PluginBench
MCP Server
Maintained
MIT

io.github.kaael1/mcp-power-automate MCP Server

io.github.kaael1/mcp-power-automate

Inspect, validate, edit, and revert Power Automate flows with AI agents using browser-backed auth and local snapshots.

What is the io.github.kaael1/mcp-power-automate MCP server?

The MCP Power Automate server is a local-first MCP that lets AI agents inspect, validate, edit, run, review, and revert Microsoft Power Automate cloud flows using your existing browser session. It requires no Microsoft Entra ID app registration and keeps all state and backups on your machine, with built-in safety features like preview, validation, and rollback.

This server bridges AI agents to Power Automate by capturing your logged-in browser session and exposing a command surface for flow inspection, safe editing with diff review, run debugging, and Dataverse solution management. It's designed for supervised AI work on real flows, with explicit safeguards: preview before save, validate before and after edits, review diffs, and revert when needed.

How to install io.github.kaael1/mcp-power-automate

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-power-automate": {
      "command": "npx",
      "args": [
        "-y",
        "@kaael1/mcp-power-automate"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • get_context — Detect browser-captured flows and check readiness status.
  • doctor — Validate MCP and extension setup.
  • connect_flow — Explicitly lock onto a target flow.
  • list_flows — List available Power Automate flows.
  • get_flow — Read the full definition of a flow.
  • preview_flow_update — Preview the smallest candidate update before saving.
  • validate_flow — Validate flow definition against Power Automate schema.
  • apply_flow_update — Save flow changes.
  • get_last_update — Review the diff of the last saved change.
  • revert_last_update — Revert the most recent flow update.
  • list_runs — Inspect recent flow runs.
  • get_latest_run — Get details of the latest run.
  • get_run — Get details of a specific run.
  • get_run_actions — Inspect action-level failures in a run.
  • wait_for_run — Wait for a flow run to complete.
  • invoke_trigger — Invoke safe manual or request trigger flows.
  • get_trigger_callback_url — Get the callback URL for a trigger.
  • list_solutions — List unmanaged Dataverse solutions.
  • list_solution_components — Inspect solution components.
  • list_environment_variables — List environment variables in a solution.

Use cases

  • Safely edit Power Automate flows with AI assistance while reviewing all changes before they go live.
  • Debug flow runs by inspecting recent executions and action-level failures to identify issues.
  • Test flows by invoking manual or request triggers and waiting for results without manual intervention.
  • Manage Dataverse solutions by adding flows to unmanaged solutions and inspecting solution components.
  • Revert problematic flow changes instantly using rollback when an edit produces unexpected results.

io.github.kaael1/mcp-power-automate MCP server FAQ

What is the MCP Power Automate server?

It's a local MCP server that connects AI agents to Microsoft Power Automate using your browser's logged-in session. It lets you inspect, edit, validate, test, and revert flows with built-in safety features like preview, diff review, and rollback—no app registration required.

Is it free?

Yes, the MCP Power Automate server is open-source under the MIT license and available on npm as @kaael1/mcp-power-automate.

How do I install it in Cursor or Claude?

Register it with your MCP client using `codex mcp add power-automate-local -- npx -y @kaael1/mcp-power-automate`, then load the bundled Chromium extension from the path returned by `npx -y @kaael1/mcp-power-automate extension-path` into your browser's developer mode.

Do I need to set up Microsoft Entra ID or admin consent?

No. The server uses browser-backed auth by capturing tokens from your existing logged-in Power Automate session, so no app registration, admin consent flow, or enterprise application setup is required.

What safety features does it have?

The server enforces a supervised edit loop: inspect context, read the flow, preview the update, validate, save, review the diff, and optionally revert. Write operations are scoped—no blind production edits, solution deletion, or managed-solution modification by default.

What happens if a save fails?

The server reports specific errors like CONNECTION_AUTHORIZATION_FAILED (fix the connection in Power Automate) or SCHEMA_VALIDATION_FAILED (with the rejected field so the agent can correct it), preventing silent failures.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="./assets/readme-cover.png" alt="MCP Power Automate cover: inspect, validate, edit, and revert Power Automate flows with an MCP agent" width="720" /> </p>

MCP Power Automate

Local-first MCP server and Chromium extension for AI-assisted Microsoft Power Automate work.

Use your existing logged-in browser session to let an MCP client inspect, validate, edit, run, review, and revert Power Automate cloud flows. No Microsoft Entra ID app registration, admin consent flow, or custom enterprise application setup is required to get started.

Early public signal: 15,000+ LinkedIn post views and 14 GitHub stars while the project is still small, practical, and moving fast.

Why It Exists

Power Automate is powerful, but AI agents need more than raw convenience before they should touch real flows. This project keeps the workflow visible and reversible:

  • The browser extension captures the active Power Automate context and compatible tokens from your own Chromium session.
  • The MCP server exposes a v1 command surface for targeting, reading, previewing, validating, saving, run inspection, and rollback.
  • The extension stays mostly passive: status, diagnostics, and review surfaces instead of mystery buttons that hide what changed.
  • Local state, snapshots, and backups stay on your machine.

What It Can Do

AreaCapabilities
ContextDetect browser-captured flows, list flows, and explicitly lock onto a target flow.
Safe editingRead the flow, preview the smallest candidate update, validate, save, review the diff, and revert.
DebuggingInspect recent runs, latest run details, and action-level failures.
TestingInvoke safe manual/request trigger flows and wait for the resulting run.
SolutionsList unmanaged Dataverse solutions, inspect solution components and environment variables, add existing flows, and create blank flows inside solutions.

Write operations are deliberately scoped. The MCP does not expose solution deletion, component deletion, managed-solution modification, environment-variable writes, or blind production edits as the default path.

Quickstart

Register the MCP in Codex:

codex mcp add power-automate-local -- npx -y @kaael1/mcp-power-automate

Find the packaged extension path:

npx -y @kaael1/mcp-power-automate extension-path

Load that folder in Chromium:

  1. Open chrome://extensions or edge://extensions.
  2. Enable Developer Mode.
  3. Choose Load unpacked.
  4. Select the folder printed by extension-path.

Then open or focus a Power Automate flow page. The extension captures the session and target context automatically.

Check readiness:

npx -y @kaael1/mcp-power-automate doctor

Recommended Agent Loop

For a supervised edit, ask your MCP client to follow this loop:

  1. doctor
  2. get_context
  3. connect_flow
  4. get_flow
  5. preview_flow_update
  6. validate_flow
  7. apply_flow_update
  8. get_last_update
  9. validate_flow again when available

For run inspection and manual/request trigger tests, use list_runs, get_latest_run, get_run, get_run_actions, wait_for_run, get_trigger_callback_url, and invoke_trigger.

For Dataverse solution work, use list_solutions, list_solution_components, list_environment_variables, add_flow_to_solution, and create_flow_in_solution. Solution writes are intentionally limited to adding cloud flows to unmanaged solutions.

Public v1 Tools

get_context
doctor
connect_flow
list_flows
list_solutions
list_solution_components
list_environment_variables
add_flow_to_solution
get_flow
preview_flow_update
validate_flow
apply_flow_update
get_last_update
revert_last_update
list_runs
get_latest_run
get_run
get_run_actions
wait_for_run
get_trigger_callback_url
invoke_trigger
create_flow
create_flow_in_solution
clone_flow

Safety Model

  • Inspect with get_context, connect_flow, and get_flow before any write.
  • Preview with preview_flow_update before saving.
  • Validate before and after meaningful edits when Power Automate accepts validation.
  • Review get_last_update after save so the diff is visible.
  • Use revert_last_update when the saved result is wrong.
  • Prefer test or staging flows before production flows.

If Power Automate rejects a save because of a connection permission problem, the MCP reports CONNECTION_AUTHORIZATION_FAILED and waits for the user to fix that connection in Power Automate. If the service rejects a field such as retryPolicy, the MCP reports SCHEMA_VALIDATION_FAILED with the rejected member so the agent can correct the candidate flow instead of guessing.

Browser-Backed Auth

The extension can capture Power Automate, Power Platform/BAP, and Dataverse-audience tokens from your logged-in browser session. When those tokens are present, get_context and /health expose readiness details such as canManageSolutions.

This means the MCP can work without a new Microsoft Entra app registration, but it also means the browser session remains the live authority. If a token expires or a permission is missing, reopen or focus the relevant Power Automate, Power Apps, or Dataverse page and retry after capture.

HTTP Bridge

The local bridge listens on 127.0.0.1:17373.

  • GET /health is kept for simple probes.
  • GET /v1/health returns bridge identity and readiness.
  • GET /v1/context returns the same context used by the MCP.
  • GET /v1/commands lists the public v1 command surface.
  • POST /v1/commands/:name runs any public v1 command with a JSON body.

Only the process that owns the bridge port executes stateful work. If another process already owns the port, new MCP instances refuse to reuse it; stop the existing bridge process or choose a different POWER_AUTOMATE_BRIDGE_PORT.

Development

npm install
npm run typecheck
npm run lint
npm run test
npm run build
npm run pack:dry-run

For a local clone, prefer registering Codex against the built server from this checkout:

npm run build
$nodePath = (Get-Command node).Source
$serverPath = Join-Path (Get-Location) "dist/server/index.js"
codex mcp add power-automate-local -- $nodePath $serverPath

If an older local entry exists, remove it first:

codex mcp remove power-automate-local

Load the browser extension from dist/extension after rebuilding. Runtime state lives in data/ and must not be committed.

Docs

Package Links

License

MIT. See LICENSE.

Related MCP servers

Check Exa, BlockRun, OneSource, Apify and other x402 dependencies before invoking or paying.

Free MCP endpoint preflight before deployment, plus x402-paid PASS/FAIL/PARTIAL evidence receipt.

Persistent memory for AI coding agents — past bugs, decisions, and your corrections, in your repo.

1
JavaScript
MIT
View repository →
KAKadam Ad Network logo

Kadam advertising platform — manage ads, campaigns, creatives, audiences and stats

0
JavaScript
MIT
View repository →

x402 payment safety for AI agents: counterparty risk gate, payment firewall, compliance, RWA gate.

1
JavaScript
View repository →

Non-custodial Solana MCP: compare yields, buy tokenized US stocks (xStocks) & Ondo USDY. You sign.

2
TypeScript
MIT
View repository →