Aspirerelease/13.6
Watch Aspire live streamsDocsTry Aspire
Watch Aspire live streamsDocsTry

Azure Connector Namespace hosting integration

Azure Connector Namespace connects applications to external services such as Office 365 and SharePoint. Aspire models the namespace, authenticated connections, managed MCP server configurations, and access policies together.

Aspire CLI — Add Aspire.Hosting.Azure.ConnectorNamespace package
aspire add azure-connectornamespace

The Aspire CLI is interactive, be sure to select the appropriate search result when prompted:

Aspire CLI — Example output prompt
Select an integration to add:
> azure-connectornamespace (Aspire.Hosting.Azure.ConnectorNamespace)
> Other results listed as selectable options...

Configure Azure provisioning before running or deploying the AppHost. The integration provisions real Azure resources; it doesn’t provide a local connector emulator.

A connection is an authenticated binding to a service. A managed MCP server configuration exposes selected operations from that connection as MCP tools. The current preview supports one connector per managed MCP server configuration.

This example exposes only the Office 365 GetEmailsV3 operation. Replace the tenant and principal IDs with your own Microsoft Entra IDs and verify the connector’s operation IDs against the metadata available in your region.

apphost.mts
import {
type AzureConnectorNamespaceMcpAccessPolicyPrincipalType = "User" | "Group"
const AzureConnectorNamespaceMcpAccessPolicyPrincipalType: {
readonly User: "User";
readonly Group: "Group";
}

Enum Aspire.Hosting.Azure.AzureConnectorNamespaceMcpAccessPolicyPrincipalType

AzureConnectorNamespaceMcpAccessPolicyPrincipalType
,
function createBuilder(): IDistributedApplicationBuilder

Creates a new distributed application builder

createBuilder
,
} from './.aspire/modules/aspire.mjs';
const
const builder: IDistributedApplicationBuilder
builder
= await
function createBuilder(): IDistributedApplicationBuilder

Creates a new distributed application builder

createBuilder
();
const
const connectors: AzureConnectorNamespaceResource
connectors
= await
const builder: IDistributedApplicationBuilder
builder
.
IDistributedApplicationBuilder.addAzureConnectorNamespace(name: string): AzureConnectorNamespaceResource

Adds an Azure Connector Namespace resource to the application model.

addAzureConnectorNamespace
('connectors');
const
const outlook: AzureConnectorNamespaceConnectionResource
outlook
= await
const connectors: AzureConnectorNamespaceResource
connectors
.
AzureConnectorNamespaceResource.addConnection(name: string, connectorName: string, options?: AzureConnectorNamespaceConnectionOptions): AzureConnectorNamespaceConnectionResource

Adds a connection to an Azure Connector Namespace.

addConnection
('outlook', 'office365', {
AzureConnectorNamespaceConnectionOptions.connectionName?: string | undefined
connectionName
: 'office365-outlook',
AzureConnectorNamespaceConnectionOptions.displayName?: string | undefined
displayName
: 'Office 365 Outlook',
});
await
const outlook: AzureConnectorNamespaceConnectionResource
outlook
.
AzureConnectorNamespaceConnectionResource.withAccessPolicy(name: string, options: AzureConnectorNamespaceAccessPolicyOptions): AzureConnectorNamespaceConnectionResource

Adds a Microsoft Entra access policy to a Connector Namespace connection.

withAccessPolicy
('worker-access', {
AzureConnectorNamespaceAccessPolicyOptions.objectId?: string | undefined
objectId
: '33333333-3333-3333-3333-333333333333',
AzureConnectorNamespaceAccessPolicyOptions.tenantId?: string | undefined
tenantId
: '22222222-2222-2222-2222-222222222222',
});
const
const worker: ProjectResource
worker
= await
const builder: IDistributedApplicationBuilder
builder
.
IDistributedApplicationBuilder.addProject(name: string, projectPath: string, options?: {
launchProfileOrOptions?: string | ProjectResourceOptions;
}): ProjectResource (+1 overload)

Adds a .NET project resource

addProject
('worker', '../Worker/Worker.csproj');
await
const worker: ProjectResource
worker
.
ProjectResource.withReference(source: IResource | EndpointReference | string | uri, options?: {
connectionName?: string;
optional?: boolean;
name?: string;
} | undefined): ProjectResource (+1 overload)

Adds a reference to another resource

withReference
(
const outlook: AzureConnectorNamespaceConnectionResource
outlook
);
const
const mcp: AzureConnectorNamespaceMcpServerConfigResource
mcp
= await
const connectors: AzureConnectorNamespaceResource
connectors
.
AzureConnectorNamespaceResource.addMcpServerConfig(name: string, options?: AzureConnectorNamespaceMcpServerConfigOptions): AzureConnectorNamespaceMcpServerConfigResource

Adds a managed MCP server configuration to an Azure Connector Namespace.

addMcpServerConfig
('outlook-mcp');
await
const mcp: AzureConnectorNamespaceMcpServerConfigResource
mcp
.
AzureConnectorNamespaceMcpServerConfigResource.withConnector(connectorName: string, connection: AzureConnectorNamespaceConnectionResource, options: AzureConnectorNamespaceMcpConnectorOptions): AzureConnectorNamespaceMcpServerConfigResource

Adds a connector route and an explicit operation allow-list to a managed MCP server configuration.

withConnector
('office365',
const outlook: AzureConnectorNamespaceConnectionResource
outlook
, {
AzureConnectorNamespaceMcpConnectorOptions.operations?: AzureConnectorNamespaceMcpOperationOptions[] | undefined
operations
: [{
AzureConnectorNamespaceMcpOperationOptions.name?: string | undefined
name
: 'GetEmailsV3',
AzureConnectorNamespaceMcpOperationOptions.displayName?: string | undefined
displayName
: 'Get emails' }],
});
await
const mcp: AzureConnectorNamespaceMcpServerConfigResource
mcp
.
AzureConnectorNamespaceMcpServerConfigResource.withAccessPolicy(name: string, options: AzureConnectorNamespaceMcpAccessPolicyOptions): AzureConnectorNamespaceMcpServerConfigResource

Adds a Microsoft Entra user or group access policy to a managed MCP server configuration.

withAccessPolicy
('developer-access', {
AzureConnectorNamespaceMcpAccessPolicyOptions.objectId?: string | undefined
objectId
: '11111111-1111-1111-1111-111111111111',
AzureConnectorNamespaceMcpAccessPolicyOptions.tenantId?: string | undefined
tenantId
: '22222222-2222-2222-2222-222222222222',
AzureConnectorNamespaceMcpAccessPolicyOptions.principalType?: AzureConnectorNamespaceMcpAccessPolicyPrincipalType | undefined
principalType
:
const AzureConnectorNamespaceMcpAccessPolicyPrincipalType: {
readonly User: "User";
readonly Group: "Group";
}

Enum Aspire.Hosting.Azure.AzureConnectorNamespaceMcpAccessPolicyPrincipalType

AzureConnectorNamespaceMcpAccessPolicyPrincipalType
.
type User: "User"
User
,
});
await
const builder: IDistributedApplicationBuilder
builder
.
IDistributedApplicationBuilder.build(): DistributedApplication

Builds the distributed application

build
().
DistributedApplication.run(cancellationToken?: cancellationToken): void

Runs the distributed application

run
();

The worker reference supplies outlook__connectorGatewayName and outlook__connectionName for the Azure Connector SDK. It doesn’t grant access: the connection policy must identify the Entra principal that the worker actually uses. An explicit connection name on the reference can change the consumer’s configuration prefix.

After provisioning, open https://connectors.azure.com/<subscription-id>/<resource-group>/<connector-namespace-name>/overview and authorize connections that require consent. Aspire doesn’t automate consent or store OAuth credentials.

Keep the two authorization surfaces separate:

  • Connection policies grant a specified Entra principal access to the connection. Use WithIdentityAccessPolicy / withIdentityAccessPolicy for a user-assigned managed identity without hard-coding its principal ID.
  • MCP server policies grant an Entra user or group access to the managed MCP endpoint. This preview doesn’t support service principals or managed identities for MCP access policies.
  • Operation allow-lists restrict the connector operations exposed as MCP tools. Expose only what your application needs; don’t put credentials or tokens in descriptions or operation metadata.

Use the standard Azure PublishAsExisting / publishAsExisting and AsExisting / asExisting workflows for a namespace. Existing connection and MCP configuration children support AsExisting / asExisting and are emitted as read-only Bicep references.

When adding a new access policy beneath an existing namespace, set the Azure deployment location to the namespace’s location. Bicep can’t read the existing location early enough to assign the child resource location automatically.

The integration doesn’t support secret-valued connection parameter sets, connector triggers, event subscriptions, hosted MCP servers, or arbitrary MCP operation parameter schemas. Create connections that require unsupported secret parameter sets outside Aspire and reference them as existing resources.