# ALM X++ MCP server

> Search and analyze Dynamics 365 Finance & Operations X++ code, and work with Azure DevOps work items, wikis and pull requests.

- Listing: https://mcp.tc/i/alm-x
- Connect: use the server's own URL `https://api.almxpp.com/mcp` (with your API key); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: API key
- Category: [Developer Tools](https://mcp.tc/c/developer-tools)
- Vendor: alimbenhelal-pro
- Homepage: <https://www.almxpp.com>
- Repository: <https://github.com/alimbenhelal-pro/ALM-XPP-MCP>
- Package: npm `almxppmcp`

## About

ALM X++ answers D365 Finance & Operations questions from a prebuilt index of the standard codebase: over 200K AOT objects, 25M+ cross-references and label translations. Tools cover code search, object details, references and callers, change impact, extension strategy, best-practice checks, query generation and security reports. It also includes Azure DevOps tools for work items, wikis and X++ pull request review, plus Data Management Framework and OData import helpers.

It runs as a hosted streamable-http endpoint, or locally through the npx launcher almxppmcp. Both need an API token from almxpp.com, sent as the X-API-Key header or, for the npx launcher, in ALMXPPMCP\_API\_KEY. Azure DevOps tools need DEVOPS\_ORG\_URL and DEVOPS\_PAT. Some tools write data or modify work items.

## What it can do

- Search D365 F&O X++ code, tables, classes and forms by keyword or concept
- Get object details, relations and full context for an exact AOT object
- Find references, callers and change impact before editing an object
- Recommend extension strategy such as Chain of Command or event handlers
- Run best-practice audits and refactoring suggestions on X++ objects
- Query, update and analyze Azure DevOps work items and wiki pages
- Review X++ pull requests and analyze their impact
- Import data through DMF and OData upsert tools

## Tools (90)

- `validate_best_practices`: Run an in-house best-practice audit on an AOT object from the indexed source. (read-only)
- `find_extensions`: Find extension objects, CoC classes and event handlers for a base object. (read-only)
- `dmf_import_file`: Bulk-import a CSV into a D365 F&O entity through the Data Management package API. (can modify or delete data)
- `search_d365_code`: Search the knowledge base for X++ code, tables, classes, forms and views. (read-only)
- `dmf_transform_excel`: Transform a multi-sheet Excel file into DMF-ready rows using a JSON mapping.
- `generate_query`: Generate X++ select or T-SQL for D365 tables with joins and filters. (read-only)
- `ado_wiki_delete_page`: Delete an Azure DevOps wiki page and its sub-pages. (can modify or delete data)
- `appinsights_diagnose_slowness`: Diagnose slow D365 environments using Application Insights telemetry. (read-only)
- `ado_wiki_list`: List all wikis in an Azure DevOps project. (read-only)
- `get_object_details`: Get details of a D365 object by its exact name. (read-only)
- `ado_query_workitems`: Query Azure DevOps work items such as bugs, tasks, FDDs and user stories. (read-only)
- `dmf_apply_entity_filter`: Apply a single-field value filter to an entity row of a DMF project.
- `ado_update_workitem`: Update fields on an existing Azure DevOps work item. (can modify or delete data)
- `find_references`: Scan the full index for all usages of an object, method, field or label. (read-only)
- `ado_gap_fit_analysis`: Classify a requirement as standard, configuration, extension or gap. (read-only)
- `batch_search`: Run multiple D365 searches in parallel. (read-only)
- `ado_read_attachment`: Read the content of a file attached to an Azure DevOps work item. (read-only)
- `trace_field_lineage`: Trace who writes and reads a table field, plus forms and reports using it. (read-only)
- `plan_and_execute`: Execute a multi-step JSON plan by chaining tools in one call. (can modify or delete data)
- `find_similar_implementations`: Find D365 objects structurally similar to a given one. (read-only)
- `recommend_extension_strategy`: Advise between table extension, Chain of Command, event handler or delegate. (read-only)
- `diff_model_versions`: Compare two knowledge base snapshots into a changelog. (read-only)
- `find_related_objects`: Return outgoing relations and incoming back-references for an object. (read-only)
- `ado_review_xpp_pr`: Produce a structured review of a pull request that changes X++ objects. (read-only)
- `dmf_create_data_project`: Create or extend a DMF export or import data project through OData.
- `find_entity_for_table`: Find the OData entity for a table, or generate an entity template. (read-only)
- `summarize_for_stakeholder`: Rewrite technical tool output for a chosen audience. (read-only)
- `suggest_refactoring`: Suggest refactorings for an X++ object or method before a PR merge. (read-only)
- `resync_devops_index`: Force a full re-download and re-index of an Azure DevOps custom model. (can modify or delete data)
- `ado_wiki_get_page`: Read an Azure DevOps wiki page and its sub-page paths. (read-only)
- `dmf`: Consolidated Data Management Framework tool with an action parameter.
- `find_callers`: Show callers, callees, inheritance and overrides for a class or method. (read-only)
- `healthcheck`: Report server status, loaded D365 version and index state. (read-only)
- `ado_analyze_pr_impact`: Analyze what changed in a pull request and its impact. (read-only)
- `find_error_patterns`: Explain a D365 error message or exception and suggest causes. (read-only)
- `suggest_edt`: Find the best existing extended data type for a new table field. (read-only)
- `get_object_context`: Return structure, methods, relations and validation of an object in one call. (read-only)
- `odata_upsert_rows`: Idempotently import rows into an entity via OData PATCH or POST. (can modify or delete data)
- `find_change_impact`: Blast-radius report of callers and dependents for a planned change. (read-only)
- `generate_security_report`: Report roles, duties, privileges and license needs for indexed models. (read-only)
- `ado_create_task`: WHEN: user asks to create a DevOps Task or start development on a Work Item.
- `appinsights_set_connection`: Securely register the D365 F&O environment's Application Insights / Log Analytics connection for the CURRENT session.
- `dmf_get_job_status`: Poll the status of a DMF import/export execution by its executionId (e.g. (read-only)
- `detect_performance_issues`: Profile an X++ object for N+1 queries, queries in loops, missing field lists, row-by-row inserts/updates, missing firstOnly. (read-only)
- `get_relation_graph`: WHEN: you need the COMPLETE bidirectional relation graph for an object in ONE call. (read-only)
- `d365fo_clear_connection`: Removes the D365 F&O connection cached for the current session by d365fo\_set\_connection.
- `generate_xpp_template`: WHEN: writing an extension or customization -- generates ready-to-use X++ code. (read-only)
- `get_security_coverage_for_object`: WHEN: developer/security architect needs to know WHICH ROLES can access a specific form, table, menu item or service operation. (read-only)
- `get_output_page`: Retrieve the NEXT page of a previously PAGINATED tool output. (read-only)
- `ado_pr_dependency_map`: PR DEPENDENCY MAP -- Scan multiple Pull Requests and build a cross-PR dependency graph based on (a) shared X++/AOT objects and (b) branch chain relationships. (read-only)
- `generate_fdd`: WHEN: user asks to write or generate a Functional Design Document, FDD, functional spec, CdC, or cahier des charges. (read-only)
- `map_business_process`: WHEN: mapping the technical D365 objects behind a business process, or understanding which tables/forms implement a flow. (read-only)
- `ado_post_comment`: WHEN: user explicitly asks to post, add, or save a comment to an ADO Work Item.
- `get_data_entity_info`: WHEN: developer building an OData / DMF integration needs a quick rundown of a specific data entity: its public OData name, datasources, key fields, and IsPublic status. (read-only)
- `compare_objects`: Compare two D365 F&O objects side-by-side (fields, methods, signatures). (read-only)
- `list_objects`: WHEN: you need ALL objects of a given type or in a given model. (read-only)
- `explain_workflow`: WHEN: user asks how an approval workflow works, who approves a document, what states it goes through, or what happens on submission/rejection. (read-only)
- `trace_role_license_tree`: WHEN: security design, licence audit, or 'what licence does this role require?'. (read-only)
- `prepare_release_note_context`: WHEN: building an AI-assisted D365 F&O upgrade release note (regressions + opportunities) for a specific client, and you (the calling assistant) want to do the reasoning yourself instead of the server calling its own… (read-only)
- `ado_analyze_workitem`: AZURE DEVOPS ONLY -- Fetch a Work Item and assemble ALL technical context needed for D365 F&O expert analysis. (read-only)
- `ado_wiki_create_or_update_page`: AZURE DEVOPS ONLY -- Create a new wiki page, or OVERWRITE an existing one with new markdown content. (can modify or delete data)
- `resolve_workspace_roots`: WHEN: you need to know which folder(s) are configured as the workspace/project root for the current caller. (read-only)
- `resolve_client_profile`: WHEN: at the START of any release-note / upgrade-impact conversation -- call this BEFORE list\_release\_note\_inputs to check whether a Client Profile already exists for the CURRENT caller's Azure DevOps org/project… (read-only)
- `generate_unit_test`: WHEN: developer needs to write or scaffold unit tests for a custom D365 object. (read-only)
- `create_aot_object`: Generate a complete, ready-to-deploy D365 F&O AOT XML scaffold for any object type. (read-only)
- `d365fo_set_connection`: Securely register the D365 F&O connection (URL + Entra app-registration credentials) for the CURRENT session.
- `appinsights_clear_connection`: Removes the Application Insights connection cached for the current session by appinsights\_set\_connection.
- `generate_data_entity`: WHEN: developer needs to CREATE a data entity (AxDataEntityView) AOT XML from a table for OData/DMF/data migration. (read-only)
- `find_event_handlers`: Find all event handlers that subscribe to events on a D365 table or class. (read-only)
- `generate_xpp_form`: Generate a complete, compilable AxForm AOT XML with the CORRECT control serialization (\<AxFormControl xmlns="" i:type="..."\>) for the requested pattern. (read-only)
- `appinsights_query`: Run a raw KQL (Kusto) query against the D365FO environment's Application Insights / Log Analytics workspace (read-only -- the query language has no mutation operators). (read-only)
- `search_context_docs`: WHEN: the user asks about business/functional context that lives OUTSIDE the D365 code KB -- specs, functional design docs, mapping sheets, contracts, meeting notes, screenshots' captions -- anything an admin uploaded… (read-only)
- `trace_security_chain`: WHEN: security audit -- need the TECHNICAL chain from Role/Duty/Privilege to Entry Points and Table/Form permissions. (read-only)
- `find_relation_path`: WHEN: you need to know HOW two AOT objects are connected -- the chain of relations linking them. (read-only)
- `ado_estimate_effort`: WHEN: user asks for an effort estimate, chiffrage, or development hours for a D365 Work Item. (read-only)
- `ado_list_prs`: \[~\] PRIORITY TRIGGER: Use this tool when user mentions 'PR', 'Pull Request', 'list PRs', 'show PRs', 'active PRs', 'mes PR', 'liste des PR', 'pull requests ouverts', 'what PRs are open', 'PRs by \[author\]', 'PRs… (read-only)
- `validate_object_naming`: WHEN: developer needs to check that a proposed object name follows D365 + ISV naming conventions, is unique against the indexed KB, and does not collide with a reserved or standard prefix. (read-only)
- `generate_diagram`: WHEN: generating a visual diagram of D365 table relationships or security chains. (read-only)
- `save_client_profile`: WHEN: no profile was found by resolve\_client\_profile and the user wants one created (or updated) for their client, so future release-note requests never need v1/v2/customModelIds again. (can modify or delete data)
- `dmf_export_package`: Trigger a bulk export through the Data Management package REST API and return the download URL when complete.
- `ado_post_pr_comment`: WHEN: user explicitly asks to post, add, or save a review comment to an ADO Pull Request.
- `list_release_note_inputs`: WHEN: ALWAYS call this FIRST, before prepare\_release\_note\_context -- it discovers the exact D365FO version strings and custom model ids actually indexed on THIS server, which you cannot guess. (read-only)
- `federated_search`: Fan-out search across multiple ALM XPP MCP server instances in parallel and merge results using Reciprocal Rank Fusion (RRF). (read-only)
- `search_labels`: Search D365 F&O labels across all indexed languages. (read-only)
- `odata_export_entity`: Export any D365 F&O data entity via OData (transactional, no DMF project required). (read-only)
- `list_custom_model_objects`: WHEN: developer wants to see what custom/extension objects exist in their model. (read-only)
- `analyze_upgrade_impact`: WHEN: upgrading D365 F&O to a new version or applying a Microsoft update -- check if your custom code will break. (read-only)
- `fix_best_practice_violations`: WHEN: validate\_best\_practices returned violations and you want concrete X++ fix suggestions. (read-only)
- `generate_release_note_document`: WHEN: you have already called prepare\_release\_note\_context and analyzed its 'objects' array yourself, producing a findings JSON array per the 'instructions' field it returned.
- `get_menu_item_info`: WHEN: developer needs to resolve a menu item -- find its target object (form / action / output), linked security privilege, label, and parameters. (read-only)

## Example prompts

- "Find all extensions of SalesTable and show the Chain of Command classes."
- "Generate an X++ select joining CustTable and CustTrans for one customer group."
- "What breaks if I change the method validateWrite on VendInvoiceJour?"
- "Review Azure DevOps pull request 1234 for X++ impact."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http alm-x https://api.almxpp.com/mcp --header "X-API-Key: <YOUR_API_KEY>"
```

2. Replace the placeholder with your key before you run it, then check it with `/mcp` inside Claude Code.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Use the `mcp-remote` bridge, which keeps the key on this computer (a connector added on claude.ai with the key under **Request headers** also shows up here). Open **Settings → Developer → Edit Config** and add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "alm-x": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://api.almxpp.com/mcp",
        "--header",
        "X-API-Key: <YOUR_API_KEY>"
      ]
    }
  }
}
```

2. Replace the placeholder with your key and restart Claude Desktop.

The bridge needs Node.js on your computer.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=ALM%20X%2B%2B&connectorUrl=https%3A%2F%2Fapi.almxpp.com%2Fmcp>) (opens connector settings)

2. Check that the URL reads `https://api.almxpp.com/mcp`. Under **Request headers**, add `X-API-Key: <YOUR_API_KEY>` with your key from alimbenhelal-pro, then click **Add**.

3. Turn it on in a chat from the tools menu.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=alm-x&config=eyJ1cmwiOiJodHRwczovL2FwaS5hbG14cHAuY29tL21jcCIsImhlYWRlcnMiOnsiWC1BUEktS2V5IjoiPFlPVVJfQVBJX0tFWT4ifX0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "alm-x": {
      "url": "https://api.almxpp.com/mcp",
      "headers": {
        "X-API-Key": "<YOUR_API_KEY>"
      }
    }
  }
}
```

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the key the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "alm-x": {
      "type": "http",
      "url": "https://api.almxpp.com/mcp",
      "headers": {
        "X-API-Key": "${input:x-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "x-api-key",
      "description": "X-API-Key",
      "password": true
    }
  ]
}
```

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "alm-x": {
      "serverUrl": "https://api.almxpp.com/mcp",
      "headers": {
        "X-API-Key": "<YOUR_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add alm-x --url https://api.almxpp.com/mcp
```

`codex mcp add` can’t set the `X-API-Key` header, so this step is required: put this entry in `~/.codex/config.toml` instead of running the command, or add its `env_http_headers` line to the entry the command made:

`config.toml`:

```toml
[mcp_servers.alm-x]
url = "https://api.almxpp.com/mcp"
env_http_headers = { "X-API-Key" = "X_API_KEY" }
```

Codex reads the header values from the environment variables named in `env_http_headers`.

### Gemini CLI

```bash
gemini mcp add --transport http --header "X-API-Key: <YOUR_API_KEY>" alm-x https://api.almxpp.com/mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "alm-x": {
      "type": "http",
      "url": "https://api.almxpp.com/mcp",
      "headers": {
        "X-API-Key": "<YOUR_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://api.almxpp.com/mcp`.

## Recent changes

- 2026-10-06 21:21 UTC: Tracking started: 90 tools read. Source: automatic check.

More on the History tab, with descriptions before and after for the newest entries: https://mcp.tc/i/alm-x#history (Atom feed: https://mcp.tc/i/alm-x/history.xml). It records what mcp.tc's anonymous checks saw, every 3 hours where the tool list can be read without sign-in; it is not a security review.

## Details

- Server version: 1.5.518
- MCP protocol version: 2026-07-28
- Last checked: 2026-10-07 (reachable)
- Listed: 2026-10-05
- Updated: 2026-10-07

---
Source: https://mcp.tc/i/alm-x (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
