Power Automate API - Connection

The Dashboard fields, how tokens are obtained and refreshed, invoke for endpoints without a method of their own, and ping.

A Power Automate connection is created once in the Dashboard and used in services as self.microsoft.power_platform[name]. This page covers the connection form, how the connection uses the credentials, and the methods that are not tied to flows or runs - invoke with its four HTTP shorthands, and ping.

Dashboard fields

Under Cloud → Microsoft → Power Automate:

FieldValue
NameAny, used as self.microsoft.power_platform[name] - the examples on these pages use Zato Power Automate
AddressThe Power Automate API, https://api.flow.microsoft.com for the public cloud, or the address your admin gives you for a national cloud
Tenant IDThe directory (tenant) ID of the app registration, from its overview page in the Azure portal
Client IDThe application (client) ID, from the same page
Client secretA secret created under the app registration's Certificates and secrets
Environment IDThe Power Platform environment the flows are in, from Environments in the Power Platform admin center, e.g. Default-98765432-5432-5432-5432-dcba98765432

Every flow and run method works within the environment named here. A second environment needs a second connection.

What the app registration needs

An admin does two things once:

  1. Adds the Flows.Read.All and Flows.Manage.All permissions of the Power Automate API, listed as Flow Service under API permissions, and consents to them for the tenant
  2. Registers the app registration with Power Platform and gives it access to the environment the flows are in, which is done from an administrator's own sign-in, as an app registration cannot register itself

Tokens

The connection signs in with the client credentials grant - it posts the client ID and secret to https://login.microsoftonline.com/<tenant ID>/oauth2/v2.0/token and gets a token back, with the scope https://service.flow.microsoft.com/.default.

The token is obtained the first time it is needed, kept, and replaced a minute before it would expire. When Power Automate rejects a token anyway - for instance, the secret was rotated - the connection gets a new one and repeats the request once. Services never see a token.

trigger_url is the one method that sends no token, the callback URL it posts to carries its own signature instead.

invoke

conn.invoke(method, path, params=None, data=None)

Calls any endpoint of the Power Automate API with the connection's token, for the parts of the API that have no method of their own.

ParameterTypeMeaning
methodstrGET, POST, PATCH or DELETE
pathstrThe path after the address, e.g. /providers/Microsoft.ProcessSimple/environments
paramsdictQuery string parameters, or none - api-version is 2016-11-01 unless given here
datadictThe JSON body, or none

Returns the parsed JSON response, or nothing when the endpoint returned no body. A status code outside the success range for the method raises an exception with the code and the response text.

The flow and run methods all use one environment, the one in the connection form. invoke is how a service reaches beyond it, e.g. to list the environments the app registration can see:

# -*- coding: utf-8 -*-

# Zato
from zato.server.service import Service

class ListEnvironments(Service):

    def handle(self):

        conn = self.microsoft.power_platform['Zato Power Automate']

        response = conn.invoke('GET', '/providers/Microsoft.ProcessSimple/environments')

        names = []
        for environment in response['value']:
            names.append(environment['properties']['displayName'])

        self.response.payload = {'environments': names}
{"environments": ["Contoso (default)", "Contoso Finance"]}

conn.get(path, params), conn.post(path, data, params), conn.patch(path, data, params) and conn.delete(path, params) are the same call with the method filled in.

ping

conn.ping()

Confirms the connection works by obtaining a token and listing the flows in the environment. The Ping button in the Dashboard calls it, and a service can too. Returns nothing, raises an exception when the token or the listing fails, and logs how many flows it found.

# -*- coding: utf-8 -*-

# Zato
from zato.server.service import Service

class Ping(Service):

    def handle(self):

        conn = self.microsoft.power_platform['Zato Power Automate']
        conn.ping()

        self.response.payload = {'connection': conn.name}

See also

PageWhat it covers
Your first Power Automate integrationCreating the app registration and the connection step by step
Power Automate API - FlowsThe flow methods, including trigger and trigger_url
Power Automate API - RunsThe run methods and the run statuses

Learn more