# Azure Private Link > Azure Private Link gives a virtual network a private IP onto an Azure PaaS service, a partner service, > or a service you publish yourself, so the traffic never traverses the public internet. There are two > halves: a CONSUMER creates a private endpoint pointing at a target resource id, and a PRODUCER publishes > a private link service in front of a Standard Load Balancer and approves or rejects the connections > that arrive. The management surface is the Azure Resource Manager REST API at management.azure.com. Generated by API Evangelist on 2026-09-17 from this repository's harvested contracts. Microsoft publishes no llms.txt of its own — /llms.txt was probed on learn.microsoft.com, azure.microsoft.com and www.microsoft.com on 2026-09-17 and all returned 404. ## What you are calling - Base URL: https://management.azure.com - Auth: OAuth2 bearer only. No API keys. Token scope https://management.azure.com/.default from Microsoft Entra ID; discovery at https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration - Every request must carry ?api-version=YYYY-MM-DD. Omitting it is a 400 before the call is routed. Current stable 2026-01-01; the contract harvested here is 2025-03-01. - Authorization is two-layered: a valid token, then Azure RBAC per resource. Network Contributor covers the Private Link actions. ## Contracts - [Private endpoint (Swagger 2.0, verbatim)](openapi/_original/microsoft-azure-private-link-private-endpoint-swagger.json): 11 operations — private endpoints and private DNS zone groups - [Private link service (Swagger 2.0, verbatim)](openapi/_original/microsoft-azure-private-link-private-link-service-swagger.json): 13 operations — private link services, endpoint connections, visibility - [Upstream source](https://github.com/Azure/azure-rest-api-specs/tree/main/specification/network/resource-manager/Microsoft.Network/Network/stable/2025-03-01): Microsoft's own specification repository ## Documentation - [Private Link overview](https://learn.microsoft.com/en-us/azure/private-link/private-link-overview) - [Private link service overview](https://learn.microsoft.com/en-us/azure/private-link/private-link-service-overview) - [Private endpoints REST reference](https://learn.microsoft.com/en-us/rest/api/virtualnetwork/private-endpoints) - [Private link services REST reference](https://learn.microsoft.com/en-us/rest/api/virtualnetwork/private-link-services) - [Availability matrix — which Azure services support Private Link](https://learn.microsoft.com/en-us/azure/private-link/availability) - [Create a private endpoint (quickstart)](https://learn.microsoft.com/en-us/azure/private-link/create-private-endpoint-portal) - [FAQ](https://learn.microsoft.com/en-us/azure/private-link/private-link-faq) - [Azure REST API conventions](https://learn.microsoft.com/en-us/rest/api/azure/) ## The four things that trip up a first integration 1. NINE OF 24 OPERATIONS ARE LONG-RUNNING. Creating a private endpoint returns 201 immediately and the endpoint is not usable yet. Poll the URL in the Azure-AsyncOperation header until provisioningState is Succeeded, Failed or Canceled. Treating 202 as success is the most common mistake here. 2. AN ENDPOINT WITHOUT A DNS ZONE GROUP RESOLVES NOTHING. The private endpoint gets a private IP; the PaaS hostname still resolves publicly until you attach a privateDnsZoneGroup (or write your own records from properties.customDnsConfigs). Two API calls, not one. 3. CONNECTIONS ARE A TWO-PARTY STATE MACHINE. The consumer's privateLinkServiceConnectionState and the producer's privateEndpointConnection carry the same status field: Pending, Approved, Rejected, Disconnected. A manual connection sits Pending until the producer acts. And the reversal is asymmetric — Approved can go back to Rejected, but a Rejected connection cannot be re-approved; the consumer must delete and recreate the endpoint. 4. DELETES ARE FINAL. There is no soft delete, restore or recycle bin for a private endpoint, private link service or endpoint connection, and no retention window is published. Read the resource and keep the body before you delete it — that capture is the only rollback that exists. ## Operations Consumer side (private endpoints): PrivateEndpoints_CreateOrUpdate, PrivateEndpoints_Get, PrivateEndpoints_List, PrivateEndpoints_ListBySubscription, PrivateEndpoints_Delete, AvailablePrivateEndpointTypes_List, AvailablePrivateEndpointTypes_ListByResourceGroup, PrivateDnsZoneGroups_CreateOrUpdate, PrivateDnsZoneGroups_Get, PrivateDnsZoneGroups_List, PrivateDnsZoneGroups_Delete Producer side (private link services): PrivateLinkServices_CreateOrUpdate, PrivateLinkServices_Get, PrivateLinkServices_List, PrivateLinkServices_ListBySubscription, PrivateLinkServices_Delete, PrivateLinkServices_GetPrivateEndpointConnection, PrivateLinkServices_ListPrivateEndpointConnections, PrivateLinkServices_UpdatePrivateEndpointConnection, PrivateLinkServices_DeletePrivateEndpointConnection, PrivateLinkServices_CheckPrivateLinkServiceVisibility, PrivateLinkServices_CheckPrivateLinkServiceVisibilityByResourceGroup, PrivateLinkServices_ListAutoApprovedPrivateLinkServices, PrivateLinkServices_ListAutoApprovedPrivateLinkServicesByResourceGroup ## Runtime semantics - [Conventions — idempotency, pagination, async, reversibility](conventions/microsoft-azure-private-link-conventions.yml) - [Errors — the ARM envelope, not RFC 9457](errors/microsoft-azure-private-link-problem-types.yml) - [Rate limits — ARM token bucket plus Microsoft.Network ceilings](rate-limits/microsoft-azure-private-link-rate-limits.yml) - [Authentication](authentication/microsoft-azure-private-link-authentication.yml) and [scopes](scopes/microsoft-azure-private-link-scopes.yml) - [Data model](data-model/microsoft-azure-private-link-data-model.yml) - [Lifecycle, SLA, status](lifecycle/microsoft-azure-private-link-lifecycle.yml) ## SDKs and tools - npm @azure/arm-network 39.0.0, PyPI azure-mgmt-network 32.0.0, NuGet Azure.ResourceManager.Network 1.17.0, Maven com.azure.resourcemanager:azure-resourcemanager-network 2.51.0, Go .../resourcemanager/network/armnetwork/v7 v7.2.0 - Azure CLI: az network private-endpoint, az network private-link-service - The Ruby gem azure_mgmt_network last shipped 2021-03-11 and is retired — do not start there. - [Full package inventory with versions and dates](packages/microsoft-azure-private-link-packages.yml) ## Pricing Metered consumption, no plans and no free tier. Private endpoint $0.01/hour; data processed $0.01/GB graduating to $0.006 above 1 PB and $0.004 above 5 PB, billed separately inbound and outbound. Publishing a private link service is free — the consumer's endpoint is what bills. List prices read 2026-09-17 from the Azure Retail Prices API. [Detail](plans/microsoft-azure-private-link-plans-pricing.yml) · [Pricing page](https://azure.microsoft.com/en-us/pricing/details/private-link/) ## Optional - [Status](https://azure.status.microsoft/en-us/status) — HTML only, no public JSON or RSS health feed - [SLA](https://azure.microsoft.com/en-us/support/legal/sla/private-link/) - [Azure Updates / retirements](https://azure.microsoft.com/en-us/updates/?updateType=retirements) - [Security disclosure](https://www.microsoft.com/.well-known/security.txt) — MSRC - There is no MCP server and no A2A agent card for Azure Private Link. Microsoft's first-party Azure MCP Server exists but ships no Private Link tools; see mcp/microsoft-azure-private-link-mcp.yml.