Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
[This article is prerelease documentation and is subject to change.]
Note
The MCP client and A2A client channels are available only in early release cycle environments. If you don't see these channels in the Add a channel dialog, your environment isn't part of the rollout yet.
The MCP client and A2A client channels let you expose a published Copilot Studio agent to applications outside of Copilot Studio.
- MCP client: Your agent is exposed as a remote Model Context Protocol (MCP) server. MCP clients—such as development tools, IDEs, and other agent hosts—can discover the agent and call it as a tool.
- A2A client: Your agent is exposed as an agent over the Agent2Agent (A2A) protocol. Other agents and orchestrators can send tasks to your agent and receive its responses.
Both channels use the same connection model. Copilot Studio publishes an HTTPS endpoint for the agent, and clients authenticate to that endpoint with Microsoft Entra ID on behalf of the signed-in user. Because each request carries a user identity, Copilot Studio still checks whether that user has access to the agent before it responds.
Note
Features in this article are used by agents or workflows powered by the GitHub Copilot harness.
Usage-based billing applies to using, building, testing, and evaluating agents. These actions might consume Copilot Credits. Learn more in Manage costs for agents powered by the GitHub Copilot harness.
Prerequisites
- An agent that you published at least once. Learn more in Publish an agent.
- Permission to create app registrations in the Microsoft Entra tenant that contains the agent, or an administrator who can create one for you.
- An MCP client or A2A client that supports connecting to a remote MCP server or A2A agent, and that supports the OAuth 2.0 authorization code flow.
Prerequisite: Create an app registration
Before anyone can connect, create an app registration in the Microsoft Entra tenant that contains the Copilot Studio agent.
This registration identifies the MCP and A2A clients that connect to the agent and users in your tenant can sign in with their own identity. Copilot Studio still checks whether each signed-in user has access to the agent.
A single app registration can support:
- Both MCP and A2A.
- Multiple MCP and A2A clients.
- Multiple Copilot Studio agents in the same tenant.
Create the registration
Open the Microsoft Entra admin center.
Switch to the tenant that contains the Copilot Studio agent.
Go to Identity > Applications > App registrations.
Select New registration.
Enter a name, such as
Copilot Studio MCP and A2A client.Select Accounts in this organizational directory only.
Leave Redirect URI empty. Each client provides its own URI later.
Select Register.
Add the Copilot Studio permissions
In the app registration, select API permissions.
Select Add a permission > APIs my organization uses.
In the Search box, paste the following application ID:
6f46e6ed-07bf-4616-80f0-47546850f654Searching by application ID is the most reliable way to find the API. The API appears in the results as Microsoft Copilot Studio Agent as MCP channel, and it provides the permissions for both the MCP and A2A channels. Select it.
Select Delegated permissions.
Add the permissions for the protocols you want to support:
Protocol Permission in Entra Full scope URI MCP MCS.InvokeAsMCPhttps://api.powerplatform.com/copilotstudio-mcp/MCS.InvokeAsMCPA2A MCS.InvokeAsA2Ahttps://api.powerplatform.com/copilotstudio-a2a/MCS.InvokeAsA2AThe Entra permissions list shows the short name. The full scope URI is what a client sends in its token request, and it's the value you use when you configure the client.
Note
These values use
api.powerplatform.com, which applies to production environments. If your agent is in another environment, such as a preview or preproduction environment, adjust the host to match the endpoint that Copilot Studio shows for your agent.Grant administrator consent if your tenant's policies require it.
Tip
If the API doesn't appear even when you search by application ID, open the MCP client or A2A client channel in Copilot Studio first. Opening the channel provisions the required enterprise application in the tenant. Then return to the app registration and search again.
Retain these details
Record these values from the app registration's Overview page. You need them when you configure each client.
| Value | How it's used |
|---|---|
| Application (client) ID | Identifies the registered client during OAuth sign-in. |
| Directory (tenant) ID | Identifies the tenant where users authenticate. Use it to build the authorization and token URLs when you configure the client. |
| App registration name | Helps administrators locate and manage the registration. |
Note
Record the Directory (tenant) ID now. You need it in Configure the client, where it replaces {tenant-id} in the authorization and token URLs. The same value also appears on the Overview page for your tenant in the Microsoft Entra admin center.
You can share the client ID and tenant ID with the people who configure approved clients. If a client also requires a client secret, create one under Certificates & secrets and record the secret Value when you create it. The value isn't shown again.
Connect a client to the agent
Copy the agent endpoint
Open your published agent.
Select Channels > Add a channel.
Select MCP client or A2A client.
Copy the URL shown in the dialog, and then select Done.
Configure the client
Add a remote MCP or A2A connection in your client. The client might request some or all of the following values.
| Setting | Value |
|---|---|
| Endpoint | The URL you copied from Copilot Studio. |
| Authentication type | OAuth authorization code, or OAuth identity passthrough. |
| Client ID | The Application (client) ID from the app registration. |
| Client secret | The secret from the app registration, if the client requires one. |
| Authorization URL | https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/authorize |
| Token URL | https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token |
| Refresh URL | https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token |
Replace {tenant-id} with the Directory (tenant) ID that you recorded in Retain these details.
If the client asks for a scope, use the full scope URI that matches the endpoint you're connecting to, together with offline_access.
For MCP:
https://api.powerplatform.com/copilotstudio-mcp/MCS.InvokeAsMCP offline_access
For A2A:
https://api.powerplatform.com/copilotstudio-a2a/MCS.InvokeAsA2A offline_access
Note
These scopes use api.powerplatform.com, which applies to production environments. If your agent is in another environment, such as a preview environment, adjust the host to match the endpoint you copied from the channel dialog.
Register the client's redirect URI
During or after configuration, the client provides an OAuth redirect URI. Add it to the app registration before you complete the sign-in and test calling your agent from the client.
Copy the redirect URI from the client.
Return to the app registration in the Microsoft Entra admin center.
Select Authentication > Add a platform.
Select the platform that the client specifies. Hosted clients commonly use Web.
Paste the redirect URI exactly as the client provides it.
Select Configure, and then select Save.
Return to the client and complete or retry the connection.
When the connection succeeds, the client prompts the user to sign in with their work or school account and to consent to the requested permissions. After the user signs in, the client can call the agent.
Each client you connect from can provide a redirect URI and you can add all approved URIs to the same app registration.
Troubleshooting
| Symptom | What to check |
|---|---|
| The MCP client or A2A client channel isn't listed | The channel is available only in early release cycle environments. |
| The Copilot Studio agent channel API doesn't appear in Entra | Search by the application ID 6f46e6ed-07bf-4616-80f0-47546850f654 rather than by name. If it still doesn't appear, open the MCP client or A2A client channel in Copilot Studio to provision the enterprise application, then search again. |
| Sign-in fails with a redirect URI mismatch | The redirect URI in the app registration must match the value the client provides exactly, including the scheme, port, and trailing path. |
| The user signs in but the agent doesn't respond | Confirm the signed-in user has access to the agent, and that the agent is published. Learn more in Publish an agent. |
| The client is denied access to the endpoint | Confirm the correct delegated permission (MCS.InvokeAsMCP or MCS.InvokeAsA2A) is added and that administrator consent is granted. |