcp azure?
mcp-azure
A Model Context Protocol server for Azure (via the Azure Resource Manager API — the programmatic layer behind the Azure Portal). It lets an MCP-capable client (Claude Desktop, Claude Code, Cursor, Codex, …) inventory and operate Azure resources — with a governance layer that keeps an AI agent inside safe boundaries.
What this offers
- Inventory — list subscriptions, locations, resource groups, and resources; get any resource by ARM id.
- Operations — create resource groups (in approved regions), merge tags onto any resource, and control VM power state (start / stop / restart / deallocate).
- Lifecycle — delete resource groups and individual resources, guarded.
- Governance built in — access modes, subscription/resource-group allowlists, protected resource groups, a location allowlist for new groups, delete gating, typed confirmation for high-impact deletes, dry-run, and JSON audit logging.
Governance & security model
| Concern | Flag | Default | Effect |
|---|---|---|---|
| What can the server do? | AZURE_MODE |
read-only |
read-only → inventory; read-write → create RG, tag, VM power; admin → deletes. Tools above the mode are never registered. |
| Which subscriptions? | AZURE_SUBSCRIPTION_ALLOWLIST |
(all) | Operations on other subscriptions are refused. |
| Which resource groups? | AZURE_RESOURCE_GROUP_ALLOWLIST |
(all) | Operations outside the list are refused. |
| Read-only-forever groups | AZURE_PROTECTED_RESOURCE_GROUPS |
(none) | Readable, never mutable. |
| Approved regions | AZURE_LOCATION_ALLOWLIST |
(any) | New resource groups may only be created here. |
| Can it delete? | AZURE_ALLOW_DELETE |
false |
Deletes need this and admin mode. |
| Typed confirmation | AZURE_REQUIRE_CONFIRMATION |
true |
Deletes require confirm to equal the target name — not just a boolean. |
| Preview | AZURE_DRY_RUN |
false |
Write/admin tools validate + log intent, then return. |
| Audit trail | AZURE_AUDIT_LOG |
true |
JSON line to stderr per guarded operation. |
Tools
Read (read-only+): list_subscriptions, list_locations, list_resource_groups, list_resources, get_resource
Write (read-write+): create_resource_group, tag_resource, control_vm
Admin (admin): delete_resource_group, delete_resource (both need AZURE_ALLOW_DELETE + typed confirm)
Quickstart — add to your agent
Published on npm as @dockndevai/mcp-azure. Runs via npx with an Entra ID service principal. See docs/CLIENTS.md for every client and .env.example for all variables.
Claude Code
claude mcp add azure -e AZURE_TENANT_ID="…" -e AZURE_CLIENT_ID="…" -e AZURE_CLIENT_SECRET="…" -e AZURE_SUBSCRIPTION_ID="…" -e AZURE_MODE="read-only" -- npx -y @dockndevai/mcp-azure
Claude Desktop · Cursor · Windsurf
{
"mcpServers": {
"azure": {
"command": "npx",
"args": ["-y", "@dockndevai/mcp-azure"],
"env": {
"AZURE_TENANT_ID": "…",
"AZURE_CLIENT_ID": "…",
"AZURE_CLIENT_SECRET": "…",
"AZURE_SUBSCRIPTION_ID": "…",
"AZURE_MODE": "read-only"
}
}
}
}
Example prompts
- "List all resource groups in my subscription and which region each is in"
- "Show every resource in the rg-web group"
- "Tag the app-plan resource with env=prod and owner=team-a" (needs read-write)
- "Stop the build-agent VM in rg-ci" (needs read-write)
Run from source (development)
npm install
npm run build
node dist/index.js # with the environment variables set
Develop
npm run dev
npm test # governance policy: modes, scoping, location allowlist, delete + confirmation
npm run typecheck
Publishing
Ships a server.json for the official MCP registry and an mcpName for npm ownership validation. See PUBLISHING.md.
License
MIT
Instalación
Añade mcp azure a tu cliente. Elige el que uses.
claude mcp add mcp-azure -- npx -y @dockndevai/mcp-azurecodex mcp add mcp-azure -- npx -y @dockndevai/mcp-azureamp mcp add mcp-azure -- npx -y @dockndevai/mcp-azure{
"mcpServers": {
"mcp-azure": {
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"mcp-azure": {
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"mcp-azure","command":"npx","args":["-y","@dockndevai/mcp-azure"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"mcp-azure": {
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"mcp-azure": {
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"mcp-azure": {
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"mcp-azure": {
"type": "local",
"command": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"mcp-azure": {
"command": {
"path": "npx",
"args": [
"-y",
"@dockndevai/mcp-azure"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y @dockndevai/mcp-azureRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
Puntuación
39 / 100
Incompleta
- Documentación25/25
- Mantenimiento25/25
- Confianza13/20
- Capacidad0/15
- Instalación12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 2 days ago
- Has a release history
- Repository is not archived
- Licensed MIT
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Historial de versiones
| Versiones | Publicada |
|---|---|
| 0.1.2Última | 30 ago 2026 |
| 0.1.1 | 28 ago 2026 |
| 0.1.0 | 23 ago 2026 |