Query Azure DevOps work items

flurryport:azure-devops-querydeliveryv1first-partysha256:25a845ae9f5eNeeds: read/write agent token

Query Azure DevOps work items with WIQL and read the matching ids back, without your AI ever holding the PAT.

Run a WIQL query against an Azure DevOps project and read the matching work item ids back off the replay execution. The org and project are fixed at install; the PAT is the secret, entered in the browser as an HTTP Basic credential. The response is a reference list of {id, url} with no fields on it, so this pipe pairs with azure-devops-read. Choose your scope. The azure-devops family is a ladder. File only: azure-devops-workitem on its own, which runs on the free Deckhand tier and fits a developer logging bugs without leaving the code. Read: azure-devops-query plus azure-devops-read, which needs two pipe slots and a plan that stores full response bodies (Bosun), runs on a PAT scoped Work Items (Read) when nothing else in the family is installed, and fits a developer checking their own assignments or a manager checking team progress. Manage: those two plus azure-devops-manage, which needs three pipe slots (First Mate) and a PAT scoped Work Items (Read & write), for a PM or QA grooming the whole backlog.

The credential never enters the model context: it lives in the FlurryPORT secret store, deliveries are signed server-side, and every send returns a receipt your agent can quote.

Install with your agent

npx flurryport mcp

Point your agent at the FlurryPORT MCP server (npx flurryport mcp) and ask it for the flurryport:azure-devops-query recipe. Works from AI clients that can run a local process: desktop apps and terminal agents. Web-only chat clients cannot reach a local MCP server; open a desktop client instead.

Tools your agent gains

flry_azure_devops_query
Run a WIQL query against the configured Azure DevOps org and project. Input: wiql (required). Returns nothing inline; the matching work item ids arrive on the replay execution, read them with get_replay_execution and pass them to flry_azure_devops_read for fields.

Setup walkthrough

  1. AZURE_DEVOPS_PAT: In Azure DevOps: User settings, Personal access tokens, New Token. This recipe on its own needs only scope Work Items (Read); the same token needs Work Items (Read & write) if it also serves azure-devops-workitem or azure-devops-manage. The value to paste in the FlurryPORT secret page is the HTTP Basic credential, NOT the raw token: run `printf ':YOUR_PAT' | base64` and paste the result. The recipe sends it as `Authorization: Basic <value>`. A raw PAT answers 401, or 203 with a sign-in page.

Intent schema

{
  "type": "object",
  "required": [
    "wiql"
  ],
  "properties": {
    "wiql": {
      "type": "string",
      "description": "A WIQL query string. Scope by person in the query, not at install: SELECT [System.Id] FROM WorkItems WHERE [System.AssignedTo] = @Me AND [System.State] <> 'Done' returns the open items assigned to whoever owns the PAT."
    }
  }
}

Install-time parameters

org
install-time: Azure DevOps organization.
project
install-time: Project within the organization.

Transformation

{ "body": { "query": $body.wiql } }

Delivery target

POST https://dev.azure.com/$install.org/$install.project/_apis/wit/wiql?api-version=7.1

Placeholders like $secrets.NAME resolve server-side at delivery, never in the agent.

Gotchas

Where this fits

Related recipes

flurryport:azure-devops-managedelivery

Create and update Azure DevOps work items in one batched pipe: priority, state, tags, and sprint included.

flurryport:azure-devops-readdelivery

Read fields for a batch of Azure DevOps work items by id: title, state, tags, priority, iteration.

flurryport:azure-devops-workitemdelivery

Let your AI file Azure DevOps work items (bugs, tasks) the model never holds credentials for.

flurryport:github-create-issuedelivery

Let your AI file GitHub issues with a fine-grained PAT it never touches.

flurryport:jira-create-issuedelivery

Let your AI file Jira Cloud issues with an API token it never touches.

flurryport:linear-create-issuedelivery

Let your AI file Linear issues with an API key it never touches.