Fabric MCP Server

Microsoft's official local MCP server for Fabric APIs, OneLake data operations, and item definitions β€” running directly on your development machine.

Description

Fabric MCP Server (local) is Microsoft's official open-source Model Context Protocol server for the Microsoft Fabric platform. It runs as a local subprocess on your development machine and provides AI agents with three core capabilities: Fabric API documentation including OpenAPI specifications, OneLake file operations, and creation of Fabric items such as Lakehouses, Notebooks, and Data Pipelines. The server is development-focused and is not a replacement for the also-official hosted Fabric Core MCP Server (remote), which handles workspace management, permissions, and audit logging.

The primary product link points to the official Microsoft quickstart documentation; the source code lives in the microsoft/mcp monorepo on GitHub.

Clarification: monorepo star count

The GitHub star count in this catalog entry (exactly 3,650 stars, retrieved on 2026-09-08 via the GitHub API) refers to the entire microsoft/mcp monorepo, which contains all official Microsoft MCP server implementations, including the Azure MCP Server, the Fabric MCP Server, and other components. The stars are not an isolated rating for the Fabric MCP Server alone β€” they are a point-in-time popularity signal for the whole Microsoft MCP catalog. They are not evidence of quality, security, or production readiness for any individual component.

What the Fabric MCP Server (local) does

According to Microsoft, the local server provides the following tools:

API documentation and specifications β€” Offline access to Fabric REST API specs, OpenAPI operations, and best practices for individual workload types (Lakehouse, Notebook, Data Pipeline, Eventhouse, KQL database, and more). An agent can retrieve sample creation request bodies or API throttling guidance without making a live Fabric call.

OneLake file operations β€” Downloading and uploading files to OneLake storage, for example a config JSON from a Sales Lakehouse. These operations require valid local credentials.

Item creation β€” Creating new Fabric items, for example a new Lakehouse named "CustomerData" in a development workspace. The local server provides only create operations according to Microsoft's comparison table, not full CRUD like the remote server.

Local file system access β€” Reading and writing local files and configurations as part of development workflows.

Offline capability β€” Documentation and best-practice tools work without an active Fabric connection.

Installation and transports

Microsoft recommends three installation paths:
VS Code extension (recommended) β€” Install the Fabric MCP Server extension from the VS Code Marketplace; no further configuration is needed. The extension registers the MCP server automatically.
npm/npx β€” Add JSON configuration to the client's mcp.json: npx -y @microsoft/fabric-mcp@latest server start --mode all. Requires Node.js 20 LTS or later.
Build from source (.NET) β€” git clone https://github.com/microsoft/mcp.git, then dotnet build servers/Fabric.Mcp.Server/src/Fabric.Mcp.Server.csproj --configuration Release. Requires .NET 9 SDK or later.

The server uses stdio transport. The official documentation notes that when configuring VS Code manually, use servers instead of mcpServers as the root JSON key.

Comparison: local vs. remote (Core)

| Feature | Core (remote) | Local |
|---|---|---|
| Workspace management | Yes | No |
| Item CRUD | Full | Create only |
| Permissions management | Yes | No |
| OneLake file operations | No | Yes |
| API docs (offline) | No | Yes |
| Installation required | No | Yes |
| Authentication | OAuth 2.0 (Entra ID) | Local credentials |
| Audit logging | Yes | No |
| Open source | No | Yes |

Both servers can be configured simultaneously according to Microsoft.

Security, limits, and risks

The Fabric MCP Server (local) connects an AI agent to the local file system and to Microsoft Fabric. Several security aspects should be assessed before deployment:

Local file system access β€” The server can read and write local files. Agents should only be able to access explicitly scoped directories; do not configure unrestricted path wildcards.

API permissions and mutations β€” Item creation operations (for example creating a Lakehouse) are write access against Fabric. Credentials should carry minimal permissions; separate development workspaces are recommended for workloads close to production.

Access tokens and credentials β€” Local credentials for OneLake operations must not be stored as plaintext in configuration files. Short-lived tokens with automatic renewal and separate development identities reduce risk.

Prompt injection β€” API documentation and OneLake file contents can contain attacker-crafted instructions that a language model may interpret as tool calls. Check inputs and file contents for unexpected control directives before processing.

Data path to the model β€” All content returned by the server (file names, API responses, schemas) is forwarded to the connected AI client and from there to the model provider. Sensitive data such as secrets, personal information, or business-critical schemas should not flow uncontrolled into agent context.

No audit logging β€” Unlike the remote Core server, the local server does not log actions to Fabric audit logs. This should be considered for compliance-relevant environments.

License, status, and FAQ

The microsoft/mcp monorepo is licensed under MIT. The Fabric MCP Server is an open-source project; Microsoft notes that the GitHub repository contains detailed setup instructions and troubleshooting guidance. The server is under active development.

FAQ: Is the Fabric MCP Server free? β€” The server itself is free and open source. Costs arise from the Microsoft Fabric resources actually consumed (OneLake storage, compute capacity) at standard Fabric pricing. The official Microsoft provider plans are authoritative.

FAQ: What is the difference from the Azure MCP Server? β€” The Azure MCP Server (also in the microsoft/mcp monorepo) targets general Azure cloud services (VMs, databases, AI services). The Fabric MCP Server is designed specifically for the Microsoft Fabric analytics platform (OneLake, Lakehouse, Eventhouse, KQL, Notebooks, and so on) and its development workflows.

Requirements

Node.js 20 LTS or later (for npx); or .NET 9 SDK (for source build); or VS Code with GitHub Copilot Chat extension.

Installation instructions

npx -y @microsoft/fabric-mcp@latest server start --mode all

Authentication

Local Microsoft Fabric credentials. Valid access tokens are required for OneLake operations; OAuth 2.0 / Entra ID for remote Core operations.

Required access permissions

Write access to Fabric items (create) and local file system. Credentials should carry minimal permissions; separate development workspaces recommended.

Transmitted or stored data

Not recorded yet.

Security risks

Local file system access, uncontrolled credentials in configuration files, prompt injection via API content or OneLake files, no audit logging, data forwarded to the connected model provider.

License and costs

License
MIT
Cost
free

The server itself is free and open source (MIT license). Costs arise from Microsoft Fabric resources used (OneLake, compute capacity) at standard Fabric pricing.

Alternatives

Not recorded yet.

At a glance

Provider
Microsoft
Status
Official server
Deployment
Local
Current version
Not recorded yet.
GitHub stars
3,719
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.