Chapter 2 of 6 · Architecture

Azure API Center and the AI/MCP inventory

Runtime assurance 3 hours in a non-production POC

Chapter 2 of 6

Architecture at a glance#

Bicep deploys API Center, its metadata schema, the default workspace, the direct agent API, and its Foundry runtime location. API Center's system identity receives API Management Service Reader Role on the exact APIM gateway service. The source integration then imports APIM APIs, definitions, environments, and deployments.

The API program owner registers the approved remote MCP server in the portal. Asset owners maintain metadata on the synchronized and portal-created entries.

API Center tracks design-time inventory while API Management remains on the separate runtime request path.

Live requests stay on the APIM path. The MCP security configuration uses the MCP entry and runtime location for tool-security work.

Design choices and tradeoffs#

DecisionChosen approachBenefitsCosts and limitations
Inventory scopeDirect agent API, linked APIM instance, and one approved remote MCP serverGives the three selected assets one searchable inventoryEvery API in the APIM instance is imported and needs an owner
APIM accessOne-way sync with API Management Service Reader RoleKeeps definitions aligned without APIM write accessInitial sync can take up to 24 hours
MCP registrationNative portal flowUses the supported MCP asset modelA person must maintain the entry
Authoritative stateDesign metadata in API Center; runtime state in each serviceKeeps inventory and runtime health separateOwners must update metadata after service changes
PlanRecord Free or Standard, then confirm it in the portalKeeps support and cost explicitStable Bicep does not set the plan

Architecture guidance#

Session 07

Azure API Center and the AI/MCP inventory slide deck