Identity-Aware MCP Server with Azure Cosmos DB

Identity-Aware MCP Server with Azure Cosmos DB

A Python MCP server that authenticates users via Microsoft Entra ID, stores per-user data in Azure Cosmos DB, and provides admin tools based on Entra group membership.

Category
访问服务器

README

Identity-Aware MCP Server with Azure Cosmos DB

A Python MCP server built with FastMCP that authenticates users via Microsoft Entra ID and stores user data in Azure Cosmos DB. The server includes admin-visible tools enabled via an Entra group membership check powered by the Microsoft Graph API. The project includes infrastructure for deployment to Azure Container Apps.

📺 Watch talk: "Know your user: Identity-aware MCP servers with Cosmos DB"

Table of Contents

Getting started

You have a few options for setting up this project. The quickest way to get started is GitHub Codespaces, since it will setup all the tools for you, but you can also set it up locally.

GitHub Codespaces

You can run this project virtually by using GitHub Codespaces. Click the button to open a web-based VS Code instance in your browser:

Open in GitHub Codespaces

Once the Codespace is open, open a terminal window and continue with the deployment steps.

VS Code Dev Containers

A related option is VS Code Dev Containers, which will open the project in your local VS Code using the Dev Containers extension:

  1. Start Docker Desktop (install it if not already installed)
  2. Open the project: Open in Dev Containers
  3. In the VS Code window that opens, once the project files show up (this may take several minutes), open a terminal window.
  4. Continue with the deployment steps.

Local environment

If you're not using one of the above options, then you'll need to:

  1. Make sure the following tools are installed:

  2. Clone the repository and open the project folder.

  3. Create a Python virtual environment and activate it.

  4. Install the dependencies:

    uv sync
    
  5. Copy .env-sample to .env and configure your environment variables:

    cp .env-sample .env
    

Deploy to Azure

This project can be deployed to Azure Container Apps using the Azure Developer CLI (azd). The deployment provisions:

  • Azure Container Apps - Hosts the MCP server
  • Azure Cosmos DB - Stores per-user expenses data
  • Azure Container Registry - Stores container images
  • Log Analytics - Monitoring and diagnostics

Azure account setup

  1. Sign up for a free Azure account and create an Azure Subscription.
  2. Check that you have the necessary permissions:

Deploying with azd

  1. Login to Azure:

    azd auth login
    

    For GitHub Codespaces users, if the previous command fails, try:

    azd auth login --use-device-code
    
  2. Create a new azd environment:

    azd env new
    

    This will create a folder inside .azure with the name of your environment.

  3. (Optional) Set the Entra admin group ID. This is used to restrict admin-only MCP tools to members of a specific Microsoft Entra ID security group. If not specified, the admin-only tools will not be available. You can find the group's Object ID in the Azure Portal under Microsoft Entra ID > Groups.

    azd env set ENTRA_ADMIN_GROUP_ID <your-group-object-id>
    
  4. Provision and deploy the resources:

    azd up
    

    It will prompt you to select a subscription and location. This will take several minutes to complete.

  5. Once deployment is complete, a .env file will be created with the necessary environment variables to run the server locally against the deployed resources.

Costs

Pricing varies per region and usage, so it isn't possible to predict exact costs for your usage.

You can try the Azure pricing calculator for the resources:

  • Azure App Service: Basic (B1) tier. Pricing
  • Azure Cosmos DB: Serverless tier. Pricing
  • Log Analytics (Optional): Pay-as-you-go tier. Costs based on data ingested. Pricing

⚠️ To avoid unnecessary costs, remember to take down your app if it's no longer in use, either by deleting the resource group in the Portal or running azd down.

Run the MCP server locally

For easier development and debugging, you can run the MCP server locally while still using the Azure resources provisioned by the deployment (Cosmos DB, Application Insights, Entra App Registration).

After deploying to Azure, the .env file should be populated with the necessary environment variables to connect to those resources. With that setup, you can run the MCP server locally against those resources:

cd servers && uv run uvicorn main:app --host 0.0.0.0 --port 8000

Use MCP server with GitHub Copilot

To use the MCP server with GitHub Copilot Chat in VS Code:

  1. Open .vscode/mcp.json. You should see two entries, one for the local server and one for the deployed server. To use the deployed server, replace https://YOUR_MCP_SERVER.azurecontainerapps.io/mcp with the URL of your deployed MCP server (from the .env file).

    {
     "servers": {
      "expenses-mcp-local": {
       "type": "http",
       "url": "http://localhost:8000/mcp"
      },
      "expenses-mcp-deployed": {
       "type": "http",
       "url": "https://YOUR_MCP_SERVER.azurecontainerapps.io/mcp"
      }
     }
    }
    
  2. Over the server that you want to use (local or deployed), select "Start" from the CodeLens options.

    Start MCP server from CodeLens

  3. You should see a dialog prompting you to authenticate with Microsoft.

    VS Code authentication prompt

    If you get an error that the server does not support DCR, that usually means the server failed to deploy correctly. Check the server logs for errors.

  4. After successful authentication, you should see "200" responses in the server logs in the Terminal, if you are running the server locally, or in the Azure Container Apps logs if you are using the deployed server.

    MCP server logs showing successful authentication

  5. Open the "Configure tools" dialog from GitHub Copilot Chat, and ensure that you have enabled the target MCP server (either local or deployed).

    Enable MCP server in GitHub Copilot Chat tools

  6. Test the MCP server by sending an expense tracking query through GitHub Copilot Chat:

    Log expense for 75 dollars of office supplies on my visa last Friday
    
  7. Verify the expense was added by checking the Cosmos DB user-expenses container in either the Azure Portal or Azure Cosmos DB extension in VS Code. You should see a new document with the expense details.

    Cosmos DB user-expenses container

  8. If you ever need to "log out" of the MCP server, select "More" from the CodeLens options and then "Disconnect account".

    Disconnect account from CodeLens


Resources

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选