Documentation
Connecting to Azure DevOps
The dashboard connects to Azure DevOps Services using the official REST APIs, authenticated with your organization URL and a personal access token.
Organization URL
The URL must point at an Azure DevOps Services organization and start with https://dev.azure.com/, for example https://dev.azure.com/contoso. The organization name is the segment after the host.
On-premises Azure DevOps Server instances are not supported: the dashboard only connects to dev.azure.com organizations.
Personal access token (PAT)
The dashboard needs a PAT with these read scopes:
- Work Items (Read) - work item lists, details, comments, history, relations and attachments.
- Project and Team (Read) - project lists, avatars and activity metadata.
- Code (Read) - Git repositories, branches, source trees, file contents and TFVC changesets.
Grant read access only. The dashboard never writes, so it never needs write scopes. Set an expiration that matches how often you want to rotate it.
What the dashboard reads
- Projects and their avatars
- Work item queries, details, comments, revision history, relations and attachments
- Git repositories, branches, source trees, file contents and commit history
- TFVC item trees, file contents at versions, changesets and linked work items
- Work item updates and comments for the activity feed
What the dashboard never touches
- It does not create, edit, reassign, resolve or delete work items.
- It does not push, branch, merge or modify code.
- It does not check in TFVC changes or alter changesets.
- It does not change project, team, board or pipeline settings.
How your credentials are handled
Your organization URL and token are stored in this browser's local or session storage and are used only for requests to Microsoft's Azure DevOps endpoints. There is no DevOps Navigator server, database or analytics. A deployment may obfuscate the stored value with a public, operator-provided key - useful against casual inspection of browser storage, but not a substitute for keeping your machine safe and using read-only scopes.
To remove your credentials at any time, sign out from the dashboard or clear the site's data in your browser settings.