Notes: Tool absence and backend authorization enforce the write boundary.
Notes: The inbound MCP token stops at APIM. The backend hop is application-only, not OBO.
Notes: HTTP GET alone does not prove that an operation has no side effects.
Notes: Keep the authority change at APIM explicit.
Notes: The implementation guide contains paired PowerShell and Bash commands.
Notes: Preflight checks the definitions, live Azure state, and deployment preview.
Notes: Stop if the version selector is hidden, the result is wrong, or correlation is absent.
Notes: The prior stable version is the immediate disable switch.
Notes: Removal is targeted and dependency-aware.