Atlas / MCP servers / mafzaal / D365FO Client

D365FO ClientCAUTION

mcp/mafzaal/d365fo-client

A comprehensive Python client library and MCP server for Microsoft Dynamics 365 Finance & Operations (D365 F&O) that provides easy access to OData endpoints, metadata operations, label management, and AI assistant integration.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
49 32r · 14w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Production-ready Model Context Protocol (MCP) server that exposes the full capabilities of Microsoft Dynamics 365 Finance & Operations (D365 F&O) to AI assistants and other MCP-compatible tools. This enables sophisticated Dynamics 365 integration workflows through standardized protocol interactions.

[](https://github.com/mafzaal/d365fo-client/watchers) [](https://github.com/mafzaal/d365fo-client/fork) [](https://github.com/mafzaal/d365fo-client/stargazers)

🚀 One-Click Installation for VS Code:

[](https://vscode.dev/redirect/mcp/install?name=d365fo&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22--from%22%2C%22d365fo-client%40latest%22%2C%22d365fo-fastmcp-server%22%5D%2C%22env%22%3A%7B%22D365FOCLIENTID%22%3A%22%24%7Binput%3Aclientid%7D%22%2C%22D365FOCLIENTSECRET%22%3A%22%24%7Binput%3Aclientsecret%7D%22%2C%22D365FOTENANTID%22%3A%22%24%7Binput%3Atenantid%7D%22%7D%7D&inputs=%5B%7B%22id%22%3A%22tenantid%22%2C%22type%22%3A%22promptString%22%2C%22description%22%3A%22The%20ID%20of%20the%20tenant%20to%20connect%20to%22%2C%22password%22%3Atrue%7D%2C%7B%22id%22%3A%22clientid%22%2C%22type%22%3A%22promptString%22%2C%22description%22%3A%22The%20ID%20of%20the%20client%20to%20connect%20to%22%2C%22password%22%3Atrue%7D%2C%7B%22id%22%3A%22clientsecret%22%2C%

Read from source at commit 7f67cecf4d07OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add d365fo-client --env D365FO_CLIENT_SECRET=${D365FO_CLIENT_SECRET} --env D365FO_CLIENT_SECRET=${D365FO_CLIENT_SECRET} -- uvx d365fo-client==0.3.7
claude-code (oci)
claude mcp add d365fo-client:0.3.6 --env D365FO_CLIENT_SECRET=${D365FO_CLIENT_SECRET} --env D365FO_CLIENT_SECRET=${D365FO_CLIENT_SECRET} -- docker run -i --rm ghcr.io/mafzaal/d365fo-client:0.3.6:None
03

Exposed tools (49)

32 read · 14 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
d365fo_call_actionwriteExecute an OData action method in D365 Finance & Operations.
d365fo_call_json_servicereadCall a D365 F&O JSON service endpoint using the /api/services pattern.
d365fo_cancel_syncwriteCancel a running sync session. Only sessions that are currently running and marked as cancellable can be cancelled.
d365fo_clone_profilereadClone an existing D365FO environment profile with optional modifications.
d365fo_create_entity_recordwriteCreate a new record in a D365 Finance & Operations data entity.
d365fo_create_profilewriteCreate a new D365FO environment profile with full configuration options.
d365fo_delete_entity_recorddestructiveDelete a record from a D365 Finance & Operations data entity.
d365fo_delete_profiledestructiveDelete a D365FO environment profile.
d365fo_download_customer_invoicereadDownload a customer invoice report as PDF from D365 Finance & Operations.
d365fo_download_debit_credit_notereadDownload a debit/credit note report as PDF from D365 Finance & Operations.
d365fo_download_free_text_invoicereadDownload a free text invoice report as PDF from D365 Finance & Operations.
d365fo_download_purchase_orderwriteDownload a purchase order report as PDF from D365 Finance & Operations.
d365fo_download_sales_confirmationreadDownload a sales confirmation report as PDF from D365 Finance & Operations.
d365fo_download_srs_reportreadDownload SQL Server Reporting Services (SSRS/SRS) reports from D365 Finance & Operations as PDF files.
d365fo_execute_sql_querywriteExecute a SELECT query against the D365FO metadata database to get insights from cached metadata.
d365fo_export_profilesreadExport all D365FO environment profiles to a file.
d365fo_get_database_schemareadGet comprehensive schema information for the D365FO metadata database.
d365fo_get_database_statisticsreadGet comprehensive database statistics and analytics including:
d365fo_get_default_profilereadGet the current default D365FO environment profile.
d365fo_get_entity_recordreadGet a specific record from a D365FO data entity.
d365fo_get_entity_schemareadGet the detailed schema for a specific D365 F&O data entity, including properties, keys, and available actions.
d365fo_get_enumeration_fieldsreadGet the detailed members (fields) and their values for a specific D365 F&O enumeration.
d365fo_get_environment_inforeadGet D365FO environment information and version details.
d365fo_get_installed_modulesreadGet the list of installed modules in the D365 F&O environment with their details including name, version, module ID, publisher, and display name.
d365fo_get_labelreadGet label text by label ID.
d365fo_get_labels_batchreadGet multiple labels in a single request.
d365fo_get_profilereadGet details of a specific D365FO environment profile.
d365fo_get_profile_namesreadGet list of all D365FO environment profile names.
d365fo_get_server_configreadGet current FastMCP server configuration and feature status.
d365fo_get_server_performancereadGet FastMCP server performance statistics and health metrics.
d365fo_get_sync_historywriteGet the history of completed sync sessions including success/failure status, duration, and statistics.
d365fo_get_sync_progresswriteGet detailed progress information for a specific sync session including current phase, completion percentage, items processed, and estimated time remaining.
d365fo_get_table_inforeadGet detailed information about a specific database table including:
d365fo_import_profileswriteImport D365FO environment profiles from a file.
d365fo_list_profilesreadGet list of all available D365FO environment profiles.
d365fo_list_sync_sessionswriteGet a list of all currently active sync sessions with their status, progress, and details.
d365fo_query_entitiesreadQuery D365FO data entities with simplified filtering capabilities.
d365fo_reset_performance_statsdestructiveReset server performance statistics.
d365fo_search_actionsreadSearch for available OData actions in D365 F&O using simple keyword-based search.
d365fo_search_entitiesreadSearch for D365 F&O data entities using simple keyword-based search.
d365fo_search_enumerationsreadSearch for enumerations (enums) in D365 F&O using simple keyword-based search.
d365fo_search_profilesreadSearch D365FO environment profiles based on criteria.
d365fo_set_default_profilewriteSet the default D365FO environment profile.
d365fo_start_syncwriteStart a metadata synchronization session and return a session ID for tracking progress.
d365fo_test_connectionreadTest connection to D365FO environment.
d365fo_test_profile_connectionreadTest connection for a specific D365FO environment profile.
d365fo_update_entity_recordwriteUpdate an existing record in a D365 Finance & Operations data entity.
d365fo_update_profilewriteUpdate an existing D365FO environment profile with full configuration options.
d365fo_validate_profilereadValidate a D365FO environment profile configuration.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (7)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/d365fo_client/mcp/auth_server/auth/redirect_validation.py:64
"http://127.0.0.1:*",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
d365fo_delete_entity_record, d365fo_delete_profile, d365fo_reset_performance_stats
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/integration/test_runner.py:140
__import__(package.replace("-", "_"))
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/d365fo_client/metadata_v2/search_engine_v2.py:201
return hashlib.md5("|".join(key_parts).encode()).hexdigest()
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/d365fo_client/client.py:1797
pdf_bytes = base64.b64decode(base64_data)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/PROFILE_CONSOLIDATION_COMPLETE.md:172
**Phase 1 Successfully Completed**: The immediate issue has been resolved. The MCP server now works correctly with existing profile configurations, and both CLI and MCP have full access to all profile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/STARTUP_IMPLEMENTATION_SUMMARY.md:71
1. **Load configuration** based on environment variables
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7f67cecf4d07full audit observations/trust-audit/mcp-server/mafzaal__d365fo-client.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087f67cecf4d07CAUTIONB89first audit
06

Questions

What is the D365FO Client MCP server?

A comprehensive Python client library and MCP server for Microsoft Dynamics 365 Finance & Operations (D365 F&O) that provides easy access to OData endpoints, metadata operations, label management, and AI assistant integration.

What tools does D365FO Client expose?

49 in total: 32 read-only, 14 that write, and 3 that can delete or overwrite (d365fo_delete_entity_record, d365fo_delete_profile, d365fo_reset_performance_stats). Every one is listed on this page with its risk.

Is D365FO Client safe to connect to an agent?

With care. The audit graded it B (89/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does D365FO Client need?

It reads D365FO_CLIENT_SECRET and D365FO_MCP_API_KEY_VALUE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does D365FO Client run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as d365fo-client.

How current is this page?

The grade is for one exact copy of the source (7f67cecf4d07), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement