Back to Directory/Cloud Providers

io.github.dockndevai/mcp-azure-devops

Azure DevOps boards, repos, pipelines & projects for AI agents — governed.

Cloud ProvidersTypeScriptv0.3.0

mcp-azure-devops

CI License: MIT npm

A Model Context Protocol server for Azure DevOps. It lets an MCP-capable client (Claude Desktop, Claude Code, Cursor, Codex, …) work across boards, repos, pipelines, and projects — with a governance layer that keeps an AI agent inside safe boundaries.

What this offers

  • Projects & teams — list projects/teams/members, inspect process templates.
  • Boards / work items — WIQL queries, get work items, create/update work items, list iterations (sprints).
  • Repos / pull requests — list repositories and branches, list/get PRs, open PRs.
  • Pipelines / builds — list pipelines and recent builds, get a build, queue a run.
  • Admin / process — list process templates, create a project, delete a project (guarded).
  • Governance built in — access modes, project allowlists, protected projects, delete gating, typed confirmation for high-impact ops, dry-run, and JSON audit logging.

Governance & security model

ConcernFlagDefaultEffect
What can the server do?AZDO_MODEread-onlyread-only → reads; read-write → work items, PRs, pipeline runs; admin → create/delete project. Tools above the mode are never registered.
Which projects are in scope?AZDO_PROJECT_ALLOWLIST(all)Operations on other projects are refused.
Which projects are read-only forever?AZDO_PROTECTED_PROJECTS(none)Readable, never mutable.
Can it delete?AZDO_ALLOW_DELETEfalsedelete_project needs this and admin mode.
Typed confirmationAZDO_REQUIRE_CONFIRMATIONtrueHigh-impact ops require confirm to equal the target name — not just a boolean.
PreviewAZDO_DRY_RUNfalseWrite/admin tools validate + log intent, then return.
Audit trailAZDO_AUDIT_LOGtrueJSON line to stderr per guarded operation.
Interactive confirmation(automatic)—Destructive & high-impact actions prompt the human to approve via MCP elicitation before running; clients without elicitation fall back to the *_ALLOW_* gate.

Tools

Read (read-only+): list_projects, get_project, list_teams, list_team_members, list_processes, query_work_items, get_work_item, list_iterations, list_repositories, list_branches, list_pull_requests, get_pull_request, list_pipelines, list_builds, get_build

Write (read-write+): create_work_item, update_work_item, create_pull_request, run_pipeline

Admin (admin): create_project, delete_project (needs AZDO_ALLOW_DELETE + typed confirm)

Quickstart — add to your agent

Published on npm as @dockndevai/mcp-azure-devops. Runs via npx; needs an org and a PAT. See docs/CLIENTS.md for every client and .env.example for all variables.

Claude Code

claude mcp add azure-devops -e AZDO_ORG_URL="https://dev.azure.com/your-org" -e AZDO_PAT="your-pat" -e AZDO_MODE="read-only" -- npx -y @dockndevai/mcp-azure-devops

Claude Desktop · Cursor · Windsurf

{
  "mcpServers": {
    "azure-devops": {
      "command": "npx",
      "args": ["-y", "@dockndevai/mcp-azure-devops"],
      "env": {
        "AZDO_ORG_URL": "https://dev.azure.com/your-org",
        "AZDO_PAT": "your-pat",
        "AZDO_MODE": "read-only"
      }
    }
  }
}

Example prompts

  • "List active pull requests in the Payments project's api repo"
  • "Query work items assigned to me that are still Active"
  • "Show the last 10 builds in the Web project and which failed"
  • "Create a Bug in Payments titled 'Checkout 500 on retry'" (needs read-write)

Run from source (development)

npm install
npm run build
node dist/index.js   # with the environment variables set

Develop

npm run dev
npm test          # governance policy: modes, allowlists, delete gating, confirmation
npm run typecheck

Publishing

Ships a server.json for the official MCP registry and an mcpName for npm ownership validation. See PUBLISHING.md.

License

MIT

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y @dockndevai/mcp-azure-devops

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "io-github-dockndevai-mcp-azure-devops": {
      "command": "npx",
      "args": [
        "-y",
        "@dockndevai/mcp-azure-devops"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

@dockndevai/mcp-azure-devopsnpm

Compatible MCP Clients

io.github.dockndevai/mcp-azure-devops works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More