Chapter 3 of 6
Confirm these prerequisites:
- The API Center name, region, resource-scope alias, and default workspace belong to the approved nonproduction or production discovery boundary.
- The approved MCP server record exists in the API Center inventory and has an owner, environment, deployment or package, transport, and lifecycle decision.
- The MCP tool security control has completed runtime authentication, authorization, tool, and telemetry decisions.
- The API Center portal uses Microsoft Entra ID. Anonymous access is off.
- The developer group has Azure API Center Data Reader at the exact API Center resource scope.
- The client owner knows which supported client or adapter reads
registry-client-settings.json. - The API Center configuration owner has recorded the prior Data API visibility configuration in the approved change system.
- The approved OAuth client can supply a short-lived token for
https://azure-apicenter.net/Data.Read.Allthrough an environment variable without writing it to disk.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Runtime | artifacts/registry-client-settings.json | The developer-client configuration pipeline or approved client adapter |
| Record | artifacts/registry-ownership.json | The API Center configuration owner and MCP server owners |
After resolving artifact values in the approved private configuration path, run preflight in Implement › 1. Complete the client and ownership records. It checks the exact endpoint path, default workspace, Microsoft Entra mode, Azure API Center Data Reader role, delegated scope, global visibility conditions, approved names, and ownership markers. A read-only deployment preview is unsupported for Data API visibility, so the Azure portal preview is the required change review.