{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/pipedream.json",
        "name": "Pipedream API + MCP",
        "score": 65.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "pipedream"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/make.json",
        "name": "Make API + MCP",
        "score": 58.7,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "make"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/workato.json",
        "name": "Workato API + MCP",
        "score": 58,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "workato"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/activepieces.json",
        "name": "Activepieces API + MCP",
        "score": 57.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "activepieces"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/tray.json",
        "name": "Tray.ai API + MCP",
        "score": 55.5,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "tray"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/n8n.json",
        "name": "n8n API + MCP",
        "score": 53.1,
        "shared": [
          "automation.workflows",
          "automation.apps",
          "automation.webhooks"
        ],
        "slug": "n8n"
      }
    ],
    "tool": {
      "slug": "power-automate",
      "name": "Microsoft Power Automate",
      "vendor": "Microsoft",
      "vendorUrl": "https://www.microsoft.com/power-platform/products/power-automate",
      "kind": "http-api",
      "category": "workflow-automation",
      "summary": "Microsoft's workflow builder for cloud flows across Microsoft 365, Dataverse and third-party connectors. Outside agents list, create, update and delete solution-aware flows through the Dataverse Web API, and start a flow through its HTTP request trigger.",
      "url": "https://www.anchorterminal.com/tools/power-automate",
      "markdownUrl": "https://www.anchorterminal.com/tools/power-automate.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/power-automate.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/power-automate.json",
      "license": "Proprietary service under the Microsoft Product Terms for Microsoft Power Platform",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "nuget",
          "name": "Microsoft.PowerPlatform.Dataverse.Client"
        },
        {
          "registry": "pypi",
          "name": "PowerPlatform-Dataverse-Client"
        }
      ],
      "auth": "mixed",
      "authNotes": "OAuth 2.0 through Microsoft Entra ID for flow management. A person registers an app in the tenant and an administrator creates an application user with a Dataverse security role, or a user signs in with delegated access. The read-only Power Platform API takes a token for `https://api.powerplatform.com` with `.default`. A flow's HTTP request trigger has three modes. Any user in my tenant (the default for new flows) and Specific users in my tenant take an Entra bearer token with audience `https://service.flow.microsoft.com/`, and the second can name service principal object IDs. The legacy Anyone mode needs only the trigger URL, which carries a shared access signature as `sig=`. No API-key path for management.",
      "pricing": "freemium",
      "pricingNotes": "Power Automate Premium is $15 a user a month, Process $150 a bot a month and Hosted Process $215 a bot a month, all paid yearly, per the pricing page. API calls carry no separate charge and count against daily Power Platform request allowances (40,000 per Premium user, 250,000 per Process licence, a 25,000 tenant pool for unlicensed service principals). A flow owned by a service principal that uses premium connectors needs a Process licence or a designated licensed co-owner. To start without a contract there is a Free licence limited to standard connectors, a self-serve 90-day trial, and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. Card requirements were not stated (checked 2026-10-08).",
      "priceSummary": "$15 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Power Automate code docs, the Power Platform API reference or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": 10702,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code",
      "capabilities": [
        "automation.workflows",
        "automation.apps",
        "automation.webhooks"
      ],
      "tags": [
        "hosted",
        "official",
        "oauth",
        "enterprise",
        "odata",
        "dotnet",
        "python",
        "closed-source",
        "sla",
        "audit-log",
        "freemium",
        "webhooks"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62,
        "grade": "B",
        "agentReady": false,
        "rank": 350,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 63,
            "points": 12.6,
            "reason": "Graded on the Dataverse Web API for solution-aware cloud flows, with the HTTP request trigger noted. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in. The unauthenticated page at status.cloud.microsoft exists but rendered only a title for our reader (10 of 20, because the page with history needs a login). No readable incident history (5). Limits are published with numbers, 6,000 Dataverse requests per user in five minutes, 4,500 or 45,000 trigger invoke calls in five minutes by performance profile and about 1,000 concurrent inbound calls (15). Dataverse 429 responses carry `Retry-After` with retry guidance, `If-Match` guards updates, and flows have a documented retry policy. No idempotency key was found for trigger calls (13 of 15). The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate (10). Web API v9.2 is generally available. OAuth on HTTP triggers is described as still rolling out (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 68,
            "points": 11.05,
            "reason": "Each environment serves a CSDL `$metadata` document and Learn has a reference page for the `workflow` entity type. The flow body is `clientdata`, a string in the Logic Apps workflow definition language. No public OpenAPI document was found for flow management (15 of 25). learn.microsoft.com/llms.txt returns 404, but Learn returns Markdown for requests with `Accept: text/markdown`, which is how we read every page (10). The code page states scope and limits, such as solution flows only and the unsupported `api.flow.microsoft.com`, and describes 14 columns (13 of 20). Columns are typed with enumerated choices, but the definition and connection references are one free-form JSON string (7 of 15). Request and response examples for .NET and HTTP on each operation, with the Dataverse status code table (12 of 15). The version is in the URL (v9.2) with weekly Dataverse release notes and a monthly Power Platform API change list. Power Automate's own released versions page stops at 2508.2 of August 2025 (11 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 69,
            "points": 11.21,
            "reason": "`$select` and `$top` size responses, which matters because `clientdata` holds a whole flow. No MCP server for cloud flows was found (18 of 25). `$filter` on category and state, `@odata.nextLink` paging, and date and owner filters on the Power Platform API list call (18 of 20). Errors are JSON with a documented status code table, and each `flowruns` row has an error code and message (16 of 20). `If-Match` and `If-None-Match` guard writes. No documented call runs, cancels or resubmits a flow, and trigger calls have no idempotency key (9 of 20). Creating a flow needs five properties, one of them a hand-built definition with connection references, and flows start switched off. Dataverse SDKs for .NET and Python exist, with flow samples for .NET only (8 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 61,
            "points": 10.68,
            "reason": "OAuth 2.0 through Microsoft Entra ID with coarse scopes, limited by Dataverse security roles (26 of 30). The legacy Anyone mode of the HTTP trigger carries a shared access signature in the URL query string, a documented option, so 10 comes off (16). Security roles, record sharing through `GrantAccess`, data policies that restrict connectors, and trigger modes that name allowed users or service principals. No approval step before an API delete was found (14 of 20). Flow runs carry third-party data from connectors, and the pages we read give no injection guidance (3 of 15). Purview logs flow creation, edits, deletions and permission changes once auditing is on, and runs are `flowruns` rows, which Microsoft says are not lossless (13 of 15). The Azure SOC 2 Type 2 report lists Power Automate, and security.txt points to MSRC and the bounty policy, but its Expires date of 23 September 2026 has passed (15 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 25,
            "points": 3.13,
            "reason": "No x402, MPP or L402 (0). Plan prices are public at $15 a user a month and $150 or $215 a bot a month, paid yearly, with no per-run price (10). A Free licence with standard connectors, a self-serve 90-day trial and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. None of the pages says whether a card is needed (15 of 20). A person registers an app in Entra ID and an administrator creates the application user (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 76,
            "points": 6.65,
            "reason": "Dataverse service update 9.2.26094 went to early release on 2 October 2026, and the Python Dataverse client 1.1.0 was published on 7 October 2026 (30). Service updates are weekly, nine listed since 7 August 2026 (20). Public release notes, a dated deprecations page and a community forum. Power Automate's own released versions page has no entry after August 2025, and we did not test support (8 of 15). Current Dataverse SDKs for .NET (1.2.27) and Python, and a monthly Power Platform management SDK (2.0.3503.299, 5 August 2026). None is specific to flows and no MCP server for cloud flows was found (12 of 15). The Python client is marked Production/Stable. CI was not checked (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 76,
            "points": 6.65,
            "note": "editorial 62, provenance 89",
            "reason": "Closed service under the Microsoft Product Terms for Microsoft Power Platform (15). The privacy statement, last updated September 2026, says customer agreements control for enterprise products and points to the Data Protection Addendum, which we did not read. Retention is stated for run history (30 days), `flowruns` rows (28 days by default) and Purview audit data (90 days). The statement's line on training AI models is not reconciled with the enterprise terms in what we read (18 of 30). The deprecations page was updated on 6 October 2026 with dated notices, the Power Platform API promises 12 months between deprecation and retirement, and the docs say plainly that `api.flow.microsoft.com` is unsupported (17 of 20). A flow runs in its environment's region, with a published region list and data kept inside the geography. We did not read a subprocessor list (12 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "`$select` and `$top` size responses, which matters because `clientdata` holds a whole flow. No MCP server for cloud flows was found (18 of 25). `$filter` on category and state, `@odata.nextLink` paging, and date and owner filters on the Power Platform API list call (18 of 20). Errors are JSON with a documented status code table, and each `flowruns` row has an error code and message (16 of 20). `If-Match` and `If-None-Match` guard writes. No documented call runs, cancels or resubmits a flow, and trigger calls have no idempotency key (9 of 20). Creating a flow needs five properties, one of them a hand-built definition with connection references, and flows start switched off. Dataverse SDKs for .NET and Python exist, with flow samples for .NET only (8 of 15).",
            "maintenance": "Dataverse service update 9.2.26094 went to early release on 2 October 2026, and the Python Dataverse client 1.1.0 was published on 7 October 2026 (30). Service updates are weekly, nine listed since 7 August 2026 (20). Public release notes, a dated deprecations page and a community forum. Power Automate's own released versions page has no entry after August 2025, and we did not test support (8 of 15). Current Dataverse SDKs for .NET (1.2.27) and Python, and a monthly Power Platform management SDK (2.0.3503.299, 5 August 2026). None is specific to flows and no MCP server for cloud flows was found (12 of 15). The Python client is marked Production/Stable. CI was not checked (6 of 10).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public at $15 a user a month and $150 or $215 a bot a month, paid yearly, with no per-run price (10). A Free licence with standard connectors, a self-serve 90-day trial and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. None of the pages says whether a card is needed (15 of 20). A person registers an app in Entra ID and an administrator creates the application user (0).",
            "reliability": "Graded on the Dataverse Web API for solution-aware cloud flows, with the HTTP request trigger noted. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in. The unauthenticated page at status.cloud.microsoft exists but rendered only a title for our reader (10 of 20, because the page with history needs a login). No readable incident history (5). Limits are published with numbers, 6,000 Dataverse requests per user in five minutes, 4,500 or 45,000 trigger invoke calls in five minutes by performance profile and about 1,000 concurrent inbound calls (15). Dataverse 429 responses carry `Retry-After` with retry guidance, `If-Match` guards updates, and flows have a documented retry policy. No idempotency key was found for trigger calls (13 of 15). The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate (10). Web API v9.2 is generally available. OAuth on HTTP triggers is described as still rolling out (10).",
            "schema": "Each environment serves a CSDL `$metadata` document and Learn has a reference page for the `workflow` entity type. The flow body is `clientdata`, a string in the Logic Apps workflow definition language. No public OpenAPI document was found for flow management (15 of 25). learn.microsoft.com/llms.txt returns 404, but Learn returns Markdown for requests with `Accept: text/markdown`, which is how we read every page (10). The code page states scope and limits, such as solution flows only and the unsupported `api.flow.microsoft.com`, and describes 14 columns (13 of 20). Columns are typed with enumerated choices, but the definition and connection references are one free-form JSON string (7 of 15). Request and response examples for .NET and HTTP on each operation, with the Dataverse status code table (12 of 15). The version is in the URL (v9.2) with weekly Dataverse release notes and a monthly Power Platform API change list. Power Automate's own released versions page stops at 2508.2 of August 2025 (11 of 15).",
            "security": "OAuth 2.0 through Microsoft Entra ID with coarse scopes, limited by Dataverse security roles (26 of 30). The legacy Anyone mode of the HTTP trigger carries a shared access signature in the URL query string, a documented option, so 10 comes off (16). Security roles, record sharing through `GrantAccess`, data policies that restrict connectors, and trigger modes that name allowed users or service principals. No approval step before an API delete was found (14 of 20). Flow runs carry third-party data from connectors, and the pages we read give no injection guidance (3 of 15). Purview logs flow creation, edits, deletions and permission changes once auditing is on, and runs are `flowruns` rows, which Microsoft says are not lossless (13 of 15). The Azure SOC 2 Type 2 report lists Power Automate, and security.txt points to MSRC and the bounty policy, but its Expires date of 23 September 2026 has passed (15 of 20).",
            "transparency": "Closed service under the Microsoft Product Terms for Microsoft Power Platform (15). The privacy statement, last updated September 2026, says customer agreements control for enterprise products and points to the Data Protection Addendum, which we did not read. Retention is stated for run history (30 days), `flowruns` rows (28 days by default) and Purview audit data (90 days). The statement's line on training AI models is not reconciled with the enterprise terms in what we read (18 of 30). The deprecations page was updated on 6 October 2026 with dated notices, the Power Platform API promises 12 months between deprecation and retirement, and the docs say plainly that `api.flow.microsoft.com` is unsupported (17 of 20). A flow runs in its environment's region, with a published region list and data kept inside the geography. We did not read a subprocessor list (12 of 20)."
          },
          "sources": [
            {
              "what": "work with cloud flows using code",
              "url": "https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code",
              "seen": "2026-10-08"
            },
            {
              "what": "cloud flow limits",
              "url": "https://learn.microsoft.com/en-us/power-automate/limits-and-config",
              "seen": "2026-10-08"
            },
            {
              "what": "OAuth for HTTP request triggers",
              "url": "https://learn.microsoft.com/en-us/power-automate/oauth-authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "regenerate the trigger SAS key",
              "url": "https://learn.microsoft.com/en-us/power-automate/regenerate-sas-key",
              "seen": "2026-10-08"
            },
            {
              "what": "cloud flow run history in Dataverse",
              "url": "https://learn.microsoft.com/en-us/power-automate/dataverse/cloud-flow-run-metadata",
              "seen": "2026-10-08"
            },
            {
              "what": "service principal owned flows",
              "url": "https://learn.microsoft.com/en-us/power-automate/service-principal-support",
              "seen": "2026-10-08"
            },
            {
              "what": "user licence for a service principal flow",
              "url": "https://learn.microsoft.com/en-us/power-automate/assign-user-license-service-principal-flow",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Platform API, list cloud flows",
              "url": "https://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/cloud-flows/list-cloud-flows",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Platform API, list flow runs",
              "url": "https://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/flow-runs/list-flow-runs",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Platform API changes by month",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/programmability-whats-new-changed",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Platform API versioning and support",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/programmability-versioning-support",
              "seen": "2026-10-08"
            },
            {
              "what": "Dataverse service protection limits",
              "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/api-limits",
              "seen": "2026-10-08"
            },
            {
              "what": "request limits and allocations",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/api-request-limits-allocations",
              "seen": "2026-10-08"
            },
            {
              "what": "Dataverse status codes and errors",
              "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/compose-http-requests-handle-errors",
              "seen": "2026-10-08"
            },
            {
              "what": "workflow entity type reference",
              "url": "https://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/reference/workflow",
              "seen": "2026-10-08"
            },
            {
              "what": "licence types",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/types",
              "seen": "2026-10-08"
            },
            {
              "what": "licensing FAQ",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/faqs",
              "seen": "2026-10-08"
            },
            {
              "what": "Free and trial licences",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/deep-dive-on-specific-license",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Apps Developer Plan",
              "url": "https://learn.microsoft.com/en-us/power-platform/developer/plan",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Automate activity logs in Purview",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/activity-logging-auditing/activity-logs-power-automate",
              "seen": "2026-10-08"
            },
            {
              "what": "data policies",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/wp-data-loss-prevention",
              "seen": "2026-10-08"
            },
            {
              "what": "compliance and data privacy",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "service health guidance",
              "url": "https://learn.microsoft.com/en-us/power-platform/admin/check-online-service-health",
              "seen": "2026-10-08"
            },
            {
              "what": "Dataverse released versions",
              "url": "https://learn.microsoft.com/en-us/dynamics365/released-versions/Microsoft-Dataverse",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Automate released versions",
              "url": "https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate",
              "seen": "2026-10-08"
            },
            {
              "what": "Power Platform deprecations",
              "url": "https://learn.microsoft.com/en-us/power-platform/important-changes-coming",
              "seen": "2026-10-08"
            },
            {
              "what": "regions",
              "url": "https://learn.microsoft.com/en-us/power-automate/regions-overview",
              "seen": "2026-10-08"
            },
            {
              "what": "SOC 2 Type 2 scope",
              "url": "https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2",
              "seen": "2026-10-08"
            },
            {
              "what": "Process Mining MCP server (preview)",
              "url": "https://learn.microsoft.com/en-us/power-automate/process-mining-mcp-server-reference",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.microsoft.com/en-us/power-platform/products/power-automate/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "SLA for Microsoft Online Services, 1 October 2026",
              "url": "https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services",
              "seen": "2026-10-08"
            },
            {
              "what": "Product Terms for Microsoft Power Platform",
              "url": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy statement",
              "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.microsoft.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "public status page",
              "url": "https://status.cloud.microsoft",
              "seen": "2026-10-08"
            },
            {
              "what": "Python Dataverse client on PyPI",
              "url": "https://pypi.org/pypi/PowerPlatform-Dataverse-Client/json",
              "seen": "2026-10-08"
            },
            {
              "what": ".NET Dataverse client on NuGet",
              "url": "https://api.nuget.org/v3-flatcontainer/microsoft.powerplatform.dataverse.client/index.json",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: incident history, because status.cloud.microsoft rendered only a title and tenant service health needs an admin sign-in",
            "unchecked: whether the Free licence, the 90-day trial or the Power Apps Developer Plan needs a card",
            "unchecked: the text of the Products and Services Data Protection Addendum and the subprocessor list",
            "unchecked: CI and issue handling on the Dataverse client repositories. No GitHub page was read",
            "unchecked: whether the Python Dataverse client can write the `workflows` table. The Power Automate docs show .NET and raw HTTP only",
            "Whether setting `statecode` to 1 through the Web API is the supported way to turn a flow on. The code page lists the values and says a new flow must be enabled, without an example",
            "Whether a public OpenAPI file exists for the Power Platform API. The reference pages were read, not a spec file",
            "Whether the Dataverse MCP server can read or write `workflows` rows. Its docs were not read for this listing and no Power Automate page mentions it",
            "The lead was right on the interface and on solution-aware flows only. It did not mention the read-only Power Platform API calls for flows and runs, or the HTTP request trigger"
          ]
        },
        "negative": 0,
        "verdict": "Cloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.",
        "bestFor": "Organisations already on Microsoft 365 and Dataverse that want an agent to inventory, deploy or adjust flows inside existing roles and solutions.",
        "strengths": [
          "Solution-aware cloud flows are rows in the Dataverse `workflows` table, with documented list, create, update, delete, share, export and import calls",
          "Service protection limits are published (6,000 requests per user in five minutes) and 429 responses carry `Retry-After`",
          "The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate",
          "Each run of a solution flow is a `flowruns` row with status, error code and message, kept 28 days by default",
          "A service principal can own flows, and new HTTP request triggers default to callers signed in to the tenant"
        ],
        "weaknesses": [
          "Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported",
          "A flow's definition travels as `clientdata`, one string of encoded JSON with connection references the caller builds by hand",
          "No documented call runs, cancels or resubmits a flow. Starting one means an HTTP request trigger built into the flow",
          "The legacy Anyone trigger mode carries its signature in the URL query string as `sig=`",
          "Power Automate's own released versions page stops at version 2508.2 of August 2025, and service health needs an admin sign-in"
        ],
        "agentNotes": [
          "Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition",
          "Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use",
          "Put the flow in a solution first. Flows that sit only under My flows are outside the supported API",
          "On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance",
          "Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 76,
          "payments": 25,
          "reliability": 63,
          "schema": 68,
          "security": 61,
          "transparency": 62
        },
        "provenanceScore": 89
      },
      "connect": {
        "http": "curl \"https://$DATAVERSE_ORG.api.crm.dynamics.com/api/data/v9.2/workflows?\\$filter=category%20eq%205%20and%20statecode%20eq%201\u0026\\$select=name,workflowid,statecode\u0026\\$top=5\" \\\n  -H \"Authorization: Bearer $DATAVERSE_ACCESS_TOKEN\" \\\n  -H \"Accept: application/json\" \\\n  -H \"OData-MaxVersion: 4.0\" \\\n  -H \"OData-Version: 4.0\""
      },
      "letme": {
        "capability": "https://letme.dev/automation.workflows",
        "tool": "https://letme.dev/power-automate"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "notable": [
        "The supported code route covers only flows on the Solutions tab. The docs state that managing flows under My flows isn't supported with code (https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code)",
        "Microsoft's FAQ says the API at `api.flow.microsoft.com` isn't supported and that customers use it at their own risk (https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code)",
        "The documented way to regenerate a trigger's signing key goes through the browser's developer tools and a call to that unsupported API (https://learn.microsoft.com/en-us/power-automate/regenerate-sas-key)",
        "OAuth for HTTP request triggers is described as still rolling out and possibly unavailable in some regions (page dated 29 April 2026, https://learn.microsoft.com/en-us/power-automate/oauth-authentication)",
        "A consistently throttled flow is turned off after 14 days, and a flow with no trigger activity for 90 days might be turned off unless its owner holds a premium licence (https://learn.microsoft.com/en-us/power-automate/limits-and-config)",
        "The Power Automate mobile app was deprecated on 31 August 2026. Cloud flows were not affected (https://learn.microsoft.com/en-us/power-platform/important-changes-coming)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Management API",
          "value": "Dataverse Web API, OData v4, at https://\u003corg\u003e.api.crm.dynamics.com/api/data/v9.2/workflows. GET, POST, PATCH and DELETE on cloud flows in solutions (`category` 5). `GrantAccess`, `ModifyAccess` and `RevokeAccess` share a flow. `ExportSolution` and `ImportSolution` move flows as solution ZIP files (https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code)"
        },
        {
          "label": "Not covered",
          "value": "Flows under My flows that are not in a solution. The API at `api.flow.microsoft.com` is unsupported and Microsoft says breaking changes could occur. No documented run, cancel or resubmit call"
        },
        {
          "label": "Flow definition",
          "value": "`clientdata`, a string of encoded JSON holding `connectionReferences` and a definition in the Azure Logic Apps workflow definition language. Required on create with `category`, `name`, `type` and `primaryentity`"
        },
        {
          "label": "Read-only inventory API",
          "value": "Power Platform API version 2024-10-01 at https://api.powerplatform.com/powerautomate/environments/{environmentId}/, with `cloudFlows`, `flowRuns` and flow actions list calls added in June 2025 (https://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/cloud-flows/list-cloud-flows)"
        },
        {
          "label": "Starting a flow",
          "value": "The When an HTTP request is received trigger gives each flow its own URL on a logic.azure.com host. Entra bearer token for tenant or named users, or a legacy signed URL (https://learn.microsoft.com/en-us/power-automate/oauth-authentication)"
        },
        {
          "label": "Run history",
          "value": "`flowruns` rows in Dataverse for solution flows, with start and end time, status, error code and message. Kept 28 days by default, settable. Microsoft says the feed is not lossless and that `flowevents` rows signal skipped runs (https://learn.microsoft.com/en-us/power-automate/dataverse/cloud-flow-run-metadata)"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 through Microsoft Entra ID. Delegated sign-in or an application user with a security role. A service principal can own flows but can't be a co-owner"
        },
        {
          "label": "Rate limits",
          "value": "Dataverse service protection of 6,000 requests per user in a five-minute window, with `Retry-After` on 429. Flow runtime endpoints allow 4,500 invoke calls in five minutes on the Low profile and 45,000 on the others, and about 1,000 concurrent inbound calls (https://learn.microsoft.com/en-us/power-automate/limits-and-config)"
        },
        {
          "label": "Flow limits",
          "value": "A run lasts at most 30 days and its history is kept 30 days. Outbound synchronous requests time out at 120 seconds. Default retry policy of 2 retries on the Low profile and 12 on Medium and High"
        },
        {
          "label": "SLA",
          "value": "Service credit of 25 per cent below 99.9 per cent uptime, 50 below 99 and 100 below 95, per the SLA for Microsoft Online Services dated 1 October 2026. Downtime is counted when users' flows have no connectivity to Microsoft's internet gateway"
        },
        {
          "label": "SDKs",
          "value": "Dataverse clients, not specific to flows. .NET `Microsoft.PowerPlatform.Dataverse.Client` 1.2.27 and Python `PowerPlatform-Dataverse-Client` 1.1.0 (7 October 2026). The Power Automate docs give samples for .NET and raw HTTP only"
        },
        {
          "label": "MCP server",
          "value": "None for cloud flows found in the Power Automate docs. The Process Mining MCP server (nine tools) is a preview and covers process analytics, not flows (https://learn.microsoft.com/en-us/power-automate/process-mining-mcp-server-reference)"
        },
        {
          "label": "Audit",
          "value": "Microsoft Purview logs flow created, edited and deleted events and permission changes once auditing is turned on, readable through the Office 365 Management API. Runs are not in Purview (https://learn.microsoft.com/en-us/power-platform/admin/activity-logging-auditing/activity-logs-power-automate)"
        },
        {
          "label": "Free tier",
          "value": "Free licence with standard connectors only, a self-serve 90-day trial, 30-day admin trials, and the Power Apps Developer Plan (free Dataverse environment, 750 flow runs a month)"
        },
        {
          "label": "Regions",
          "value": "A flow runs in the region of its Power Platform environment. The region table includes Europe, France, Germany, Switzerland, Norway, India, Japan and Australia (https://learn.microsoft.com/en-us/power-automate/regions-overview)"
        }
      ],
      "unitPrices": [
        {
          "item": "Power Automate Premium",
          "unit": "seat-month",
          "usd": 15,
          "note": "paid yearly, 40,000 Power Platform requests a day"
        },
        {
          "item": "Power Automate Process",
          "unit": "month",
          "usd": 150,
          "note": "per bot, paid yearly, 250,000 actions a day for one flow or a flow group"
        },
        {
          "item": "Power Automate Hosted Process",
          "unit": "month",
          "usd": 215,
          "note": "per bot, paid yearly, with a Microsoft-hosted virtual machine"
        }
      ],
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "The management API answers on a dynamics.com host such as https://\u003corg\u003e.api.crm.dynamics.com, flow trigger URLs on logic.azure.com and the inventory API on api.powerplatform.com, all Microsoft domains. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": true,
        "terms": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA",
        "privacy": "https://www.microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "https://status.cloud.microsoft",
        "changelog": "https://learn.microsoft.com/en-us/dynamics365/released-versions/Microsoft-Dataverse",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The terms link is the Microsoft Product Terms page for Microsoft Power Platform under the Microsoft Customer Agreement, which names Power Automate Premium, Process and Hosted Process. It showed no effective date.",
          "The Microsoft privacy statement was last updated in September 2026 and says customer agreements control for enterprise and developer products. Customer data is governed by the Products and Services Data Protection Addendum, published as a .docx download, which we did not read.",
          "www.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08, with MSRC as the contact.",
          "status.cloud.microsoft rendered only a title for our reader. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in.",
          "The changelog link is the weekly Dataverse service update page, because flow management runs on Dataverse. Power Automate's own released versions page (https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate) lists nothing after version 2508.2 of August 2025.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02. dynamics.com, azure.com and powerplatform.com were not looked up."
        ],
        "score": 89,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Microsoft Corporation",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "microsoft.com, registered 1991-05-02 (35 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "microsoft.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 2 of the 7 things a reader expects",
            "points": 5.7,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.cloud.microsoft",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 2462,
            "points": 5.7,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": false
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": false
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer may not use this functionality to share content internally."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "Service Level Agreement"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Microsoft may disable a Dataverse instance supplied with Microsoft 365 licences and delete its data once the instance has been inactive for 90 days.",
                "quote": "If a Customer allows its Dataverse instance that is provided with Microsoft 365 licenses to go inactive, Microsoft may, at its discretion, disable the inactive instance and delete the Customer Data and Personal Data within it."
              },
              {
                "date": "2026-10-08",
                "text": "Grounding with Bing in Microsoft Copilot Studio falls outside the Data Protection Addendum and is governed by separate Bing terms and the Microsoft Privacy Statement.",
                "quote": "The Data Protection Addendum does not apply to the use of Grounding with Bing Search and Grounding with Bing Custom Search."
              },
              {
                "date": "2026-10-08",
                "text": "Microsoft may show content shared through the Power BI publish to web function on a public website or gallery.",
                "quote": "Microsoft may display content published through the publish to web functionality on a public website or gallery."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.microsoft.com/en-us/privacy/privacystatement",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-01",
            "words": 33580,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: September 2026",
                "says": "Last updated 2026-09-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "The data we collect depends on the context of your interactions with Microsoft and the choices you make, including your privacy settings and the products and features you use."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "When you delete an email or item from a mailbox in Outlook.com, the item generally goes into your Deleted Items folder where it remains for approximately 7 days unless you move it back to your inbox, you empty the folder, or the service empties the folder automatically, whichever comes first.",
                "says": "Names a period of 7 days"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Service providers that help us determine your device’s location."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "not use or share student personal data for advertising or similar commercial purposes, such as providing personalized advertising to students;"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "State Data Privacy Notice (including notice at collection details) and the Consumer Health Data Privacy Policy for additional information about your rights and the processing of your personal data."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have a privacy concern, complaint, or question for the Microsoft privacy team or Data Protection Officer, please visit our privacy support and requests page and click on “Contact the Microsoft privacy team or the Microsoft Data Protection Officer” menu.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "In such cases, we implement legal safeguards-such as standard contractual clauses approved by the European Commission – to help protect your rights and ensure your data remains protected.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.",
                "costsPoints": true
              },
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "We also disclose personal data for digital advertising purposes."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict.",
                "quote": "In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control."
              },
              {
                "date": "2026-10-08",
                "text": "Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising.",
                "quote": "Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising."
              },
              {
                "date": "2026-10-08",
                "text": "Microsoft staff manually review some results of its automated systems, including AI, against the source data.",
                "quote": "For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/power-automate.json"
    },
    "verify": {
      "accepts": "a page on microsoft.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/power-automate.svg",
      "body": {
        "slug": "power-automate",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/power-automate",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/power-automate\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/power-automate.svg\" alt=\"Microsoft Power Automate on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Microsoft Power Automate on Anchor Terminal](https://www.anchorterminal.com/badges/power-automate.svg)](https://www.anchorterminal.com/tools/power-automate)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/power-automate\"\u003eMicrosoft Power Automate on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/power-automate",
    "json": "https://www.anchorterminal.com/tools/power-automate.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/power-automate.md",
    "slim": "https://www.anchorterminal.com/tools/power-automate.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62/100 · rank #350 of 722 · #2 in Workflow automation · not agent-ready · confidence medium**\n\n\nMore from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails \u0026 safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks \u0026 SDKs), [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) (Code execution sandboxes), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth \u0026 delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets \u0026 credential vaults), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code \u0026 developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code \u0026 developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud \u0026 infrastructure), [Azure Maps](https://www.anchorterminal.com/tools/azure-maps.md) (Maps, geocoding \u0026 places), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars \u0026 scheduling), [Microsoft Teams (Microsoft Graph)](https://www.anchorterminal.com/tools/microsoft-teams.md) (Work \u0026 productivity), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM \u0026 customer platforms), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising \u0026 campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets \u0026 operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access).\n\n## Assessment\n\nCloud flows in a solution are rows an agent can read and write through the Dataverse Web API under Entra ID OAuth and security roles, with published limits and a 99.9 per cent SLA. Flows under My flows can't be managed in code, a flow's body is one hand-built JSON string, and setup needs a tenant administrator.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Microsoft (https://www.microsoft.com/power-platform/products/power-automate) |\n| Kind | HTTP API |\n| Category | Workflow automation (https://www.anchorterminal.com/categories/workflow-automation) |\n| Transport | HTTP |\n| Auth | OAuth or key · OAuth 2.0 through Microsoft Entra ID for flow management. A person registers an app in the tenant and an administrator creates an application user with a Dataverse security role, or a user signs in with delegated access. The read-only Power Platform API takes a token for `https://api.powerplatform.com` with `.default`. A flow's HTTP request trigger has three modes. Any user in my tenant (the default for new flows) and Specific users in my tenant take an Entra bearer token with audience `https://service.flow.microsoft.com/`, and the second can name service principal object IDs. The legacy Anyone mode needs only the trigger URL, which carries a shared access signature as `sig=`. No API-key path for management. |\n| Pricing | Freemium ($15 / seat-mo) · Power Automate Premium is $15 a user a month, Process $150 a bot a month and Hosted Process $215 a bot a month, all paid yearly, per the pricing page. API calls carry no separate charge and count against daily Power Platform request allowances (40,000 per Premium user, 250,000 per Process licence, a 25,000 tenant pool for unlicensed service principals). A flow owned by a service principal that uses premium connectors needs a Process licence or a designated licensed co-owner. To start without a contract there is a Free licence limited to standard connectors, a self-serve 90-day trial, and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. Card requirements were not stated (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the Power Automate code docs, the Power Platform API reference or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under the Microsoft Product Terms for Microsoft Power Platform |\n| Packages | nuget: `Microsoft.PowerPlatform.Dataverse.Client`; pypi: `PowerPlatform-Dataverse-Client` |\n| Docs | https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code |\n| llms.txt | not found |\n| Last release | 2026-10-02 |\n| PyPI downloads / week | 10,702 |\n| Management API | Dataverse Web API, OData v4, at https://\u003corg\u003e.api.crm.dynamics.com/api/data/v9.2/workflows. GET, POST, PATCH and DELETE on cloud flows in solutions (`category` 5). `GrantAccess`, `ModifyAccess` and `RevokeAccess` share a flow. `ExportSolution` and `ImportSolution` move flows as solution ZIP files (https://learn.microsoft.com/en-us/power-automate/manage-flows-with-code) |\n| Not covered | Flows under My flows that are not in a solution. The API at `api.flow.microsoft.com` is unsupported and Microsoft says breaking changes could occur. No documented run, cancel or resubmit call |\n| Flow definition | `clientdata`, a string of encoded JSON holding `connectionReferences` and a definition in the Azure Logic Apps workflow definition language. Required on create with `category`, `name`, `type` and `primaryentity` |\n| Read-only inventory API | Power Platform API version 2024-10-01 at https://api.powerplatform.com/powerautomate/environments/{environmentId}/, with `cloudFlows`, `flowRuns` and flow actions list calls added in June 2025 (https://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/cloud-flows/list-cloud-flows) |\n| Starting a flow | The When an HTTP request is received trigger gives each flow its own URL on a logic.azure.com host. Entra bearer token for tenant or named users, or a legacy signed URL (https://learn.microsoft.com/en-us/power-automate/oauth-authentication) |\n| Run history | `flowruns` rows in Dataverse for solution flows, with start and end time, status, error code and message. Kept 28 days by default, settable. Microsoft says the feed is not lossless and that `flowevents` rows signal skipped runs (https://learn.microsoft.com/en-us/power-automate/dataverse/cloud-flow-run-metadata) |\n| Credentials | OAuth 2.0 through Microsoft Entra ID. Delegated sign-in or an application user with a security role. A service principal can own flows but can't be a co-owner |\n| Rate limits | Dataverse service protection of 6,000 requests per user in a five-minute window, with `Retry-After` on 429. Flow runtime endpoints allow 4,500 invoke calls in five minutes on the Low profile and 45,000 on the others, and about 1,000 concurrent inbound calls (https://learn.microsoft.com/en-us/power-automate/limits-and-config) |\n| Flow limits | A run lasts at most 30 days and its history is kept 30 days. Outbound synchronous requests time out at 120 seconds. Default retry policy of 2 retries on the Low profile and 12 on Medium and High |\n| SLA | Service credit of 25 per cent below 99.9 per cent uptime, 50 below 99 and 100 below 95, per the SLA for Microsoft Online Services dated 1 October 2026. Downtime is counted when users' flows have no connectivity to Microsoft's internet gateway |\n| SDKs | Dataverse clients, not specific to flows. .NET `Microsoft.PowerPlatform.Dataverse.Client` 1.2.27 and Python `PowerPlatform-Dataverse-Client` 1.1.0 (7 October 2026). The Power Automate docs give samples for .NET and raw HTTP only |\n| MCP server | None for cloud flows found in the Power Automate docs. The Process Mining MCP server (nine tools) is a preview and covers process analytics, not flows (https://learn.microsoft.com/en-us/power-automate/process-mining-mcp-server-reference) |\n| Audit | Microsoft Purview logs flow created, edited and deleted events and permission changes once auditing is turned on, readable through the Office 365 Management API. Runs are not in Purview (https://learn.microsoft.com/en-us/power-platform/admin/activity-logging-auditing/activity-logs-power-automate) |\n| Free tier | Free licence with standard connectors only, a self-serve 90-day trial, 30-day admin trials, and the Power Apps Developer Plan (free Dataverse environment, 750 flow runs a month) |\n| Regions | A flow runs in the region of its Power Platform environment. The region table includes Europe, France, Germany, Switzerland, Norway, India, Japan and Australia (https://learn.microsoft.com/en-us/power-automate/regions-overview) |\n| Capabilities | automation.workflows, automation.apps, automation.webhooks |\n| Tags | hosted, official, oauth, enterprise, odata, dotnet, python, closed-source, sla, audit-log, freemium, webhooks |\n| JSON | https://www.anchorterminal.com/api/v1/tools/power-automate.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 63 | 12.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 68 | 11.1 |\n| Agent ergonomics | 13% | 16.2 | 69 | 11.2 |\n| Security \u0026 auth | 14% | 17.5 | 61 | 10.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 25 | 3.1 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 76 | 6.7 |\n| Transparency \u0026 trust (editorial 62, provenance 89) | 7% | 8.8 | 76 | 6.7 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **62 → B** |\n\n### Why each score\n\n- Reliability 63: Graded on the Dataverse Web API for solution-aware cloud flows, with the HTTP request trigger noted. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in. The unauthenticated page at status.cloud.microsoft exists but rendered only a title for our reader (10 of 20, because the page with history needs a login). No readable incident history (5). Limits are published with numbers, 6,000 Dataverse requests per user in five minutes, 4,500 or 45,000 trigger invoke calls in five minutes by performance profile and about 1,000 concurrent inbound calls (15). Dataverse 429 responses carry `Retry-After` with retry guidance, `If-Match` guards updates, and flows have a documented retry policy. No idempotency key was found for trigger calls (13 of 15). The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate (10). Web API v9.2 is generally available. OAuth on HTTP triggers is described as still rolling out (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 68: Each environment serves a CSDL `$metadata` document and Learn has a reference page for the `workflow` entity type. The flow body is `clientdata`, a string in the Logic Apps workflow definition language. No public OpenAPI document was found for flow management (15 of 25). learn.microsoft.com/llms.txt returns 404, but Learn returns Markdown for requests with `Accept: text/markdown`, which is how we read every page (10). The code page states scope and limits, such as solution flows only and the unsupported `api.flow.microsoft.com`, and describes 14 columns (13 of 20). Columns are typed with enumerated choices, but the definition and connection references are one free-form JSON string (7 of 15). Request and response examples for .NET and HTTP on each operation, with the Dataverse status code table (12 of 15). The version is in the URL (v9.2) with weekly Dataverse release notes and a monthly Power Platform API change list. Power Automate's own released versions page stops at 2508.2 of August 2025 (11 of 15).\n- Agent ergonomics 69: `$select` and `$top` size responses, which matters because `clientdata` holds a whole flow. No MCP server for cloud flows was found (18 of 25). `$filter` on category and state, `@odata.nextLink` paging, and date and owner filters on the Power Platform API list call (18 of 20). Errors are JSON with a documented status code table, and each `flowruns` row has an error code and message (16 of 20). `If-Match` and `If-None-Match` guard writes. No documented call runs, cancels or resubmits a flow, and trigger calls have no idempotency key (9 of 20). Creating a flow needs five properties, one of them a hand-built definition with connection references, and flows start switched off. Dataverse SDKs for .NET and Python exist, with flow samples for .NET only (8 of 15).\n- Security \u0026 auth 61: OAuth 2.0 through Microsoft Entra ID with coarse scopes, limited by Dataverse security roles (26 of 30). The legacy Anyone mode of the HTTP trigger carries a shared access signature in the URL query string, a documented option, so 10 comes off (16). Security roles, record sharing through `GrantAccess`, data policies that restrict connectors, and trigger modes that name allowed users or service principals. No approval step before an API delete was found (14 of 20). Flow runs carry third-party data from connectors, and the pages we read give no injection guidance (3 of 15). Purview logs flow creation, edits, deletions and permission changes once auditing is on, and runs are `flowruns` rows, which Microsoft says are not lossless (13 of 15). The Azure SOC 2 Type 2 report lists Power Automate, and security.txt points to MSRC and the bounty policy, but its Expires date of 23 September 2026 has passed (15 of 20).\n- Payments \u0026 pricing 25: No x402, MPP or L402 (0). Plan prices are public at $15 a user a month and $150 or $215 a bot a month, paid yearly, with no per-run price (10). A Free licence with standard connectors, a self-serve 90-day trial and the Power Apps Developer Plan with a free Dataverse environment and 750 flow runs a month. None of the pages says whether a card is needed (15 of 20). A person registers an app in Entra ID and an administrator creates the application user (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 76: Dataverse service update 9.2.26094 went to early release on 2 October 2026, and the Python Dataverse client 1.1.0 was published on 7 October 2026 (30). Service updates are weekly, nine listed since 7 August 2026 (20). Public release notes, a dated deprecations page and a community forum. Power Automate's own released versions page has no entry after August 2025, and we did not test support (8 of 15). Current Dataverse SDKs for .NET (1.2.27) and Python, and a monthly Power Platform management SDK (2.0.3503.299, 5 August 2026). None is specific to flows and no MCP server for cloud flows was found (12 of 15). The Python client is marked Production/Stable. CI was not checked (6 of 10).\n- Transparency \u0026 trust 76: Closed service under the Microsoft Product Terms for Microsoft Power Platform (15). The privacy statement, last updated September 2026, says customer agreements control for enterprise products and points to the Data Protection Addendum, which we did not read. Retention is stated for run history (30 days), `flowruns` rows (28 days by default) and Purview audit data (90 days). The statement's line on training AI models is not reconciled with the enterprise terms in what we read (18 of 30). The deprecations page was updated on 6 October 2026 with dated notices, the Power Platform API promises 12 months between deprecation and retirement, and the docs say plainly that `api.flow.microsoft.com` is unsupported (17 of 20). A flow runs in its environment's region, with a published region list and data kept inside the geography. We did not read a subprocessor list (12 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/power-automate.md (JSON https://www.anchorterminal.com/fixes/power-automate.json)\n\n### What we couldn't check\n\n- unchecked: incident history, because status.cloud.microsoft rendered only a title and tenant service health needs an admin sign-in\n- unchecked: whether the Free licence, the 90-day trial or the Power Apps Developer Plan needs a card\n- unchecked: the text of the Products and Services Data Protection Addendum and the subprocessor list\n- unchecked: CI and issue handling on the Dataverse client repositories. No GitHub page was read\n- unchecked: whether the Python Dataverse client can write the `workflows` table. The Power Automate docs show .NET and raw HTTP only\n- Whether setting `statecode` to 1 through the Web API is the supported way to turn a flow on. The code page lists the values and says a new flow must be enabled, without an example\n- Whether a public OpenAPI file exists for the Power Platform API. The reference pages were read, not a spec file\n- Whether the Dataverse MCP server can read or write `workflows` rows. Its docs were not read for this listing and no Power Automate page mentions it\n- The lead was right on the interface and on solution-aware flows only. It did not mention the read-only Power Platform API calls for flows and runs, or the HTTP request trigger\n\n### Sources\n\n- work with cloud flows using code: \u003chttps://learn.microsoft.com/en-us/power-automate/manage-flows-with-code\u003e (seen 2026-10-08)\n- cloud flow limits: \u003chttps://learn.microsoft.com/en-us/power-automate/limits-and-config\u003e (seen 2026-10-08)\n- OAuth for HTTP request triggers: \u003chttps://learn.microsoft.com/en-us/power-automate/oauth-authentication\u003e (seen 2026-10-08)\n- regenerate the trigger SAS key: \u003chttps://learn.microsoft.com/en-us/power-automate/regenerate-sas-key\u003e (seen 2026-10-08)\n- cloud flow run history in Dataverse: \u003chttps://learn.microsoft.com/en-us/power-automate/dataverse/cloud-flow-run-metadata\u003e (seen 2026-10-08)\n- service principal owned flows: \u003chttps://learn.microsoft.com/en-us/power-automate/service-principal-support\u003e (seen 2026-10-08)\n- user licence for a service principal flow: \u003chttps://learn.microsoft.com/en-us/power-automate/assign-user-license-service-principal-flow\u003e (seen 2026-10-08)\n- Power Platform API, list cloud flows: \u003chttps://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/cloud-flows/list-cloud-flows\u003e (seen 2026-10-08)\n- Power Platform API, list flow runs: \u003chttps://learn.microsoft.com/en-us/rest/api/power-platform/powerautomate/flow-runs/list-flow-runs\u003e (seen 2026-10-08)\n- Power Platform API changes by month: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/programmability-whats-new-changed\u003e (seen 2026-10-08)\n- Power Platform API versioning and support: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/programmability-versioning-support\u003e (seen 2026-10-08)\n- Dataverse service protection limits: \u003chttps://learn.microsoft.com/en-us/power-apps/developer/data-platform/api-limits\u003e (seen 2026-10-08)\n- request limits and allocations: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/api-request-limits-allocations\u003e (seen 2026-10-08)\n- Dataverse status codes and errors: \u003chttps://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/compose-http-requests-handle-errors\u003e (seen 2026-10-08)\n- workflow entity type reference: \u003chttps://learn.microsoft.com/en-us/power-apps/developer/data-platform/webapi/reference/workflow\u003e (seen 2026-10-08)\n- licence types: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/types\u003e (seen 2026-10-08)\n- licensing FAQ: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/faqs\u003e (seen 2026-10-08)\n- Free and trial licences: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/power-automate-licensing/deep-dive-on-specific-license\u003e (seen 2026-10-08)\n- Power Apps Developer Plan: \u003chttps://learn.microsoft.com/en-us/power-platform/developer/plan\u003e (seen 2026-10-08)\n- Power Automate activity logs in Purview: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/activity-logging-auditing/activity-logs-power-automate\u003e (seen 2026-10-08)\n- data policies: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/wp-data-loss-prevention\u003e (seen 2026-10-08)\n- compliance and data privacy: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/wp-compliance-data-privacy\u003e (seen 2026-10-08)\n- service health guidance: \u003chttps://learn.microsoft.com/en-us/power-platform/admin/check-online-service-health\u003e (seen 2026-10-08)\n- Dataverse released versions: \u003chttps://learn.microsoft.com/en-us/dynamics365/released-versions/Microsoft-Dataverse\u003e (seen 2026-10-08)\n- Power Automate released versions: \u003chttps://learn.microsoft.com/en-us/power-platform/released-versions/power-automate\u003e (seen 2026-10-08)\n- Power Platform deprecations: \u003chttps://learn.microsoft.com/en-us/power-platform/important-changes-coming\u003e (seen 2026-10-08)\n- regions: \u003chttps://learn.microsoft.com/en-us/power-automate/regions-overview\u003e (seen 2026-10-08)\n- SOC 2 Type 2 scope: \u003chttps://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2\u003e (seen 2026-10-08)\n- Process Mining MCP server (preview): \u003chttps://learn.microsoft.com/en-us/power-automate/process-mining-mcp-server-reference\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.microsoft.com/en-us/power-platform/products/power-automate/pricing\u003e (seen 2026-10-08)\n- SLA for Microsoft Online Services, 1 October 2026: \u003chttps://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services\u003e (seen 2026-10-08)\n- Product Terms for Microsoft Power Platform: \u003chttps://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA\u003e (seen 2026-10-08)\n- privacy statement: \u003chttps://www.microsoft.com/en-us/privacy/privacystatement\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.microsoft.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- public status page: \u003chttps://status.cloud.microsoft\u003e (seen 2026-10-08)\n- Python Dataverse client on PyPI: \u003chttps://pypi.org/pypi/PowerPlatform-Dataverse-Client/json\u003e (seen 2026-10-08)\n- .NET Dataverse client on NuGet: \u003chttps://api.nuget.org/v3-flatcontainer/microsoft.powerplatform.dataverse.client/index.json\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 89/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Microsoft Corporation | 20/20 |\n| Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 |\n| Endpoint on the vendor's domain | microsoft.com | 15/15 |\n| Terms of service | read, states 2 of the 7 things a reader expects | 5.7/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | status.cloud.microsoft | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe management API answers on a dynamics.com host such as https://\u003corg\u003e.api.crm.dynamics.com, flow trigger URLs on logic.azure.com and the inventory API on api.powerplatform.com, all Microsoft domains. microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.\n\nThe terms link is the Microsoft Product Terms page for Microsoft Power Platform under the Microsoft Customer Agreement, which names Power Automate Premium, Process and Hosted Process. It showed no effective date.\n\nThe Microsoft privacy statement was last updated in September 2026 and says customer agreements control for enterprise and developer products. Customer data is governed by the Products and Services Data Protection Addendum, published as a .docx download, which we did not read.\n\nwww.microsoft.com/.well-known/security.txt carries Expires 2026-09-23T16:00:00.000Z when read on 2026-10-08, with MSRC as the contact.\n\nstatus.cloud.microsoft rendered only a title for our reader. Tenant service health is in the Power Platform and Microsoft 365 admin centres behind an admin sign-in.\n\nThe changelog link is the weekly Dataverse service update page, because flow management runs on Dataverse. Power Automate's own released versions page (https://learn.microsoft.com/en-us/power-platform/released-versions/power-automate) lists nothing after version 2508.2 of August 2025.\n\nRDAP for microsoft.com gives a registration date of 1991-05-02. dynamics.com, azure.com and powerplatform.com were not looked up.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.microsoft.com/licensing/terms/productoffering/MicrosoftPowerPlatform/MCA), read 2026-10-08, gives no date, states 2 of the 7 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Not found in the text. Names the governing law or courts.\n- Not found in the text. States a limit on its liability.\n- Not found in the text. Says how the agreement or account can be ended.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). Microsoft may disable a Dataverse instance supplied with Microsoft 365 licences and delete its data once the instance has been inactive for 90 days. \"If a Customer allows its Dataverse instance that is provided with Microsoft 365 licenses to go inactive, Microsoft may, at its discretion, disable the inactive instance and delete the Customer Data and Personal Data within it.\"\n- Also in the text (2026-10-08). Grounding with Bing in Microsoft Copilot Studio falls outside the Data Protection Addendum and is governed by separate Bing terms and the Microsoft Privacy Statement. \"The Data Protection Addendum does not apply to the use of Grounding with Bing Search and Grounding with Bing Custom Search.\"\n- Also in the text (2026-10-08). Microsoft may show content shared through the Power BI publish to web function on a public website or gallery. \"Microsoft may display content published through the publish to web functionality on a public website or gallery.\"\n\n**Privacy policy** (https://www.microsoft.com/en-us/privacy/privacystatement), read 2026-10-08, dated 2026-09-01, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"As part of our efforts to improve and develop our products, we may use your data to develop and train our AI models.\"\n- To know. Says it sells personal data or shares it for advertising. \"We also disclose personal data for digital advertising purposes.\"\n- Gives the date it was last updated. Last updated 2026-09-01.\n- Says how long data is kept. Names a period of 7 days.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). For enterprise and developer products, the customer's agreement with Microsoft takes precedence over this privacy statement where the two conflict. \"In the event of a conflict between our privacy statement and the terms of any agreement(s) between a customer and Microsoft for Enterprise and Developer Products, the terms of those agreement(s) will control.\"\n- Also in the text (2026-10-08). Prompts and related data sent to the consumer Microsoft Copilot are used to improve services and for relevant advertising. \"Microsoft Copilot also uses prompts and related data to provide and improve services, including relevant advertising.\"\n- Also in the text (2026-10-08). Microsoft staff manually review some results of its automated systems, including AI, against the source data. \"For example, to build, train, and improve the accuracy of our automated systems – such as AI - we manually review some of the results against the underlying data.\"\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Power Automate Premium | $15 | per seat per month | paid yearly, 40,000 Power Platform requests a day |\n| Power Automate Process | $150 | per month (plan) | per bot, paid yearly, 250,000 actions a day for one flow or a flow group |\n| Power Automate Hosted Process | $215 | per month (plan) | per bot, paid yearly, with a Microsoft-hosted virtual machine |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Solution-aware cloud flows are rows in the Dataverse `workflows` table, with documented list, create, update, delete, share, export and import calls\n- Service protection limits are published (6,000 requests per user in five minutes) and 429 responses carry `Retry-After`\n- The SLA of 1 October 2026 pays a 25 per cent credit below 99.9 per cent uptime for Power Automate\n- Each run of a solution flow is a `flowruns` row with status, error code and message, kept 28 days by default\n- A service principal can own flows, and new HTTP request triggers default to callers signed in to the tenant\n\n## Weaknesses\n\n- Flows under My flows can't be managed in code, and Microsoft calls the `api.flow.microsoft.com` API unsupported\n- A flow's definition travels as `clientdata`, one string of encoded JSON with connection references the caller builds by hand\n- No documented call runs, cancels or resubmits a flow. Starting one means an HTTP request trigger built into the flow\n- The legacy Anyone trigger mode carries its signature in the URL query string as `sig=`\n- Power Automate's own released versions page stops at version 2508.2 of August 2025, and service health needs an admin sign-in\n\n## Before you call it (notes for agents)\n\n1. Filter `workflows` on `category eq 5` for cloud flows, and add `$select`, because `clientdata` holds the whole definition\n2. Flows created through the API start with `statecode` 0 (off). The docs say to turn the flow on before use\n3. Put the flow in a solution first. Flows that sit only under My flows are outside the supported API\n4. On 429 wait the `Retry-After` seconds. Reads of `flowruns` count against the daily Power Platform request allowance\n5. Treat an HTTP trigger URL with `sig=` as a secret, and prefer the tenant or named-user trigger modes with a bearer token for `https://service.flow.microsoft.com/`\n\n## Connect\n\nFirst request:\n\n```bash\ncurl \"https://$DATAVERSE_ORG.api.crm.dynamics.com/api/data/v9.2/workflows?\\$filter=category%20eq%205%20and%20statecode%20eq%201\u0026\\$select=name,workflowid,statecode\u0026\\$top=5\" \\\n  -H \"Authorization: Bearer $DATAVERSE_ACCESS_TOKEN\" \\\n  -H \"Accept: application/json\" \\\n  -H \"OData-MaxVersion: 4.0\" \\\n  -H \"OData-Version: 4.0\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/power-automate. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Pipedream API + MCP | B | 65.5 | 255 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/pipedream.md |\n| Make API + MCP | C | 58.7 | 446 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/make.md |\n| Workato API + MCP | C | 58 | 460 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/workato.md |\n| Activepieces API + MCP | C | 57.5 | 471 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/activepieces.md |\n| Tray.ai API + MCP | C | 55.5 | 508 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/tray.md |\n| n8n API + MCP | D | 53.1 | 551 | automation.workflows, automation.apps, automation.webhooks | no | https://www.anchorterminal.com/tools/n8n.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The supported code route covers only flows on the Solutions tab. The docs state that managing flows under My flows isn't supported with code (source: \u003chttps://learn.microsoft.com/en-us/power-automate/manage-flows-with-code\u003e)\n- Microsoft's FAQ says the API at `api.flow.microsoft.com` isn't supported and that customers use it at their own risk (source: \u003chttps://learn.microsoft.com/en-us/power-automate/manage-flows-with-code\u003e)\n- The documented way to regenerate a trigger's signing key goes through the browser's developer tools and a call to that unsupported API (source: \u003chttps://learn.microsoft.com/en-us/power-automate/regenerate-sas-key\u003e)\n- OAuth for HTTP request triggers is described as still rolling out and possibly unavailable in some regions (page dated 29 April 2026, https://learn.microsoft.com/en-us/power-automate/oauth-authentication)\n- A consistently throttled flow is turned off after 14 days, and a flow with no trigger activity for 90 days might be turned off unless its owner holds a premium licence (source: \u003chttps://learn.microsoft.com/en-us/power-automate/limits-and-config\u003e)\n- The Power Automate mobile app was deprecated on 31 August 2026. Cloud flows were not affected (source: \u003chttps://learn.microsoft.com/en-us/power-platform/important-changes-coming\u003e)\n\n## Compare\n\n- [Activepieces API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/activepieces-vs-power-automate.md): C 57.5 vs B 62\n- [Make API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/make-vs-power-automate.md): C 58.7 vs B 62\n- [n8n API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/n8n-vs-power-automate.md): D 53.1 vs B 62\n- [Paragon ActionKit + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/paragon-vs-power-automate.md): D 47.5 vs B 62\n- [Pipedream API + MCP vs Microsoft Power Automate](https://www.anchorterminal.com/compare/pipedream-vs-power-automate.md): B 65.5 vs B 62\n- [Microsoft Power Automate vs Tray.ai API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-tray.md): B 62 vs C 55.5\n- [Microsoft Power Automate vs Windmill API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-windmill.md): B 62 vs C 55.9\n- [Microsoft Power Automate vs Workato API + MCP](https://www.anchorterminal.com/compare/power-automate-vs-workato.md): B 62 vs C 58\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"power-automate\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/power-automate\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/power-automate.svg\" alt=\"Microsoft Power Automate on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Microsoft Power Automate on Anchor Terminal](https://www.anchorterminal.com/badges/power-automate.svg)](https://www.anchorterminal.com/tools/power-automate)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/power-automate\"\u003eMicrosoft Power Automate on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Microsoft Power Automate is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/power-automate-dark.png\n- Light: https://www.anchorterminal.com/assets/share/power-automate-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Workflow automation",
        "url": "https://www.anchorterminal.com/categories/workflow-automation"
      },
      {
        "name": "Microsoft Power Automate",
        "url": ""
      }
    ],
    "description": "Microsoft's workflow builder for cloud flows across Microsoft 365, Dataverse and third-party connectors. Outside agents list, create, update and delete solution-aware flows through the Dataverse Web API, and start a flow through its HTTP request trigger.",
    "facts": [
      "rank #350 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "Microsoft Power Automate",
    "image": "https://www.anchorterminal.com/assets/og/tools-power-automate.png",
    "path": "/tools/power-automate",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Power Automate review for AI agents, grade B (62/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/power-automate"
  },
  "tokens": {
    "markdown": 9600,
    "slim": 2280
  },
  "version": 1
}
