Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -112,7 +112,13 @@ A Toolbox exposes one MCP endpoint for its configured tools. See [Add a Toolbox]
| `FoundryFeatures` | Required `Foundry-Features` request-header value |
| `AuthorizationScope` | Microsoft Entra scope for Toolbox requests |

For a resource named `field-tools`, read `FIELD_TOOLS_URI`, `FIELD_TOOLS_FOUNDRYFEATURES`, and `FIELD_TOOLS_AUTHORIZATIONSCOPE`. Acquire an Entra token for the supplied scope, include the `Foundry-Features` header, and perform the MCP `initialize` and `tools/list` handshake against `Uri`. The composed connection string contains `Uri=https://.../toolboxes/field-tools/mcp`.
For a resource named `field-tools`, read `FIELD_TOOLS_URI`, `FIELD_TOOLS_FOUNDRYFEATURES`, and `FIELD_TOOLS_AUTHORIZATIONSCOPE`. Acquire an Entra token for the supplied scope, include the `Foundry-Features` header, and perform the MCP `initialize` and `tools/list` handshake against `Uri`.

**Example connection string:**

```
Uri=https://my-foundry.services.ai.azure.com/api/projects/my-project/toolboxes/field-tools/mcp?api-version=v1
```

Tool approval policies returned during discovery aren't enforced by the Toolbox service. Your client must inspect them and obtain approval before calling a tool.

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -355,7 +355,15 @@ await foundry

## Add a Toolbox

A [Toolbox](https://learn.microsoft.com/azure/foundry/agents/how-to/tools/toolbox) is a Foundry data-plane resource that bundles reusable tools behind a single MCP endpoint. Toolboxes don't have an ARM or Bicep representation — Aspire manages them directly through the Foundry data-plane API. Use `AddToolbox` on a Foundry project to declare one:
A [Toolbox](https://learn.microsoft.com/azure/foundry/agents/how-to/tools/toolbox) is a Foundry data-plane resource that bundles reusable tools behind a single MCP endpoint. Toolboxes don't have an ARM or Bicep representation — Aspire manages them directly through the Foundry data-plane API.

:::note[Prerequisite]
Before running `aspire run` or `aspire deploy`, ensure the identity running the command has the [Foundry User role](https://learn.microsoft.com/azure/foundry/concepts/rbac-foundry) on the Foundry project. Aspire requires this role to reconcile Toolbox versions.

Deployed compute resources that reference the Toolbox receive this role on the project automatically.
:::

Use `AddToolbox` on a Foundry project to declare one:

<Tabs syncKey='aspire-lang'>
<TabItem id='typescript' label='TypeScript'>
Expand Down Expand Up @@ -430,9 +438,9 @@ builder.Build().Run();
</TabItem>
</Tabs>

Parameter details:
The Search index named `docs` must already exist and contain data: neither `AddAzureSearch` nor `WithAISearchTool` creates or populates it. Toolbox availability depends on the Foundry service preview and its supported regions.

The identity running `aspire run` or `aspire deploy` needs the **Foundry User** role on the project to manage Toolbox versions. Deployed compute resources that reference the Toolbox receive this role on the project automatically. The Search index named `docs` must already exist and contain data: neither `AddAzureSearch` nor `WithAISearchTool` creates or populates it. Toolbox availability depends on the Foundry service preview and its supported regions.
Parameter details:

| API | Parameter | Description |
| --- | --- | --- |
Expand All @@ -450,7 +458,7 @@ MCP endpoints must be reachable from the Foundry data plane over HTTPS. Localhos
MCP approval policies are discovery metadata only. The Toolbox service doesn't enforce approval when a client calls `tools/call` — the consuming application is responsible for inspecting the returned policy and obtaining approval before invoking a tool.
</Aside>

Aspire reuses the current default Toolbox version when its configuration matches. Otherwise, it creates and promotes a new immutable version, using a deterministic configuration fingerprint to detect changes. The default consumer endpoint always serves the promoted version; set the Toolbox resource's `Version` only when a consumer must pin a specific immutable version.
Aspire reuses the current default Toolbox version when its configuration matches. Otherwise, it creates and promotes a new immutable version, using a deterministic configuration fingerprint to detect changes. The default consumer endpoint always serves the promoted version; set `FoundryToolboxResource.Version` (or the TypeScript `version` option) only when a consumer must pin a specific immutable version.

Ownership metadata provides best-effort coordination, not an atomic lease. The service doesn't expose an ETag or conditional update operation. Aspire checks ownership and the current default before promotion and verifies the result afterward, failing rather than overwriting contradictory concurrent changes.

Expand Down
Loading