Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Not through the documented on-premises data gateway custom-connector route. Microsoft’s custom connector FAQ excludes API-key authentication when that route uses the gateway. If your MCP server is reachable from Copilot Studio, its MCP onboarding wizard supports an API key sent in a header or query parameter. Microsoft’s documentation does not describe a stateless exception to the gateway limitation.

Which connection route fits your MCP server?

Copilot Studio documents two ways to connect to an existing MCP server: the MCP onboarding wizard and a Power Apps custom MCP connector. Choose based on endpoint reachability, authentication requirements, and whether the server API needs the custom-connector path.

Route When it fits Authentication and technical details
MCP onboarding wizard The MCP endpoint is reachable from Copilot Studio and you want to connect it directly. Supports no authentication, API key, or OAuth 2.0. An API key can be sent in a header or query parameter. Microsoft describes this route as supporting Streamable transport. Microsoft’s existing-server connection guide.
Power Apps custom MCP connector You need a custom connector, including for a private API accessed through an on-premises data gateway. The MCP example uses an OpenAPI 2.0 YAML schema and the x-ms-agentic-protocol: mcp-streamable-1.0 metadata. The gateway route does not support API-key authentication. Microsoft’s MCP connector example; custom connector FAQ.

Why the gateway and API key do not combine in the documented route

Microsoft presents the on-premises data gateway as an option for connecting custom connectors to private APIs. But its custom connector FAQ lists the authentication option as “API Key (except on-premises data gateway).” That is the compatibility limit for the documented gateway path.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Stateless” does not change that conclusion: Microsoft’s reviewed pages do not document a stateless exception. If your endpoint is private and API-key authentication is mandatory, the official documentation reviewed here does not establish a supported direct way to satisfy both requirements through that gateway route. A particular deployment might use an intermediary or authentication bridge, but Microsoft’s pages do not establish that arrangement as a supported solution.

Connect directly with an API key when the endpoint is reachable

  1. In Copilot Studio, add an MCP tool using the existing-server connection flow.
  2. Enter the server name, description, and URL.
  3. Choose API key authentication.
  4. Select Header or Query, then enter the corresponding header or query-parameter name and key as prompted.

Microsoft’s existing-server guide describes API keys in either a request header or query parameter. This direct route depends on Copilot Studio being able to reach the MCP server; it is not a way to pass a private endpoint through the on-premises gateway.

Use a custom MCP connector for the gateway route

For the custom-connector approach, describe the MCP endpoint with an OpenAPI 2.0 YAML schema. Microsoft’s example uses HTTPS, a POST operation, and x-ms-agentic-protocol: mcp-streamable-1.0. Import the OpenAPI file in Power Apps and complete connector setup there, following the MCP connector instructions.

The sample is illustrative: replace its fictional host and operation details with the actual service specification. Microsoft’s custom connector FAQ says custom connectors currently support OpenAPI 2.0 rather than OpenAPI 3.0. For gateway use, select an authentication type supported by that route instead of API key.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check governance and agent requirements

Copilot Studio MCP access relies on Power Platform connectors. As a result, data policies that regulate connectors also govern access to MCP servers and their tools. MCP use also requires generative orchestration. See Microsoft’s MCP connection guidance and MCP tools and resources guidance.

  • Confirm the endpoint is reachable through the route you intend to use.
  • Check tenant data policies and connector governance before enabling access.
  • Describe external server tools clearly and expose only the tools needed for the agent’s task.
  • Validate gateway configuration and server-side authentication behavior in your own environment; product documentation does not establish the behavior of every deployment or intermediary.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.