Security change on December 1, 2026: TLS 1.2 will become the minimum standard for 365 business Print Agent. Details and system requirements
365 business development
MCP Server

Tools reference

The MCP server exposes a focused toolset over the businessdev.ALbuild module. Read-only tools are synchronous; mutating / long-running tools are asynchronous: they return a jobId you poll with get-job.


Tools

ToolTierNotes
list-containersread-onlyDocker state + pool metadata.
inspect-containerread-onlyContainer detail + installed apps.
find-artifactread-onlyResolve a BC artifact URL for a country/version/type.
get-build-orderread-onlyMulti-project dependency build order.
resolve-dependencies-planread-onlyDry-run dependency resolution (what would be fetched).
ensure-containermutating (job)Warm-reuse or provision a container; optional dependency install + license.
restart-containermutating (job)Restart a container.
remove-containerdestructiveSelf-created → runs; shared/pre-existing → approval_required.
reconcile-dependenciesread-onlyManifest vs container vs feeds → satisfied / available-from-feed / missing.
publish-appmutating (job)Upload a built .app (base64) and publish it, the remote file transport.
unpublish-appmutating (job)Uninstall (-Force) + unpublish one or more apps by name, makes a re-publish at the same version idempotent.
deploy-and-testmutating (job)appFolder (local) or apps (base64 uploads) → publish clean → run tests.
run-testsmutating (job)Re-run tests without redeploy, the fast inner-inner loop.
build-appmutating (job)Compile the workspace fresh (fresh symbols → alc). Always runs on the host.
install-dependenciesmutating (job)Resolve and install an app's dependency closure into a container.
diagnose-appread-onlyA container's actual app state: published versions, install/sync state, tenant data version, event-log tail, and named blockers with remedies.
get-test-resultsread-onlyFetch the last test run's results.
convert-coverageread-onlyRaw BC coverage (.dat) → ALbuild JSON / Cobertura / Markdown.
coverage-summaryread-onlySummarise a coverage report.
coverage-thresholdread-onlyGate on coverage; reports below-threshold as a failure.
coverage-deltaread-onlyPatch coverage of git-changed lines against a baseline ref.
coverage-mergeread-onlyMerge coverage from several runs into one report.
test-qualityread-onlyAssess AL test quality (assertions / empty tests / score).
get-job / cancel-jobread-onlyAsync job control.

The async job model

Anything that mutates a container or runs long returns immediately with a jobId:

  1. Call the tool → get { jobId }.
  2. Poll get-job { jobId } → state (running / succeeded / failed / cancelled), the streamed log, and on success the structured result (e.g. tests: { passed, failed, skipped, failures[] }).
  3. cancel-job aborts a running job.

Remote app and dependency flow

When the agent is not on the MCP host (e.g. OpenClaw or Claude Code on a Mac talking to a Windows host), a filesystem path is meaningless on the host, so apps and feed credentials travel in the call:

  1. reconcile-dependencies: send the app.json dependencies and the merged (app + workspace) albuild.json feeds, because the host can't read your repo. A private feed carries its API key in feeds[].token, the host doesn't have your credentials, so the agent supplies them (kept out of logs, passed to PowerShell via a child env var). You get back what's satisfied (already in the container, including Microsoft apps), availableFromFeed, and missing.
  2. publish-app / deploy-and-test (upload form), send the missing .app files (and your app + test app) as base64, in dependency order; the server stages them on the host and publishes. Tests run by testExtensionId.

Local agents are simpler

When the agent runs on the MCP host, deploy-and-test takes an appFolder host path instead, it resolves the dependency closure from your feeds and publishes every .app in the folder directly.


Per-agent tool scoping

Each agent, identified by the stdio ALBUILD_MCP_AGENT value or its HTTP bearer token, sees only its allowed tools. This is a correctness requirement for small local models (fewer, relevant tools = better tool selection). Example roles: a coding-loop agent (full deploy/test), an ops agent (container hygiene), an architecture/DevOps agent (read-only visibility). The full toolset is available to claude-code.


Governance

  • Mutating tools run as logged async jobs: every action is traceable.
  • remove-container protects shared resources: a container the agent did not create this session returns { status: "approval_required" } instead of acting, for a human (or the OpenClaw Escalation Router) to approve. Only self-created containers are auto-removable (toggle with ALBUILD_ALLOW_SELF_CLEANUP).
  • Secrets stay where they belong: the host's own credentials (its PAT, signing cert) live on the host as the service identity. Per-feed API keys, which the host does not have, are supplied by the agent via reconcile-dependencies feeds[].token, kept out of logs and passed to PowerShell through a child env var (never inline). This relies on the authenticated, LAN/Tailscale-only channel.

Configuration (environment variables)

VariableDefaultPurpose
ALBUILD_MODULE_PATHinstalled modulePath to the businessdev.ALbuild module to import.
ALBUILD_POWERSHELLpwshPowerShell executable (falls back to powershell).
ALBUILD_DOCKERdockerDocker executable.
ALBUILD_MAX_WARM_CONTAINERS2Warm-pool size cap (LRU eviction beyond it). RAM-bound.
ALBUILD_CONTAINER_MEMORY8GMemory per container; ceiling for a tool's memoryLimit request.
ALBUILD_DEFAULT_ARTIFACT_TYPESandboxFallback artifact type.
ALBUILD_ALLOW_SELF_CLEANUPtrueAgent may remove containers it created without approval.
ALBUILD_POOL_STATE%LOCALAPPDATA%/albuild-mcp/pool.jsonPool registry file.
ALBUILD_MCP_HTTP_HOST127.0.0.1HTTP bind host.
ALBUILD_MCP_PORT5020HTTP port.
ALBUILD_MCP_TOKENS(none)JSON { "<token>": "<agentId>" } for HTTP bearer auth.
ALBUILD_MCP_AGENTclaude-codeAgent identity for the stdio transport (scopes the toolset).
ALBUILD_MCP_SKIP_PREFLIGHT(unset)Set to 1 to bypass the start-up preflight gate.

See the step-by-step guide to wire the server into VS Code, Claude Code, or a remote host.

Last modified on