Azure DevOpsCAUTION
An MCP server for Azure DevOps
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server implementation for Azure DevOps, allowing AI assistants to interact with Azure DevOps APIs through a standardized protocol.
Looking for the official server? Microsoft maintains a product-supported Azure DevOps MCP at microsoft/azure-devops-mcp. If you use Azure DevOps Services (cloud), start there. This community server remains a good fit when you need Azure DevOps Server (on-premises) support — especially older versions that may not work with Microsoft's MCP — or features not yet available in the official server. See Discussion #237 for more context. See ROADMAP.md for where this server differentiates and what is planned.
Overview
This server implements the Model Context Protocol (MCP) for Azure DevOps, enabling AI assistants like Claude to interact with Azure DevOps resources securely. The server acts as a bridge between AI models and Azure DevOps APIs, providing a standardized way to:
- Access and manage projects, work items, repositories, and more
- Create and update work items, branches, and pull requests
- Execute common DevOps workflows through natural language
- Access repository content via standardized resource URIs
- Safely authenticate and interact with Azure DevOps resources
Server Structure
The server is structured around the Model Context Protocol (MCP) for communicating with AI assistants. It provides tools for interacting with Azure DevOps resources including:
- Projects
- Work Items
- Repositories
- Pull Requests
- Branches
- Pipelines
Core Components
- AzureDevOpsServer: Main server class that initializes the MCP server and registers tools
- Feature Modules: Organized by feature area (work-items, projects, repositories, etc.)
- Request Handlers: Each feature module
f11663873237OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-azure-devops --env AZURE_DEVOPS_AUTH_METHOD=${AZURE_DEVOPS_AUTH_METHOD} -- npx -y @tiberriver256/[email protected]{
"mcpServers": {
"mcp-server-azure-devops": {
"command": "npx",
"args": [
"-y",
"@tiberriver256/[email protected]"
],
"env": {
"AZURE_DEVOPS_AUTH_METHOD": "${AZURE_DEVOPS_AUTH_METHOD}"
}
}
}
}Exposed tools (49)
31 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Agile | read | Agile process |
Bug | read | Tracks defects in the product |
add_pull_request_comment | write | Add a comment to a pull request (repositoryId optional; derived from pullRequestId when omitted) |
create_branch | write | Create a new branch from an existing one |
create_pull_request | write | Create a new pull request, including reviewers, linked work items, and optional tags |
create_wiki | write | Create a new wiki in the project |
create_wiki_page | write | Create a new page in a wiki. If the page already exists at the specified path, it will be updated. |
create_work_item | write | Create a new work item |
create_work_item_attachment | write | Upload a file and attach it to a work item. The file is read from the local filesystem, uploaded to Azure DevOps, and linked to the specified work item. |
delete_work_item_attachment | destructive | Delete an attachment from a work item. The attachment ID can be obtained from the work item relations. |
download_pipeline_artifact | write | Download a file from a pipeline run artifact and return its textual content |
get_all_repositories_tree | read | Displays a hierarchical tree view of files and directories across multiple Azure DevOps repositories within a project, based on their default branches |
get_file_content | read | Get content of a file or directory from a repository |
get_me | read | Get details of the authenticated user (id, displayName, email) |
get_pipeline | read | Get details of a specific pipeline |
get_pipeline_log | read | Retrieve a specific pipeline log using the timeline log identifier |
get_pipeline_run | write | Get details for a specific pipeline run |
get_project | read | Get details of a specific project |
get_project_details | read | Get comprehensive details of a project including process, work item types, and teams |
get_pull_request | read | Get a pull request by ID (no repositoryId required; best for Azure DevOps Server where PR IDs are project-scoped) |
get_pull_request_changes | read | Get the files changed in a pull request, their unified diffs, source/target branch names, and the status of policy evaluations |
get_pull_request_comments | read | Get comments from a specific pull request |
get_repository | read | Get details of a specific repository |
get_repository_details | read | Get detailed information about a repository including statistics and refs |
get_repository_tree | read | Displays a hierarchical tree view of files and directories within a single repository starting from an optional path |
get_wiki_page | read | Get the content of a wiki page |
get_wikis | read | Get details of wikis in a project |
get_work_item | read | Get details of a specific work item |
get_work_item_attachment | write | Download an attachment from Azure DevOps and save it to the local filesystem. The attachment ID can be obtained from the work item relations. |
get_work_item_comments | read | Get comments and discussion history for a specific work item |
list_commits | read | List recent commits on a branch including file-level diff content for each commit |
list_organizations | read | List all Azure DevOps organizations accessible to the current authentication |
list_pipeline_runs | read | List recent runs for a pipeline |
list_pipelines | read | List pipelines in a project |
list_projects | read | List all projects in an organization |
list_pull_requests | read | List pull requests in a repository |
list_repositories | read | List repositories in a project |
list_wiki_pages | read | List pages within an Azure DevOps wiki |
list_work_items | read | List work items in a project |
manage_work_item_link | destructive | Add or remove links between work items |
pipeline_timeline | write | Retrieve the timeline of stages and jobs for a pipeline run, to reduce the amount of data returned, you can filter by state and result |
search_code | read | Search for code across repositories in a project |
search_wiki | read | Search for content across wiki pages in a project |
search_work_items | read | Search for work items across projects in Azure DevOps |
trigger_pipeline | write | Trigger a pipeline run |
update_pull_request | write | Update an existing pull request with new properties, manage reviewers and work items, and add or remove tags |
update_pull_request_thread_status | write | Update the status of a comment thread in a pull request (repositoryId optional; derived from pullRequestId when omitted) |
update_wiki_page | write | Update content of a wiki page |
update_work_item | write | Update an existing work item |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (13)
.mockResolvedValue({ token: 'mock-azure-identity-token' }),delete_work_item_attachment, manage_work_item_link
.clinerules
.oxfmtrc.json
.oxlintrc.json
return createHash('sha1').update(text).digest('hex');import { AzureDevOpsConfig } from '../../../shared/types';import { AuthenticationMethod } from '../../../shared/auth';import { AuthenticationMethod } from '../../shared/auth';} from '../../shared/types/request-handler';
import { AzureDevOpsConfig } from '../../shared/types';@azure/identity, @modelcontextprotocol/sdk, axios, azure-devops-node-api, diff, dotenv, jszip, minimatch
- Used in [`src/index.ts`](src/index.ts:1) to load environment variables from a `.env` file.
Gates applied: no_behavioural_pass.
f11663873237full audit observations/trust-audit/mcp-server/tiberriver256__azure-devops-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | f11663873237 | CAUTION | B | 87 | first audit |
Questions
What is the Azure DevOps MCP server?
An MCP server for Azure DevOps
What tools does Azure DevOps expose?
49 in total: 31 read-only, 16 that write, and 2 that can delete or overwrite (delete_work_item_attachment, manage_work_item_link). Every one is listed on this page with its risk.
Is Azure DevOps safe to connect to an agent?
With care. The audit graded it B (87/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Azure DevOps need?
It reads AZURE_DEVOPS_AUTH_METHOD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Azure DevOps run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tiberriver256/mcp-server-azure-devops at 0.1.48.
How current is this page?
The grade is for one exact copy of the source (f11663873237), read on 2026-10-02. The repository is watched and re-audited when it changes.