1. Help
  2. Integrations
  3. MCP
  4. Connecting Copilot Studio to Xurrent MCP
  1. Help
  2. Integrations
  3. MCP
  4. Connecting Copilot Studio to Xurrent MCP
purple icon for coordination.
We’ve moved!
Our Help Center has a new home and our URLs have changed. Please update your bookmark to this page before April 30, 2026

Connecting Copilot Studio to Xurrent MCP

Configure a Copilot Studio agent to use the Xurrent MCP server, signing in with OAuth or using a Personal Access Token.

The Xurrent MCP server can be added to a Copilot Studio agent as a custom MCP tool, giving the agent access to Xurrent's tools. There are two ways to authenticate it.

  • OAuth 2.0 with dynamic discovery. The recommended route. Copilot Studio discovers the Xurrent authorization server and registers itself, so there is nothing to configure and no token to manage. Each user of the agent signs in to Xurrent themselves.
  • API key with a Personal Access Token. A single long-lived token, shared by the agent, that acts as the person who created it.

Prerequisites

  • A Copilot Studio environment with permission to add custom tools.
  • Sera AI enabled on the Xurrent account you are connecting to. If it is not, MCP requests are refused with a 403.
  • The Xurrent MCP endpoint URL for your region and environment.
  • For the API key route only, a Xurrent Personal Access Token with the MCP scope. See MCP Authentication.

Endpoints

The Xurrent MCP server is hosted per region. The Global region has no region segment; every other region inserts its code. Production Global uses .com, Demo uses -demo.com, and QA uses .qa.

InstanceRegion
https://mcp.xurrent.com/mcpGlobal
https://mcp.au.xurrent.com/mcpAustralia
https://mcp.uk.xurrent.com/mcpUnited Kingdom
https://mcp.ch.xurrent.com/mcpSwitzerland
https://mcp.us.xurrent.com/mcpUnited States

Demo Global is https://mcp.xurrent-demo.com/mcp and QA Global is https://mcp.xurrent.qa/mcp. For a non-Global region, insert the region code the same way, for example https://mcp.ch.xurrent.qa/mcp.

Copilot Studio supports the Streamable transport, which is what these endpoints serve.

Option 1: OAuth 2.0 with dynamic discovery

  1. Go to the Tools page for your agent.
  2. Select Add a tool, then New tool, then Model Context Protocol.
  3. Fill in Server name, Server description, and Server URL. Use the endpoint for your region from the table above. Write the description carefully: the agent orchestrator uses it to decide whether to call Xurrent at runtime.
  4. For the authentication type, select OAuth 2.0.
  5. For the OAuth 2.0 Type, select Dynamic discovery.
  6. Select Create. Copilot Studio reads the Xurrent discovery endpoint, finds the authorization server, and registers itself. There are no URLs, client IDs, or secrets to enter.
  7. Select Next, then Create a new connection, then Add to agent.

Users of the agent sign in to Xurrent when they first use it, and the agent then acts as each of them individually, with their own roles and permissions. Nothing long-lived is stored in the agent's configuration.

Option 2: API key with a Personal Access Token

Use this where you want the agent to act as one service identity rather than as each user, or where the OAuth route is not available to you.

  1. Go to the Tools page for your agent.
  2. Select Add a tool, then New tool, then Model Context Protocol.
  3. Fill in Server name, Server description, and Server URL.
  4. Select API key as the authentication type, not None.
  5. Set the Type to Header, and the header name to Authorization.
  6. Select Create, then create a connection. Enter your token in this exact format: Bearer YOUR_PAT_HERE — the word Bearer, a space, then the token.
  7. Select Add to agent, then publish or test.

Everyone using the agent shares this identity, so the Xurrent audit trail attributes every action to the token's owner rather than to the person who asked. Prefer OAuth where that distinction matters.

Getting the PAT scope right

If the scope on your token is wrong, every tool call fails with a 403 even when you hold admin rights. The token needs one scope:

  • Effect: Allow
  • Actions: MCP, with Tools, Resources, and Prompts all selected

Make sure you click Add Scope so the scope is actually saved to the token. A scope left unsaved in the form is the most common cause of a token that authenticates but cannot call anything.

The order in which you add the actions makes no difference. Xurrent stores a scope's actions in a fixed order regardless of how they were entered, so there is no need to regenerate a token that already has the right scope.

Verifying the connection

Ask your agent: "What are my open requests in Xurrent?" The agent should call the appropriate Xurrent tool and return results.

Seeing the tools listed only confirms the connection reached the server. A real query is what confirms the credential is authorized.

Reconfiguring an existing tool

If you set up the Xurrent MCP tool with the wrong authentication type and want to change it:

  1. On the Tools page, locate the existing Xurrent MCP tool.
  2. Delete it.
  3. Follow the setup steps above from the start.

This is typically faster than editing a misconfigured tool in place.

A note on data policies

MCP servers in Copilot Studio connect through Power Platform connectors, so any data policy governing Power Platform connectors also governs the agent's access to Xurrent. Check with whoever administers your Power Platform environment if the tool is blocked.

Related

See MCP Authentication for both credential routes, Available Tools and Capabilities for what the agent can do, and Troubleshooting for 403 errors and missing tools.