Chapter 3 of 6
Confirm:
- the MCP server record in the approved API Center inventory is approved and identifies the remote MCP server version and deployment;
- the MCP control owner has approved the exact MCP tool name and the server's authentication path;
- the API catalog owner has approved public-preview use in this nonproduction scope;
- the operator has Azure API Center Data Reader on the exact API Center resource;
- the operator has Foundry User on the exact project and Foundry Project Manager if the catalog configuration creates a project connection;
- the agent release owner understands that Toolbox approval metadata still needs an enforcing runtime approval experience;
- Azure Developer CLI 1.27.1 or later has the
microsoft.foundryextension.
Complete every __REQUIRED_*__ value under artifacts/ in an approved private working copy. Do not commit the completed copy because it contains tenant-specific resource coordinates and the MCP endpoint.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Record | artifacts/governance/catalog-toolbox-binding.json | The API catalog owner and Foundry tool owner |
| Deployment | artifacts/toolbox/toolbox-version.json | The Foundry Toolbox deployment process |
| Runtime | artifacts/operations/check_toolbox.py | The Foundry tool owner |
The module uses standard mode for its bounded configuration change and read-only check.
The private catalog's Azure RBAC assignment can take up to 24 hours to propagate, so assign access before the delivery window.