Repository navigation
Conversation
|
📁 PR Artifacts Notice This PR contains a |
enyst
left a comment
There was a problem hiding this comment.
I'm an AI agent (Claude Code, based on Opus 5.5) helping Engel Nyst (@enyst) with project work.
Of the two Azure DevOps PRs, this is the one to take forward, and #384 should be closed in its favour. This PR is based on current main and passes the current schema. Its connection details match Microsoft's docs and the live OAuth metadata, which #384's do not. I'm leaving a comment rather than approving only because the PR is still a draft and the process gates are open.
To make it mergeable:
- Write the
HUMAN:note. It still has the template placeholder, soValidate PR descriptionwill fail once the PR is marked ready. - Link an issue in this repo that has
ready-for-dev. OpenHands/OpenHands#15769 is in another repo, so the checker can't see it. As written, it would read the bare#384in that section as the linked issue. - The required
test,sync-extensionsandvalidate-claude-codechecks haven't run on this fork head yet.
Minor, non-blocking:
- azure-devops.json#L71: the link uses the anchor
#personal-access-token-pat, which doesn't exist in GETTINGSTARTED.md. The heading is### Personal Access Token, so the anchor should be#personal-access-token. - tests/test_catalogs.py#L125 pins the full transport and some of the
noteswording. A later copy edit to the entry would then need a second file changed. This is optional, but you could cut the test down to the regression you care about (strategy-only OAuth and the PAT args), since the schema tests already check the entry's shape.
Checked:
- In the
microsoft/azure-devops-mcpsource,--authentication patis a valid choice. It readsPERSONAL_ACCESS_TOKENas base64 of<email>:<PAT>, and yargs accepts the organization positional after the flags. The latest@azure-devops/mcpis 2.10.0, published 2026-09-09. Node 20+ is the documented requirement. - Microsoft's remote-server docs accept both
https://mcp.dev.azure.com/and/{organization}. They require a custom Entra app registration and say Entra doesn't support DCR. Thenotesfield reflects all of this accurately. - The public
/.well-known/oauth-protected-resourcelists the scopehttps://mcp.dev.azure.com/.defaultand the authorization serverlogin.microsoftonline.com/organizations/v2.0. - The JSON validates against main's schema, and
catalog-index.jsmatches the build script's output. Main's catalog tests pass with the entry and icon added (117). - Not verified: Entra login and authenticated PAT tool calls.
HUMAN:
AGENT:
Adds the missing Azure DevOps catalog entry and verifies the real published MCP command, package exports, and current Canvas adapter. Authenticated Azure resource calls and Entra login remain unverified.
Why
Azure DevOps is absent from the integration catalog, so clients cannot discover its official MCP server. The issue's proposed configuration names a different npm package and unsupported catalog fields. The hosted server also needs MCP OAuth discovery and a registered Entra client, rather than hard-coded Azure DevOps REST API OAuth scopes.
Summary
@azure-devops/mcpPAT stdio connection with required organization and base64-encodedPERSONAL_ACCESS_TOKENinputs..pr/.Issue Number
Refs OpenHands/OpenHands#15769.
Related existing proposal: #384. This independent branch uses current main and the current strict schema. It avoids hard-coded Entra endpoints and the REST API token audience; the live MCP resource advertises
https://mcp.dev.azure.com/.default.How to Test
Observed locally on Windows, Python 3.13 and Node 24:
core_list_projectsand work-item tools. This uses a synthetic PAT and performs no authenticated Azure API calls.scripts/sync_extensions.py --checkandgit diff --checkpassed. The sync script reported three existing non-blocking coverage warnings.Details, inspected revisions, and reproducible smoke scripts: investigation.
Video/Screenshots
No UI source changes. Package, actual Canvas adapter, and MCP protocol evidence are recorded in
.pr/analysis.md.Notes
This is the extensions-owned catalog portion. Current Canvas skips strategy-only OAuth options in its marketplace modal and selects the PAT option. The catalog documents remote setup through the custom MCP editor, where the registered client ID can be supplied. It does not claim one-click hosted OAuth or a completed authenticated Azure smoke test.
After an extensions release containing this entry, Canvas needs its normal package/lockfile dependency update. A generic marketplace flow for OAuth client inputs and connection-option selection belongs in Canvas. Real project/work-item calls and OAuth login require a reviewer-owned Azure organization, PAT, and Entra app registration.
Kept draft under the repository template; the HUMAN section is untouched.