Skip to main content
AI client guides

Connect Microsoft Copilot Studio to StackJack

Microsoft Copilot Studio adds MCP servers as agent tools (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). Copilot Studio connects to StackJack with OAuth 2.0…

Written By Christopher Scaminaci

Last updated 6 days ago

Microsoft Copilot Studio adds MCP servers as agent tools (MCP is the Model Context Protocol, the open standard AI tools use to call external tools). Copilot Studio connects to StackJack with OAuth 2.0 → Dynamic discovery: you enter the server URL, sign in with your StackJack account in the browser, and tools import automatically.

Connector or agent? A Copilot Studio agent is one of two ways to use StackJack from Microsoft Copilot. To surface StackJack data in everyday Microsoft 365 Copilot chat instead — an org-wide connector that each user signs into as themselves — see Connect Microsoft 365 Copilot.

Prerequisites

  • A Copilot Studio environment and an agent with generative (dynamic) orchestration turned on — MCP tools require it.
  • A StackJack account that is a member of your workspace (the connection signs in as that member).
  • Your StackJack MCP endpoint URL, copied from the MCP Setup page in the portal — that card shows the address for your workspace's region. The examples here use the US addresses https://mcp.stackjack.io/mcp and the recommended compact address https://compact.stackjack.io/mcp (see Tool limits). Other regions have their own hostnames; see Your region and your endpoint.

Copilot Studio speaks MCP over Streamable HTTP only (it dropped the older SSE transport in August 2025) — StackJack uses Streamable HTTP, so no transport configuration is needed.

Connect with Dynamic discovery

  1. Confirm generative (dynamic) orchestration is on for the agent.

  2. Go to copilotstudio.microsoft.com → Agents → create or edit an agent.

  3. Go to Tools → Add a tool → New tool → Model Context Protocol.

  4. Fill in these fields:

    FieldValue
    Server nameStackJack
    DescriptionRequired — the model uses it to decide when to call StackJack, so describe what your connectors do (for example "MSP PSA and RMM tools: tickets, assets, patching")
    Server URLhttps://compact.stackjack.io/mcp — the compact endpoint, recommended because Copilot Studio limits how many tools it accepts per MCP server (see Tool limits). For the full catalog use https://mcp.stackjack.io/mcp.
    AuthenticationOAuth 2.0 → Dynamic discovery
  5. Select Create → Next → Create a new connection, sign in with your StackJack account, then select Add to agent. Tools import automatically.

Large catalog? Copilot Studio limits how many tools it accepts per MCP server, so use StackJack's compact endpoint https://compact.stackjack.io/mcp — Copilot Studio then receives a small, searchable tool list automatically, with nothing to enable first. See Tool limits.

Per-agent least privilege

A Dynamic discovery connection carries the identity — and the tool access — of the StackJack member who signs it in. To give each Copilot agent its own narrow tool scope:

  1. Invite a dedicated StackJack member for the agent (for example agent-time-entry@yourdomain).
  2. On the Team page, restrict that member's allowed tools to exactly the set the agent needs. The allowed-tools list on the member is the authorization boundary — the connection can never exceed it.
  3. Sign the Copilot Studio connection in as that member.

One member per agent gives you per-agent scoping, per-agent usage attribution, and a per-agent kill switch (remove the member, the agent stops).

Several people on one tool

One Copilot Studio tool serves your whole team. Each person signs in with their own StackJack account, and a connection always runs with the tools and connector access of the person who signed in on it — so HaloPSA and the other per-user connectors see the right person.

  1. Sign in to Copilot Studio as the person who needs access.
  2. Open the agent, then Tools, then the StackJack tool.
  3. On the connection step, create a new connection. A connection that is already there also connects, but it keeps running as the person who signed in on it.
  4. Sign in with that person's own StackJack account. They must be an active member of your workspace.

The person who signs in is the person StackJack sees. So when someone needs their own access, have them do their own sign-in — creating a new connection and signing in as that person is the surest way to get it. Connections that work today keep working, and nobody has to reconnect.

To see who is connected, or to turn one person off, open Team in StackJack and expand that member's row. Under Shared connections, Turn off stops that person on their next request and leaves everyone else on the same tool working; Turn back on restores them. You must be a team admin to use either.

If a sign-in answers "This connection belongs to a different StackJack organization", the tool was set up by someone outside your workspace. Create a new connection, and sign in with an account in your own organization. If it still fails, open a support ticket with the tool name and the sign-in email.

If a sign-in says an administrator turned that person's access off, restore it from the Team page and have them sign in again. If the Team page says StackJack support turned it off, contact support — a team admin cannot restore that one.

Why Manual OAuth is not the path here

Older versions of this guide described a Manual OAuth setup that pasted a generated MCP client credential into Copilot Studio's OAuth fields (Authorization URL https://mcp.stackjack.io/authorize, Token URL https://mcp.stackjack.io/token). Use Dynamic discovery instead. The reasons, stated precisely:

  • StackJack's authorization endpoint requires PKCE with the S256 code challenge on every request. Copilot Studio's Manual OAuth configuration is not documented to send PKCE, and a request without S256 is refused before anything else is evaluated.
  • An organization-wide MCP credential (created by an admin on the Endpoints page) can complete the browser authorization flow when the client does everything right — including PKCE and presenting the client secret when the code is redeemed. A personal MCP credential (auto-created for an individual sign-in) cannot: it is refused at authorization.
  • Dynamic discovery handles all of this for you: you enter the server URL, sign in as yourself, and the tokens carry your identity and your allowed-tools boundary.

If you have an old Manual OAuth connection, edit the tool and switch Authentication to OAuth 2.0 → Dynamic discovery, then create a new connection.

Generated MCP client credentials themselves remain fully supported — they authenticate harnesses that send HTTP Basic or Bearer headers directly (n8n, Cline, custom integrations), and organization-wide ones also serve connector UIs that only speak the browser authorization flow.

Tool limits

Copilot Studio limits how many tools it accepts per MCP server, and StackJack can expose hundreds depending on your connectors and plan, so you will exceed it quickly.

Two cautions about the number itself:

  • It is an observed limit, not a published one. StackJack verified it in practice; Microsoft's published quotas do not document a per-server MCP tool cap. The figure StackJack works from is in Client tool limits, which is the one place it is maintained.
  • Copilot Studio and GitHub Copilot in VS Code are different products with different limits. Do not carry a number from one to the other. That confusion is exactly what this section was corrected for.

Keeping the served catalog small matters beyond the per-server count. Two other limits apply at the same time. Copilot Studio's generative orchestration works within a separate per-agent tool budget, documented by Microsoft and counted across every tool the agent has — a different denominator from the per-server cap above. It also limits how large a single connector-action response may be. So a full multi-thousand-tool catalog can fail to load regardless of the per-server number. The options below keep StackJack's served list small enough to stay clear of all of these, best first:

  • Connect to the compact endpoint (recommended). Set the wizard's Server URL to https://compact.stackjack.io/mcp instead of https://mcp.stackjack.io/mcp. Requests arriving on that address are served a compact catalog automatically — a small set of tools where the agent searches for and runs the rest on demand, with every tool still reachable and every permission still enforced. Copilot Studio can't carry a ?tools= query string on a server URL, so this dedicated address is how it selects the compact profile; nothing else in the setup changes, and there is nothing to enable first.
  • Set your connection to compact catalog mode. On the Connectors page, in the My AI tool catalog card of your personal sign-ins section, set the catalog mode to Compact — for this route your organization must first enable catalog modes on the Settings page. This serves your Copilot Studio connection the same small, searchable catalog with no special URL. See Choosing tools for each client and managing harness tool limits.
  • Split across dedicated members. Because the budget is counted per MCP server, connect each job as its own MCP server signed in by a dedicated member with a trimmed allowed-tools list (for example an "agent-tickets" member and an "agent-devices" member) — see Per-agent least privilege.