Σημείωμα
Η πρόσβαση σε αυτήν τη σελίδα απαιτεί εξουσιοδότηση. Μπορείτε να δοκιμάσετε να εισέλθετε ή να αλλάξετε καταλόγους.
Η πρόσβαση σε αυτήν τη σελίδα απαιτεί εξουσιοδότηση. Μπορείτε να δοκιμάσετε να αλλάξετε καταλόγους.
A Microsoft Foundry Toolbox is a named, versioned server-side bundle of hosted tool configurations, such as code interpreter, file search, image generation, MCP, and web search. Toolboxes let you manage tool configuration once in Foundry and reuse it across agents.
Agent Framework covers Toolbox consumption. Create and update Toolbox versions through the Foundry portal or the azure-ai-projects SDK.
Important
FoundryToolbox is provided by the beta agent-framework-foundry-hosting package and can change before stable release.
For a service-managed FoundryAgent, attach the Toolbox to the agent definition in Foundry.
For a hosted agent built with Microsoft Agent Framework, use AddFoundryToolboxes from Microsoft.Agents.AI.Foundry.Hosting, as shown in the following example.
Use a .NET 10 web project with implicit usings enabled, matching versions of Microsoft.Agents.AI.Foundry and Microsoft.Agents.AI.Foundry.Hosting, and DotNetEnv. Set TOOLBOX_NAME to an existing toolbox and AZURE_AI_MODEL_DEPLOYMENT_NAME to your model deployment. Foundry supplies FOUNDRY_PROJECT_ENDPOINT to the deployed host. For local model access, set AZURE_AI_PROJECT_ENDPOINT and sign in with Azure CLI. The hosting integration loads toolbox tools when FOUNDRY_PROJECT_ENDPOINT is available.
using Azure.AI.Projects;
using Azure.Identity;
using DotNetEnv;
using Microsoft.Agents.AI;
using Microsoft.Agents.AI.Foundry.Hosting;
// Load .env file if present (for local development)
Env.TraversePath().Load();
string endpoint = System.Environment.GetEnvironmentVariable("FOUNDRY_PROJECT_ENDPOINT")
?? System.Environment.GetEnvironmentVariable("AZURE_AI_PROJECT_ENDPOINT")
?? throw new InvalidOperationException(
"Neither FOUNDRY_PROJECT_ENDPOINT (platform-injected in hosted runtime) " +
"nor AZURE_AI_PROJECT_ENDPOINT (local-dev convention) is set.");
string deploymentName = FirstNonBlank(
System.Environment.GetEnvironmentVariable("AZURE_AI_MODEL_DEPLOYMENT_NAME"),
System.Environment.GetEnvironmentVariable("FOUNDRY_MODEL"),
"gpt-4o")!;
string toolboxName = FirstNonBlank(
System.Environment.GetEnvironmentVariable("TOOLBOX_NAME"),
"my-toolset")!;
var credential = new DefaultAzureCredential();
AIAgent agent = new AIProjectClient(new Uri(endpoint), credential)
.AsAIAgent(
model: deploymentName,
instructions: """
You are a helpful assistant with access to tools provided by the Foundry Toolbox.
Use the available tools to answer user questions.
If a tool is not available for a request, let the user know clearly.
""",
name: System.Environment.GetEnvironmentVariable("AGENT_NAME") ?? "hosted-toolbox-agent",
description: "Hosted agent backed by Foundry Toolbox MCP tools");
var builder = WebApplication.CreateBuilder(args);
// Register the agent and response handler
builder.Services.AddFoundryResponses(agent);
builder.Services.AddFoundryToolboxes(credential, toolboxName);
var app = builder.Build();
app.MapFoundryResponses();
app.Run();
static string? FirstNonBlank(params string?[] candidates) =>
Array.Find(candidates, candidate => !string.IsNullOrWhiteSpace(candidate));
The same hosting registration supports tools configured for per-user OAuth consent on their toolbox connections. Users still need the required permissions and consent; no separate host-registration block is needed.
For the project files and deployment instructions, see Hosted-Toolbox. For per-user consent setup, see Hosted-Toolbox-AuthPaths.
Install the packages
pip install agent-framework-foundry-hosting agent-framework-foundry --pre
FoundryToolbox is imported from agent_framework.foundry and supplied by agent-framework-foundry-hosting.
Configure the Toolbox
Set an explicit Toolbox MCP endpoint:
TOOLBOX_ENDPOINT="https://<account>.services.ai.azure.com/api/projects/<project>/toolboxes/<name>/mcp?api-version=v1"
Or let FoundryToolbox construct the endpoint:
FOUNDRY_PROJECT_ENDPOINT="https://<account>.services.ai.azure.com/api/projects/<project>"
TOOLBOX_NAME="<toolbox-name>"
The hosted-agent samples also use AZURE_AI_MODEL_DEPLOYMENT_NAME for FoundryChatClient.
Use FoundryToolbox with a hosted agent
FoundryToolbox resolves its endpoint, authenticates every MCP request with the
supplied Azure credential, forwards the Foundry per-request call ID, and
participates in the agent's connection lifecycle. In a hosted Responses agent,
create the Toolbox, its client, and its credential inside the request-scoped
agent factory. The MCP writer captures the request context when it connects, so
don't share one connected Toolbox across callers.
import asyncio
import os
from contextlib import AsyncExitStack
from types import TracebackType
from agent_framework import Agent
from agent_framework.foundry import FoundryChatClient, FoundryToolbox
from agent_framework_foundry_hosting import ResponsesHostServer
from azure.ai.agentserver.core import AgentConfig, get_request_context
from azure.identity.aio import AzureCliCredential, ManagedIdentityCredential
from dotenv import load_dotenv
def create_agent() -> Agent:
"""Create tools inside this request so the MCP writer captures its call ID."""
endpoint = os.environ["FOUNDRY_PROJECT_ENDPOINT"]
model = os.environ["AZURE_AI_MODEL_DEPLOYMENT_NAME"]
credential = (
ManagedIdentityCredential(client_id=os.environ.get("FOUNDRY_AGENT_INSTANCE_CLIENT_ID"))
if AgentConfig.from_env().is_hosted
else AzureCliCredential()
)
class RequestClient(FoundryChatClient):
async def __aenter__(self) -> RequestClient:
return self
async def __aexit__(
self, exc_type: type[BaseException] | None, exc_value: BaseException | None, traceback: TracebackType | None
) -> None:
async with AsyncExitStack() as cleanup:
cleanup.push_async_callback(credential.close)
cleanup.push_async_callback(self.project_client.close)
cleanup.push_async_callback(self.client.close)
toolbox = FoundryToolbox(credential)
client = RequestClient(
project_endpoint=endpoint,
model=model,
credential=credential,
default_headers=get_request_context().platform_headers(),
)
return Agent(
client=client,
instructions="You are a friendly assistant. Keep your answers brief.",
tools=toolbox,
)
async def main() -> None:
load_dotenv()
server = ResponsesHostServer(agent=create_agent, history_source="agent_server")
await server.run_async()
Expose Toolbox skills
A Toolbox can expose Agent Skills over MCP. Set load_tools=False when only skills should be model-visible, then add the Toolbox as a tool so its MCP session connects and use as_skills_provider() as a context provider.
import asyncio
import os
from contextlib import AsyncExitStack
from types import TracebackType
from agent_framework import Agent
from agent_framework.foundry import FoundryChatClient, FoundryToolbox
from agent_framework_foundry_hosting import ResponsesHostServer
from azure.ai.agentserver.core import AgentConfig, get_request_context
from azure.identity.aio import AzureCliCredential, ManagedIdentityCredential
from dotenv import load_dotenv
def create_agent() -> Agent:
"""Keep skill caches, credentials and the MCP writer within this request."""
endpoint = os.environ["FOUNDRY_PROJECT_ENDPOINT"]
model = os.environ["AZURE_AI_MODEL_DEPLOYMENT_NAME"]
credential = (
ManagedIdentityCredential(client_id=os.environ.get("FOUNDRY_AGENT_INSTANCE_CLIENT_ID"))
if AgentConfig.from_env().is_hosted
else AzureCliCredential()
)
class RequestClient(FoundryChatClient):
async def __aenter__(self) -> RequestClient:
return self
async def __aexit__(
self, exc_type: type[BaseException] | None, exc_value: BaseException | None, traceback: TracebackType | None
) -> None:
async with AsyncExitStack() as cleanup:
cleanup.push_async_callback(credential.close)
cleanup.push_async_callback(self.project_client.close)
cleanup.push_async_callback(self.client.close)
# tools= connects the MCP session; context_providers= reads skills from that same session.
toolbox = FoundryToolbox(credential, load_tools=False)
skills_provider = toolbox.as_skills_provider(disable_load_skill_approval=True)
client = RequestClient(
project_endpoint=endpoint,
model=model,
credential=credential,
default_headers=get_request_context().platform_headers(),
)
return Agent(
client=client,
name=os.environ.get("AGENT_NAME", "hosted-toolbox-mcp-skills"),
instructions="You are a helpful assistant.",
tools=toolbox,
context_providers=[skills_provider],
)
async def main() -> None:
load_dotenv()
server = ResponsesHostServer(agent=create_agent, history_source="agent_server")
await server.run_async()
Approval remains enabled by default for skill operations. Disable individual approvals only for trusted, unattended scenarios. Keep the Toolbox and the skills provider in the same request factory so both use the same MCP session and are disposed together.
Use a Toolbox with FoundryAgent
Attach the Toolbox to the Prompt or Hosted Agent definition in Foundry. FoundryAgent uses that stored tool configuration; passing a Toolbox client-side doesn't add it to the managed agent.
Connect through MCP with FoundryToolbox
Use FoundryToolbox with ResponsesHostServer to connect a hosted agent to the
Toolbox MCP endpoint. The wrapper authenticates MCP requests and forwards the
current hosted request's caller context for per-user identity passthrough.
Create the connection inside the agent factory so each request receives its
own caller context.
import asyncio
import os
from contextlib import AsyncExitStack
from types import TracebackType
from agent_framework import Agent
from agent_framework.foundry import FoundryChatClient, FoundryToolbox
from agent_framework_foundry_hosting import ResponsesHostServer
from azure.ai.agentserver.core import AgentConfig, get_request_context
from azure.identity.aio import AzureCliCredential, ManagedIdentityCredential
from dotenv import load_dotenv
def create_agent() -> Agent:
"""Create tools inside this request so the MCP writer captures its call ID."""
endpoint = os.environ["FOUNDRY_PROJECT_ENDPOINT"]
model = os.environ["AZURE_AI_MODEL_DEPLOYMENT_NAME"]
credential = (
ManagedIdentityCredential(client_id=os.environ.get("FOUNDRY_AGENT_INSTANCE_CLIENT_ID"))
if AgentConfig.from_env().is_hosted
else AzureCliCredential()
)
class RequestClient(FoundryChatClient):
async def __aenter__(self) -> RequestClient:
return self
async def __aexit__(
self, exc_type: type[BaseException] | None, exc_value: BaseException | None, traceback: TracebackType | None
) -> None:
async with AsyncExitStack() as cleanup:
cleanup.push_async_callback(credential.close)
cleanup.push_async_callback(self.project_client.close)
cleanup.push_async_callback(self.client.close)
toolbox = FoundryToolbox(credential)
client = RequestClient(
project_endpoint=endpoint,
model=model,
credential=credential,
default_headers=get_request_context().platform_headers(),
)
return Agent(
client=client,
instructions="You are a friendly assistant. Keep your answers brief.",
tools=toolbox,
)
async def main() -> None:
load_dotenv()
server = ResponsesHostServer(agent=create_agent, history_source="agent_server")
await server.run_async()
Set TOOLBOX_ENDPOINT, or set both FOUNDRY_PROJECT_ENDPOINT and TOOLBOX_NAME, as described in Configure the Toolbox. The sample uses AZURE_AI_MODEL_DEPLOYMENT_NAME for the model deployment.
Limitations
- MCP tools inside a Toolbox use server-side authentication through a Foundry
project_connection_id; the Agent Framework client doesn't hold the upstream MCP bearer token. - Consuming a Toolbox as an MCP server requires client-side Entra ID authentication for the Toolbox endpoint.
- Consent-flow responses such as
CONSENT_REQUIREDare handled while the agent runs, not while the Toolbox connection is created.
Samples
| Sample | Description |
|---|---|
| foundry_toolbox/main.py | FoundryToolbox with a hosted Responses agent |
| foundry_toolbox_mcp_skills/main.py | Toolbox-backed Agent Skills |
| foundry_chat_client_with_toolbox.py | Toolbox MCP consumption with MCPStreamableHTTPTool |
| foundry_chat_client_with_toolbox_skills.py | Toolbox-backed skills configuration |
| invoke_foundry_toolbox_mcp | Workflow-side MCP consumption |
Go doesn't currently expose a Foundry Toolbox helper. Configure Toolboxes through Foundry and use supported local or hosted tool declarations for Go agents.