fabric-mcp-server
Provides tools for Git integration with Fabric workspaces, enabling committing workspace items to a Git repository, pulling updates from the repository, and checking the status of changes between the workspace and the remote branch.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@fabric-mcp-serverList recent pipeline runs in Sales workspace"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
fabric-mcp-server
Microsoft Fabric as an MCP server and as a CLI, from one tool registry.
The MCP server gives Claude Code, Claude Desktop, or any Model Context Protocol client typed, permission-gated access to Fabric.
The
fabricCLI exposes the exact same tools from a shell, so you can pipe large results throughjqor PowerShell, loop over workspaces in one call, and run unattended from a scheduled task with no model in the loop.
Both talk to the public Fabric REST API (api.fabric.microsoft.com), the Power BI REST API (api.powerbi.com), and the OneLake DFS endpoint, authenticating with @azure/identity.
Features
Resolve workspaces, items, pipelines, deployment pipelines, folders, and semantic models by display name or GUID.
Continuation-token paging, HTTP 429 retry (honors
Retry-After), and long-running-operation polling built in.Read-only by default. Every mutating tool is gated behind
FABRIC_MCP_MODE=writeon both surfaces and audit-logged to stderr.Safety rails on the dangerous operations:
deploy_stageandcommit_to_gitrefuse blanket "everything" runs;update_item_definitionanddelete_itemsnapshot the live definition first for one-call rollback.
Related MCP server: PowerBI MCP Server
Which surface when
Situation | Use |
Ad hoc question in a Claude session, small result | MCP |
A write operation you want permission-gated per tool by the MCP client | MCP |
Result is large and you only need a slice (OneLake listing, run history, item definition) | CLI piped through a filter |
Sweep across many workspaces or items | CLI in one shell call |
Anything that runs without a model (scheduled task, CI step) | CLI |
Fabric access from Claude Desktop or another MCP host | MCP |
Tools
Tool names and parameters are identical on both surfaces. On the CLI, list_item_runs is fabric list-item-runs (either spelling works) and each parameter is a --flag.
Tool | Mode | Description |
| read | All workspaces the signed-in identity can see. |
| read | Items in a workspace, optional type filter; includes |
| read | Workspace folders as a flat list with full paths. |
| read | Role assignments on a workspace. |
| read | SQL databases in a workspace with connection properties. |
| read | Data pipelines in a workspace. |
| read | Run history for a pipeline, most-recent first, optional status filter. |
| read | One pipeline run by job instance ID, including |
| read | New. Run history for any item type (notebooks, Spark jobs, dataflows), with status/job-type filters. |
| read | New. One job instance of any item: terminal status, timings, full |
| read | Job schedules on an item, including each schedule's |
| read | Read-only DAX query against a semantic model (Power BI |
| read | Recent refresh history for a semantic model. |
| read | New. Power BI data sources of a model with gateway binding ( |
| read | New. Fabric connections an item is bound to; |
| read | Items changed between the workspace and its Git branch, plus |
| read | Definition parts of an item (TMDL, notebook, report). Manifest by default; decoded content for one part. |
| read | Deployment pipelines the identity can see. |
| read | Stages of a deployment pipeline; optionally a stage's items for |
| read | Files/tables under an item in OneLake via the DFS API. |
| read | Read a small OneLake file as text, size-capped. |
| write | Grant a principal a workspace role. |
| write | Workspace folder management. |
| write | Trigger or cancel a pipeline run; |
| write | Run a notebook and wait, or detach with |
| write | Schedule management. |
| write | Trigger an on-demand semantic model refresh. |
| write | New. Power BI |
| write | New. Power BI |
| write | New. Fabric |
| write | Pull repo into workspace. Changed: |
| write | New. Commit workspace items to Git. Selective by item name/GUID; |
| write | Deploy a definition from a local folder, snapshotting the live one first. |
| write | Create (optionally from a definition) or delete an item, with best-effort snapshot. |
| write | New. Force a lakehouse SQL analytics endpoint to re-sync table metadata now, optionally scoped to tables or with |
| write | Selective stage-to-stage deployment; explicit item list required. |
Requirements
Node.js >= 20
An Entra identity with access to the target workspaces.
For
execute_dax: Build permission on the semantic model and the tenant's "Dataset Execute Queries REST API" setting enabled.For
bind_semantic_model_connection: the caller must own the model (takeover_itemfirst if not).
Install
git clone <this-repo-url> fabric-mcp-server
cd fabric-mcp-server
npm install
npm link # optional: puts `fabric` and `fabric-mcp-server` on your PATHConfiguration
All configuration is via environment variables (see .env.example). Both surfaces read the same variables.
Variable | Required | Purpose |
| no (default |
|
| for interactive / device-code / service-principal | Entra tenant ID. |
| for service-principal | App registration client ID. |
| for service-principal | App registration secret. |
| no (default |
|
| no |
|
| no | Cache partition name (default |
Auth modes
interactive — opens a browser; best for desktop/AVD. With the persistent cache, the CLI signs in once and then runs silently.
device-code — prints a code + URL to stderr; for SSH / WSL / headless.
cli — reuses your
az loginsession.azure-powershell — reuses your
Connect-AzAccountsession.service-principal — non-interactive; the right choice for scheduled tasks.
managed-identity — for hosting on Azure.
default — tries env → managed identity → CLI → browser in turn.
Use as an MCP server
Add to your MCP client config (~/.claude.json for Claude Code, claude_desktop_config.json for Claude Desktop):
{
"mcpServers": {
"fabric": {
"command": "node",
"args": ["/absolute/path/to/fabric-mcp-server/index.js"],
"env": {
"FABRIC_AUTH_MODE": "interactive",
"AZURE_TENANT_ID": "<your-entra-tenant-id>"
}
}
}
}Add "FABRIC_MCP_MODE": "write" to the env block to expose the write tools. Existing v1.x client configs keep working unchanged.
Use as a CLI
fabric tools # every tool with its mode
fabric help list-item-runs # a tool's flags
fabric list-workspaces
fabric list-item-runs --workspace BI-Prod --item brz_nb_clean --status Failed --top 5
fabric get-item-definition --workspace BI-Prod --item "Sales Model" --out sales-model.jsonConventions:
Flags mirror tool parameters;
--job_instance_idand--job-instance-idare equivalent.Object and array parameters take inline JSON or
@path/to/file.json. String arrays also take comma-separated values:--items "Notebook A,Notebook B".Booleans:
--wait,--wait=false,--no-wait.Output is JSON on stdout.
--compactfor one line,--out <file>to write to disk and print a short receipt instead.Exit codes:
0success,1the tool failed (message on stderr),2usage problem.Write tools need
FABRIC_MCP_MODE=writein the environment. The CLI will not accept it as a flag, so the same safety property holds on both surfaces.
Filtering large results in the shell
The point of the CLI is that filtering happens before anything reaches a model or your eyes.
# Which tables in the lakehouse have not been written today?
fabric list-onelake --workspace BI-Prod --item Bronze --directory Tables/dbo |
ConvertFrom-Json | Select-Object -Expand paths |
Where-Object { [datetime]$_.lastModified -lt (Get-Date).Date } |
Select-Object name, lastModified# Failed runs across every pipeline in a workspace, last 24 hours
fabric list-pipelines --workspace BI-Prod | jq -r '.pipelines[].displayName' | while read -r p; do
fabric list-pipeline-runs --workspace BI-Prod --pipeline "$p" --status Failed --top 5 --compact |
jq -c --arg p "$p" '.runs[] | select(.startTimeUtc > (now - 86400 | todate)) | {pipeline: $p, startTimeUtc, failureReason}'
doneScheduled tasks
Use service-principal auth (or seed the persistent cache with one interactive sign-in under the task's account) and FABRIC_MCP_MODE=write only when the task needs it.
# Morning health check written to a share, no model involved
$env:FABRIC_AUTH_MODE = "service-principal"
fabric list-pipeline-runs --workspace BI-Prod --pipeline Nightly-Load --status Failed --top 3 --compact |
Set-Content "\\share\reports\fabric-health-$(Get-Date -f yyyyMMdd).json"Deployment recipes the new tools cover
Semantic model promoted through a deployment pipeline will not refresh. Every leg resets its connections to Automatic.
get_item_connections (target model) -> confirm paths point at the target stage, unboundCount > 0
bind_semantic_model_connection copy_from=<a bound model in the same workspace>
refresh_datasetGit-synced model fails with "default data connection without explicit credentials".
get_dataset_datasources (a working sibling) -> gatewayId + datasourceId values
bind_dataset_to_gateway gateway_id=... datasource_ids=[...]Notebook just wrote to a lakehouse but the SQL endpoint still shows the old schema.
refresh_sql_endpoint_metadata --workspace W --item Lakehouse --tables dbo.lp_waterusageCommit one item from a workspace with other people's dirty items.
get_git_status -> see what is dirty
commit_to_git items=["my_notebook"] comment="..." (Selective; nothing else moves)Development
npm test # node --test: registry, CLI arg mapping, helpers, pollingTools live in src/tools/*.js as plain { name, description, mode, schema, handler } objects. src/mcp/register.js wraps them for MCP; src/cli/main.js maps each schema field to a flag. Adding a tool means adding one object; both surfaces pick it up.
Security notes
No secrets are stored in the repo. Credentials come from environment variables at runtime;
.envis git-ignored.Write tools are only registered (MCP) or runnable (CLI) under
FABRIC_MCP_MODE=write, and each logs an[AUDIT]line to stderr.The persistent token cache uses the OS secure store via
@azure/identity-cache-persistence. If the native module is unavailable the process falls back to the in-memory cache and says so on stderr.list_onelake/read_onelake_fileuse the Azure Storage token audience; the same credential acquires it.execute_daxuses the Power BIexecuteQueriesAPI, which only runs read-only DAX.
License
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only finance and operations controls for AI agents with evidence and safe next actions.
Query your org's data in natural language — read-only MCP access to SQL, NoSQL, files & warehouses.
Read-only MCP access to sessions, funnels, campaigns, errors, live visitors, and anomalies.
Services, case studies, 169 data and AI guides, and AI readiness scoring. Read-only, keyless.
Related MCP Servers
- AlicenseBqualityDmaintenanceEnables AI assistants to interact with Microsoft Fabric and Power BI services through the Model Context Protocol. Users can manage workspaces, execute DAX queries, refresh datasets, and create Fabric notebooks using natural language.614 npm2MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to query PowerBI workspaces, datasets, and execute DAX queries through the PowerBI REST API.719 PyPIMIT
- AlicenseNot gradedqualityAmaintenanceEnables read-only analysis of Power BI China reports and semantic models through the China REST API, supporting report discovery, metadata retrieval, and DAX query execution.MIT
- FlicenseNot gradedqualityCmaintenanceEnables management of Power BI resources including workspaces, datasets, tables, measures, reports, gateways, and DAX queries via Azure AD authentication.-