Chapter 1 of 6 · Scope and outcomes

Azure API Center and the AI/MCP inventory

Runtime assurance 3 hours in a non-production POC

Chapter 1 of 6

Session scope#

What we will do#

Objective. Add three selected assets to API Center: deploy the Governed agent baseline guide agent API, synchronize the APIM AI gateway guide APIM API, and register an approved remote MCP server.

The three entries receive owner, lifecycle, classification, risk, review, and runtime-location metadata. The read-only check confirms that each entry appears once and that the APIM integration points to the approved source.

Why it matters#

Problem. Developers need to know what they can use, where it runs, and who owns its review and retirement.

Solution. API Center makes missing inventory decisions visible before an asset is treated as approved.

Boundaries#

API Center holds design-time inventory and discovery metadata. Foundry, APIM, and the MCP runtime remain authoritative for live service state, and API Center does not inspect or block runtime calls. MCP tool security guide governs MCP tool use on the synchronized route.

Approving the APIM link approves its full source boundary: the integration is read-only, one-way, and imports every API in the linked instance, so assign metadata owners before creating it. Register the remote MCP server through the portal, because the stable Microsoft.ApiCenter@2024-03-01 ARM surface has no native MCP fields. Production discovery, write-capable MCP tools, the API Center portal, private discovery, Foundry Toolbox reuse, registry discovery, and A2A inventory stay out of scope, pending separate approval or their optional modules.

Session preparation

Who should join

  • API platform and Microsoft Foundry engineers
  • API product, risk, and data owners
  • Developers responsible for agent and MCP discovery

What you need

  • The approved nonproduction Foundry agent endpoint and APIM API are available. The platform and gateway owners confirm the endpoint, marked policy-assistant-responses API, and both resource scopes. (Sessions 02, 04, and 06.)
  • Choose an approved API Center region, Free or Standard plan, and remote read-only MCP server with an HTTPS Streamable HTTP endpoint.
  • Give the deployment operator time-bound Contributor on the exact resource group where this session deploys API Center.
  • Give that same deployment operator time-bound User Access Administrator on the exact Session 06 API Management instance. The deployment runs both operations in one Azure deployment.
  • Approve the full API Management source boundary because the integration imports every API from the linked instance.
  • Name the owners and complete the required metadata for the direct agent API, synchronized APIs, and MCP server.

Session 07

Azure API Center and the AI/MCP inventory slide deck