🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

partner-center-mcp

Package Overview
Dependencies
Maintainers
1
Versions
15
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

partner-center-mcp

Unofficial MCP server: knowledge and codegen assistant for the Partner Center REST API (not affiliated with Microsoft)

latest
Source
npmnpm
Version
0.13.0
Version published
Maintainers
1
Created
Source

partner-center-mcp

partner-center-mcp MCP server

An MCP server that helps you build against the Partner Center REST API: scenario discovery, ready-to-run REST examples, current authentication guidance, an auth deprecation linter, archived-.NET-SDK → REST migration, error decoding, and reference. Grounded in a curated, date-versioned knowledge pack plus live Microsoft Learn doc fetch. It holds no credentials and makes no live Partner Center calls — it is a knowledge & codegen assistant.

Unofficial, community project — not affiliated with, sponsored, or endorsed by Microsoft. "Partner Center" and "Microsoft" are trademarks of Microsoft, used here only descriptively.

partner-center-mcp demo

Why

The Partner Center .NET SDK (3.4.0) was archived in June 2023; Microsoft directs partners to the REST APIs. Deprecated auth (the retired graph.windows.net audience) still causes 401 / 900420 failures, and from 2026-04-01 App+User API usage enforces MFA. This server steers you to the current REST + auth patterns and decodes the errors you hit along the way.

How it works

Your MCP host (Claude Code, Cursor, Copilot, VS Code…) talks to this server over the MCP protocol (stdio by default, or HTTP). The server answers from a curated knowledge pack that is zod-validated at load and grounded in official Microsoft Learn docs — falling back to a cached live doc search only when needed. It never sees your credentials and never calls Partner Center.

flowchart LR
  subgraph Host["MCP host (Claude / Cursor / Copilot / VS Code)"]
    LLM["LLM agent"]
  end
  LLM -->|"MCP protocol"| T{"Transport<br/>stdio · HTTP"}
  T --> S["partner-center-mcp"]
  S --> Tools["26 tools<br/>list/get scenario · generate_call<br/>validate_request · plan_purchase<br/>explain_lifecycle · lookup_error · diagnose · …"]
  S --> RP["Resources & Prompts<br/>pc://… · migrate / diagnose / plan"]
  Tools --> KP[("Knowledge pack<br/>data/*.json")]
  KP -. "zod-validated at load" .-> Tools
  Tools -->|"fallback (cached)"| ML[("Microsoft Learn<br/>live doc search")]
  KP -. "docUrl + lastVerified" .-> CI[["Weekly doc-freshness CI<br/>opens an issue on high-severity drift"]]

A typical call: the agent picks a tool (e.g. pc_generate_call), the server looks the scenario up in the pack, and returns the verified method, path, headers, a ready code sample, and gotchas — each carrying the docUrl it was verified against.

Run

npx partner-center-mcp

No configuration, API keys, or network access to Partner Center required.

Requires Node.js 20 or newer. (0.9.0 dropped Node 18, which reached end of life in April 2025.)

Add to your MCP host

The server speaks MCP over stdio, so any MCP-capable host works — there's nothing host-specific to install. Use whichever config your host expects:

VS Code (.vscode/mcp.json) and Visual Studio (.mcp.json):

{ "servers": { "partner-center": { "command": "npx", "args": ["-y", "partner-center-mcp"] } } }

GitHub Copilot — Copilot reads the same .vscode/mcp.json (VS Code) / .mcp.json (Visual Studio) shown above; no extra config needed.

Cursor (.cursor/mcp.json) and Windsurf (~/.codeium/windsurf/mcp_config.json):

{ "mcpServers": { "partner-center": { "command": "npx", "args": ["-y", "partner-center-mcp"] } } }

Claude Code:

claude mcp add partner-center -- npx -y partner-center-mcp

Claude Desktop (claude_desktop_config.json), Cline, and Zed use the same mcpServers shape as Cursor above.

Tip: also add the Microsoft Learn MCP server (https://learn.microsoft.com/api/mcp) alongside this one for broad documentation search.

Remote / HTTP (optional)

Prefer a hosted endpoint over stdio? Run the Streamable HTTP variant:

PORT=3000 npx -p partner-center-mcp partner-center-mcp-http
# MCP endpoint: POST http://localhost:3000/mcp   •   health: GET /healthz

Tools

ToolPurpose
pc_list_scenariosList supported REST scenarios, optionally filtered by area.
pc_get_scenarioFull detail for one scenario: method, path, headers, examples, gotchas.
pc_generate_callEmit a current REST call (curl/csharp/typescript/powershell) with auth/retry/pagination helpers. Never the archived SDK.
pc_validate_requestLint a REST call (method, URL, headers, auth) against the known scenarios.
pc_plan_purchaseThe ordered New Commerce purchase workflow: product → SKU availability → cart → checkout → subscriptions.
pc_migrate_from_sdkTranslate archived .NET SDK code into the equivalent REST scenario(s).
pc_auth_guidanceCurrent auth guidance for app-only / app+user, per national cloud, with GDAP + MFA notes.
pc_check_authLint an auth/client snippet for retired patterns (graph.windows.net, ADAL, archived SDK, AzureAD PS).
pc_build_requestBuild a ready-to-send request: fills path placeholders, generates MS-RequestId/MS-CorrelationId, and a body skeleton from the scenario's fields.
pc_explain_lifecycleWhat you can do to a subscription in its current state: legal operations, the field each precondition reads, and the errors a failed precondition returns.
pc_plan_subscription_changeOrdered call sequence for one lifecycle change: seats up/down, upgrade, cancel, renewal changes, suspend, reactivate, migrate, transfer.
pc_plan_order_lifecycleOrdered call sequence from cart to provisioned subscriptions, with the cancellation and add-on branches.
pc_plan_transferOrdered billing-ownership transfer workflow (create → poll → verify).
pc_plan_gdap_onboardingOrdered GDAP onboarding workflow (create → approve → verify) over Microsoft Graph.
pc_plan_csp_onboardingOrdered CSP customer onboarding (account linking): invite → verify relationship → confirm agreement → transact.
pc_plan_user_onboardingOrdered user onboarding: create user → assign licenses → grant roles → verify.
pc_plan_user_offboardingOrdered user offboarding: remove licenses → strip roles → delete user (30-day restore window).
pc_plan_reconciliationOrdered reconciliation workflow (invoice → billed/unbilled line items → statement).
pc_lookup_errorDecode an error code: causes, remediation, and the scenarios it commonly hits.
pc_decode_errorPaste a raw error response → decoded code, likely scenarios, and the correlation id for support.
pc_diagnoseMap a symptom to likely causes, fixes, and relevant scenarios.
pc_get_enumsLook up enum values (billingCycle, termDuration, targetView, transitionType, status, …).
pc_get_resourceField dictionary for resources (Customer, Subscription, Order, Invoice, migration schedules, …).
pc_whats_newDeprecations & deadlines (MFA enforcement, graph.windows.net, v1→v2 reconciliation, …).
pc_search_docsFetch live Microsoft Learn excerpts — the fallback when the curated pack has no answer.
pc_get_referenceBase URLs, headers, versioning, sandbox, rate limits, national-cloud differences.

Every tool ships full metadata for the calling agent: a title, a description that says when to use it and which sibling tool to prefer instead, a description on every input parameter, a declared outputSchema, and MCP behaviour annotations. All 26 are readOnlyHint: true / destructiveHint: false — this server holds no credentials and calls no Partner Center endpoint, it only reads the bundled knowledge pack. The two exceptions to idempotentHint/openWorldHint are pc_search_docs (and pc_get_scenario with enrich: true), which reach Microsoft Learn, and pc_build_request, which mints a fresh MS-RequestId per call.

Responses use one envelope — { ok, data } on success, { ok: false, error, suggestions? } on failure — returned as structuredContent and validated against each tool's outputSchema by the MCP SDK.

Coverage

Scenarios span customers, subscriptions (the whole lifecycle: seats up and down, upgrade, cancel, renewal changes, suspend/reactivate, add-ons, New Commerce migration and transfer), orders & carts (through to provisioning status), catalog/products, licenses, invoicing/billing, utilities (address & domain validation), audit, support, security/MFA, analytics, and profiles — each with a verified docUrl and lastVerified date.

Lifecycle changes carry their preconditions, not just their endpoints: pc_explain_lifecycle returns the state machine — which operation is legal from which state, the field to read off the live subscription before attempting it (cancellationAllowedUntilDate, autoRenewEnabled, suspensionReasons), and the error a failed precondition returns. National clouds covered: commercial, 21Vianet (China), and US Gov.

The pack is also exposed as MCP resources (pc://scenarios, pc://errors, pc://auth, pc://reference, pc://sdk-map, pc://enums, pc://deprecations, pc://resources, pc://lifecycle, and pc://scenario/{id}) and three prompts (migrate-sdk, diagnose-issue, plan-purchase) for hosts that surface them.

It also ships reference datasets — enum values, a resource field dictionary, and a deprecations & deadlines timeline — and can export the whole pack to an OpenAPI 3.0 spec and a Postman collection (npm run export).

Examples

Decode an error you hit in production:

// pc_lookup_error { "code": "900420" }
{
  "httpStatus": 401,
  "errorCode": "900420",
  "description": "The audience in the token is invalid and is no longer supported in Partner Center API.",
  "causes": ["Token requested with the retired graph.windows.net audience"],
  "remediation": "Request the token with resource https://api.partnercenter.microsoft.com ...",
  "docUrl": "https://learn.microsoft.com/partner-center/developer/deprecate-azure-active-directory-graph-token"
}

Lint old auth/client code before you ship it:

// pc_check_auth { "code": "new AuthenticationContext(); get(\"https://graph.windows.net\"); partner.Customers..." }
{
  "findings": [
    { "severity": "error",   "message": "Uses the retired graph.windows.net audience; Partner Center returns 401 / 900420.", "fix": "Request the token with resource https://api.partnercenter.microsoft.com." },
    { "severity": "warning", "message": "Appears to use ADAL, which is deprecated.", "fix": "Use MSAL with the secure application model." }
  ],
  "clean": false
}

Catch a wrong call before you make it:

// pc_validate_request { "method": "POST", "url": "/v1/customers/abc/subscriptions", "headers": { "Authorization": "Bearer x" } }
{
  "ok": false,
  "findings": [
    { "severity": "error", "message": "Path matches a known scenario but the method POST is wrong; expected GET.",
      "fix": "Use GET for /v1/customers/{customer-id}/subscriptions." }
  ]
}

Develop

npm install
npm test
npm run build

The knowledge pack lives in data/ (date-versioned; each record carries a docUrl and lastVerified). Schemas in src/knowledge/schema.ts validate every file at load time, so malformed or drifted data fails fast.

Verification runs in two halves. npm run check-pack is offline and runs on every PR: it verifies each scenario's method, path, and headers against verification/doc-facts.json — a committed snapshot of what the Microsoft Learn pages actually say — and reports documented endpoints that have no scenario yet. npm run check-docs is the weekly networked half: it re-fetches every referenced page and compares it to the snapshot, keying drift off the source commit each Learn page embeds. It exits non-zero on a dead, moved, or replaced page, on a page that became unreadable, or when a field the pack depends on changed — the weekly GitHub Action then opens an issue; an upstream edit that touched only prose is reported without failing. npm run check-docs:update does the same fetch and then rewrites the snapshot. npm run docfacts:refresh rebuilds the snapshot from scratch, including the whole developer/ section of the Learn table of contents.

npm run eval runs a deterministic golden-case suite; npm run eval:llm (needs ANTHROPIC_API_KEY) checks that a real model picks the right tool for a question; npm run export emits an OpenAPI spec + Postman collection.

To regenerate the demo GIF (after npm run build): install vhs and run vhs demo.tape (writes assets/demo.gif).

Contributing

New scenarios and doc-accuracy fixes are very welcome — see CONTRIBUTING.md. This is an unofficial, community project and is not affiliated with Microsoft.

Keywords

mcp

FAQs

Package last updated on 01 Aug 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts