Azure DevOps Advanced
Delivery context, not just API calls.
Repositories, pull requests, boards, pipelines, tests, wiki, and security with compound engineering insights.
Azure DevOps Advanced is a Quilr-built MCP for Azure DevOps Services (dev.azure.com). It provides 47 tools across organizations, projects, Azure Repos, pull requests, Boards, Pipelines, Test Plans, Wiki, Search and Advanced Security. Each user signs in with their own Microsoft account through Microsoft Entra delegated OAuth, so Azure DevOps applies that user's existing permissions.
MCP client -> QuilrAI Gateway -> Azure DevOps MCP -> Microsoft Entra -> Azure DevOps
This MCP covers cloud-hosted Azure DevOps Services. It does not cover Azure DevOps Server hosted on your own network.
Tools
Direct tools cover frequent operations with explicit schemas. Dispatcher tools group related operations behind an action selector. Intelligence tools combine several API calls into one briefing. Destructive tools always require an exact confirmation phrase.
Organization and common direct tools
Compatibility dispatcher tools
Intelligence tools
Destructive tools
These tools are marked destructive, are not retried automatically, and reject the request unless the exact confirmation value is supplied. Keep them disabled in Tool visibility unless the workflow is explicitly approved.
Organization selection
Organization arguments are optional on organization-scoped tools:
- With one linked organization, the MCP selects and saves it automatically.
- With several organizations and no saved selection, a tool returns
organization_selection_requiredwith the choices. - Call
ado_select_organizationwith the exact URL-name segment, such ascontosofromhttps://dev.azure.com/contoso. Do not pass a full URL or a display label. - An organization passed directly to another tool is a one-call override and does not replace the saved selection.
The selection is stored per signed-in user. Access and refresh tokens are not stored with it.
Setup
The MCP uses a Microsoft Entra application with the delegated user_impersonation permission for Azure DevOps. It does not use the deprecated Azure DevOps OAuth app registration, which stopped accepting new apps in April 2025.
1. Create the Microsoft Entra application
If Quilr already provides a managed Entra application for your tenant, skip this step and ask your tenant administrator to approve it.
- In the Microsoft Entra admin center, open Entra ID > App registrations > New registration.
- Enter a name such as
QuilrAI Azure DevOps MCP. - Choose Accounts in this organizational directory only for a single-tenant deployment, or Accounts in any organizational directory only for an approved multi-tenant deployment.
- Under Redirect URI, select Web and enter
https://azure-devops.mcp.quilr.ai/auth/callback. Click Register. - From Overview, copy the Application (client) ID and Directory (tenant) ID. For an approved multi-tenant application, use
organizationsinstead of a tenant ID. - Open API permissions > Add a permission > APIs my organization uses, select Azure DevOps, then under Delegated permissions enable
user_impersonation. - Grant tenant-wide admin consent if your consent policy requires it. Otherwise users are prompted when they connect.
- Open Certificates & secrets > Client secrets > New client secret, then copy the secret Value (not the Secret ID).
Microsoft shows the client secret value only once. Store it in your approved secret manager and hand it to Quilr through the authorized onboarding channel. Never put it in an MCP client file, chat, ticket, repository or URL.
The service requests these scopes. 499b84ac-1321-427f-aa17-267ca6975798 is the Azure DevOps resource ID.
499b84ac-1321-427f-aa17-267ca6975798/user_impersonation
openid
profile
offline_access
2. Check Azure DevOps prerequisites
- The Azure DevOps organization is connected to the intended Entra tenant.
- Each user is a member or guest of every organization they need, with project permissions for the tools they will call.
- Advanced Security, Test Plans, Pipelines and Wiki are enabled and licensed where those tools are needed.
- Tenant consent and Conditional Access policies permit the Entra application.
3. Add the server to the MCP Gateway
- Go to Settings > AI Gateway > MCP Gateway and click Add MCP server. Choose Remote server.
- Enter Name
Azure DevOps Advanced, a Slug such asazure-devops, and Transport URLhttps://azure-devops.mcp.quilr.ai/mcp. - Under How the gateway signs in, keep Auto-detect (recommended), click Probe and continue and finish the steps to Create MCP.
- Connect OAuth once as an administrator with a Microsoft account that can reach the organization, and accept the requested permissions. The server should list 47 tools.
- In Configure, review Tool visibility, Server access and Security guardrails before users connect.
Do not enter the Entra client secret in Cursor, Claude, ChatGPT or any other client. The upstream MCP service owns it.
4. Connect a client and verify
Point clients at the server's Quilr gateway URL, never the upstream URL. A short key such as ado keeps combined server and tool names compact:
{
"mcpServers": {
"ado": {
"type": "http",
"url": "https://mcpgateway.quilr.ai/YOUR-AZURE-DEVOPS-SLUG/mcp"
}
}
}
For Claude, add a custom connector with the same URL and leave its OAuth Client ID and Client Secret fields empty. Start with a read-only prompt:
Use the Azure DevOps MCP. First call ado_list_organizations. If there is one
organization, use it automatically. If there are multiple, show me the choices
and wait for my selection. Then list the first 20 projects. Do not create,
update, run, vote, comment, or delete anything.
Reconnection
Routine redeployments do not require users to sign in again while the public MCP and callback URLs, the Entra tenant and application, the OAuth signing key and the stored OAuth and organization state stay the same. Users must reconnect after the client secret expires or rotates without a service update, consent is revoked, scopes change, refresh fails permanently, OAuth state is lost, the public resource URL changes, or the Entra application is replaced.
Organization membership is refreshed automatically. A routine restart can refresh linked organizations without the user signing in again.
Troubleshooting
References: Entra OAuth for Azure DevOps, Azure DevOps OAuth deprecation, Microsoft Azure DevOps MCP source.
Compared with the official server
Choose official for local IDE work
Use Microsoft's server when developers need first-party Azure DevOps operations directly inside a supported local coding environment.
- Excellent IDE-native workflow
- First-party core domain coverage
Choose Quilr for organization-wide access
Use Quilr when teams need one hosted endpoint with delegated OAuth, gateway policy, compound delivery intelligence, and controlled destructive actions.
- Remote multi-tenant operation
- Briefs, dashboards, and confirmed deletes
The official server is excellent for local IDE use. Quilr Advanced is designed for organization-wide access through gateway policy and auditing.