# Microsoft Power Platform > Microsoft Power Platform is a low-code application platform - Power Apps, Power Automate, > Power Pages, Power BI and Copilot Studio - built on Microsoft Dataverse. Its programmable > surface is three things: the Dataverse Web API (OData v4, per-environment host), the Power > Platform API (api.powerplatform.com, tenant-scoped administration), and the Microsoft.PowerPlatform > Azure Resource Manager provider (enterprise policies for encryption, lockbox and network injection). > Microsoft also ships a first-party Dataverse MCP server, in preview. Generated by API Evangelist on 2026-09-06 from this repository's apis.yml and artifacts. Microsoft does not publish an llms.txt on learn.microsoft.com, powerplatform.microsoft.com or microsoft.com (all probed 2026-09-06, HTTP 404), so this file is generated, not harvested. ## Authentication Every surface uses Microsoft Entra ID OAuth 2.0 bearer tokens. There are no API keys and no test/live key pair. - Dataverse: token audience is the environment, https://{org}.api.crm.dynamics.com/.default - Power Platform API: audience api.powerplatform.com; the tenant is inferred from the token - Register the app and grant permissions: https://learn.microsoft.com/en-us/power-platform/admin/programmability-authentication-v2 - Permission reference: https://learn.microsoft.com/en-us/power-platform/admin/programmability-permission-reference ## APIs - [Microsoft Dataverse Web API](https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/overview): OData v4 CRUD, actions, functions and metadata over the Dataverse data platform. Base https://{org}.api.crm.dynamics.com/api/data/v9.2/ - [Power Platform API](https://learn.microsoft.com/en-us/rest/api/power-platform/): tenant administration - licensing, environment management, governance, Power Pages, Copilot Studio, connectivity. Base https://api.powerplatform.com/{namespace}/{resource}?api-version={version} - [Power Platform enterprise policies (ARM)](https://learn.microsoft.com/en-us/rest/api/power-platform/): customer-managed keys, customer lockbox, VNet injection and private link. Base https://management.azure.com - [Power Platform connectors](https://learn.microsoft.com/en-us/connectors/overview): several hundred prebuilt integrations, plus custom connectors defined with OpenAPI 2.0 ## Agent surfaces - Dataverse MCP server (preview). Remote: https://{org}.crm.dynamics.com/api/mcp. Local stdio: `npx -y @microsoft/dataverse mcp https://yourorg.crm.dynamics.com` - Tools: create_record, read_query, update_record, delete_record, list_tables, describe_table, create_table, update_table, delete_table, search, fetch - Both require the Dataverse MCP feature enabled for the environment AND the client app id allow-listed in the Power Platform admin center. There is no anonymous access. - No A2A agent card is published; /.well-known/agent-card.json and /.well-known/agent.json 404 or return an SPA shell on every host. ## Runtime rules an agent must know - Throttling: HTTP 429 with Retry-After in seconds. Honor it exactly. Per user per web server: 6,000 requests / 1,200s execution time in a 300s sliding window, and ~52 concurrent requests. - Separately, each licence carries a 24-hour request entitlement (40,000 for a standard paid licence, 6,000 for per-app and seeded licences). - Idempotency is PARTIAL. There is no Idempotency-Key header. Updates, deletes and upserts are made safe with ETag conditional requests (If-Match / If-None-Match); a retried POST create WILL create a duplicate. Generate the GUID client-side and upsert instead. - Errors are the OData v4 error object, not RFC 9457 problem+json. Throttling codes: 0x80072322 (request count), 0x80072321 (execution time), 0x80072326 (concurrency). - Pagination is server-driven: follow @odata.nextLink, do not compute offsets. - Reversibility: there is no per-record undo. Environment restore from backup covers 7 days (28 for production managed environments); a deleted environment is recoverable for 7 days (28 days for production environments with Dynamics 365 apps). Trial environments are not backed up at all. ## SDKs and tooling - .NET: Microsoft.PowerPlatform.Dataverse.Client 1.2.27 (2026-09-04), Microsoft.PowerPlatform.Management 2.0.3503.299 (2026-08-05) - Python: powerplatform-management 2.0.3503.299 (2026-08-05), powerplatform-dataverse-client 1.0.0 (2026-05-29) - JavaScript: @microsoft/dataverse 1.0.77 (2026-09-03) - CLI plus the stdio MCP proxy - CLI: `pac` (Power Platform CLI) 2.11.2, 25 command groups. Install with `dotnet tool install --global Microsoft.PowerApps.CLI.Tool` ## Events - Dataverse webhooks: register a step on any message and table; Dataverse POSTs a serialized RemoteExecutionContext. 60-second timeout, one retry and only on 502/503/504, 256 KB payload ceiling. https://learn.microsoft.com/en-us/power-apps/developer/data-platform/use-webhooks - No AsyncAPI document is published. ## Commercial - Free: Power Apps Developer Plan - 3 developer environments, 2 GB Dataverse, 750 flows/month, development use only. https://www.microsoft.com/en-us/power-platform/products/power-apps/free - Power Apps Premium $22 per user/month paid yearly ($14 at 2,000+ seats). Dataverse capacity add-on $40 per GB/month. - Pricing: https://www.microsoft.com/en-us/power-platform/products/power-apps/pricing ## Optional - Changelog (monthly, per endpoint): https://learn.microsoft.com/en-us/power-platform/admin/programmability-whats-new-changed - Deprecations: https://learn.microsoft.com/en-us/power-platform/important-changes-coming - Release plans: https://learn.microsoft.com/en-us/power-platform/release-plan/ - Rate limits: https://learn.microsoft.com/en-us/power-apps/developer/data-platform/api-limits - Security disclosure: https://www.microsoft.com/.well-known/security.txt - Trust Center: https://www.microsoft.com/en-us/trust-center/product-overview