Connect clients to your agent with the Model Context Protocol (MCP) and Agent2Agent (A2A) channels (preview)

[This article is prerelease documentation and is subject to change.]

Note

The MCP client and A2A client channels are available only in early release cycle environments. If you don't see these channels in the Add a channel dialog, your environment isn't part of the rollout yet.

The MCP client and A2A client channels let you expose a published Copilot Studio agent to applications outside of Copilot Studio.

  • MCP client: Your agent is exposed as a remote Model Context Protocol (MCP) server. MCP clients—such as development tools, IDEs, and other agent hosts—can discover the agent and call it as a tool.
  • A2A client: Your agent is exposed as an agent over the Agent2Agent (A2A) protocol. Other agents and orchestrators can send tasks to your agent and receive its responses.

Both channels use the same connection model. Copilot Studio publishes an HTTPS endpoint for the agent, and clients authenticate to that endpoint with Microsoft Entra ID on behalf of the signed-in user. Because each request carries a user identity, Copilot Studio still checks whether that user has access to the agent before it responds.

Note

Features in this article are used by agents or workflows powered by the GitHub Copilot harness.

Usage-based billing applies to using, building, testing, and evaluating agents. These actions might consume Copilot Credits. Learn more in Manage costs for agents powered by the GitHub Copilot harness.

Prerequisites

  • An agent that you published at least once. Learn more in Publish an agent.
  • Permission to create app registrations in the Microsoft Entra tenant that contains the agent, or an administrator who can create one for you.
  • An MCP client or A2A client that supports connecting to a remote MCP server or A2A agent, and that supports the OAuth 2.0 authorization code flow.

Prerequisite: Create an app registration

Before anyone can connect, create an app registration in the Microsoft Entra tenant that contains the Copilot Studio agent.

This registration identifies the MCP and A2A clients that connect to the agent and users in your tenant can sign in with their own identity. Copilot Studio still checks whether each signed-in user has access to the agent.

A single app registration can support:

  • Both MCP and A2A.
  • Multiple MCP and A2A clients.
  • Multiple Copilot Studio agents in the same tenant.

Create the registration

  1. Open the Microsoft Entra admin center.

  2. Switch to the tenant that contains the Copilot Studio agent.

  3. Go to Identity > Applications > App registrations.

  4. Select New registration.

  5. Enter a name, such as Copilot Studio MCP and A2A client.

  6. Select Accounts in this organizational directory only.

  7. Leave Redirect URI empty. Each client provides its own URI later.

  8. Select Register.

Add the Copilot Studio permissions

  1. In the app registration, select API permissions.

  2. Select Add a permission > APIs my organization uses.

  3. In the Search box, paste the following application ID:

    6f46e6ed-07bf-4616-80f0-47546850f654
    

    Searching by application ID is the most reliable way to find the API. The API appears in the results as Microsoft Copilot Studio Agent as MCP channel, and it provides the permissions for both the MCP and A2A channels. Select it.

  4. Select Delegated permissions.

  5. Add the permissions for the protocols you want to support:

    Protocol Permission in Entra Full scope URI
    MCP MCS.InvokeAsMCP https://api.powerplatform.com/copilotstudio-mcp/MCS.InvokeAsMCP
    A2A MCS.InvokeAsA2A https://api.powerplatform.com/copilotstudio-a2a/MCS.InvokeAsA2A

    The Entra permissions list shows the short name. The full scope URI is what a client sends in its token request, and it's the value you use when you configure the client.

    Note

    These values use api.powerplatform.com, which applies to production environments. If your agent is in another environment, such as a preview or preproduction environment, adjust the host to match the endpoint that Copilot Studio shows for your agent.

  6. Grant administrator consent if your tenant's policies require it.

Tip

If the API doesn't appear even when you search by application ID, open the MCP client or A2A client channel in Copilot Studio first. Opening the channel provisions the required enterprise application in the tenant. Then return to the app registration and search again.

Retain these details

Record these values from the app registration's Overview page. You need them when you configure each client.

Value How it's used
Application (client) ID Identifies the registered client during OAuth sign-in.
Directory (tenant) ID Identifies the tenant where users authenticate. Use it to build the authorization and token URLs when you configure the client.
App registration name Helps administrators locate and manage the registration.

Note

Record the Directory (tenant) ID now. You need it in Configure the client, where it replaces {tenant-id} in the authorization and token URLs. The same value also appears on the Overview page for your tenant in the Microsoft Entra admin center.

You can share the client ID and tenant ID with the people who configure approved clients. If a client also requires a client secret, create one under Certificates & secrets and record the secret Value when you create it. The value isn't shown again.

Connect a client to the agent

Copy the agent endpoint

  1. Open your published agent.

  2. Select Channels > Add a channel.

  3. Select MCP client or A2A client.

  4. Copy the URL shown in the dialog, and then select Done.

Configure the client

Add a remote MCP or A2A connection in your client. The client might request some or all of the following values.

Setting Value
Endpoint The URL you copied from Copilot Studio.
Authentication type OAuth authorization code, or OAuth identity passthrough.
Client ID The Application (client) ID from the app registration.
Client secret The secret from the app registration, if the client requires one.
Authorization URL https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/authorize
Token URL https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token
Refresh URL https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token

Replace {tenant-id} with the Directory (tenant) ID that you recorded in Retain these details.

If the client asks for a scope, use the full scope URI that matches the endpoint you're connecting to, together with offline_access.

For MCP:

https://api.powerplatform.com/copilotstudio-mcp/MCS.InvokeAsMCP offline_access

For A2A:

https://api.powerplatform.com/copilotstudio-a2a/MCS.InvokeAsA2A offline_access

Note

These scopes use api.powerplatform.com, which applies to production environments. If your agent is in another environment, such as a preview environment, adjust the host to match the endpoint you copied from the channel dialog.

Register the client's redirect URI

During or after configuration, the client provides an OAuth redirect URI. Add it to the app registration before you complete the sign-in and test calling your agent from the client.

  1. Copy the redirect URI from the client.

  2. Return to the app registration in the Microsoft Entra admin center.

  3. Select Authentication > Add a platform.

  4. Select the platform that the client specifies. Hosted clients commonly use Web.

  5. Paste the redirect URI exactly as the client provides it.

  6. Select Configure, and then select Save.

  7. Return to the client and complete or retry the connection.

When the connection succeeds, the client prompts the user to sign in with their work or school account and to consent to the requested permissions. After the user signs in, the client can call the agent.

Each client you connect from can provide a redirect URI and you can add all approved URIs to the same app registration.

Troubleshooting

Symptom What to check
The MCP client or A2A client channel isn't listed The channel is available only in early release cycle environments.
The Copilot Studio agent channel API doesn't appear in Entra Search by the application ID 6f46e6ed-07bf-4616-80f0-47546850f654 rather than by name. If it still doesn't appear, open the MCP client or A2A client channel in Copilot Studio to provision the enterprise application, then search again.
Sign-in fails with a redirect URI mismatch The redirect URI in the app registration must match the value the client provides exactly, including the scheme, port, and trailing path.
The user signs in but the agent doesn't respond Confirm the signed-in user has access to the agent, and that the agent is published. Learn more in Publish an agent.
The client is denied access to the endpoint Confirm the correct delegated permission (MCS.InvokeAsMCP or MCS.InvokeAsA2A) is added and that administrator consent is granted.