Power Apps code apps: React hosted and managed by the Power Platform
Code apps host a React or Vue application within the Power Platform, along with its identity and governance, without having to rebuild authentication and the application lifecycle separately. Environment-based activation, Power Apps Premium licensing, limitations to be aware of, and when the low-code is still sufficient.
Until now, the choice was binary. Either an application was built as a low-code and inherited the identity, connectors, and governance of the Power Platform, or it was developed as code, in which case all of these elements had to be rebuilt: hosting, authentication, secret management, application lifecycle, and data policies.
Code apps eliminate this choice: you write a web application in your usual editor, using React, Vue, or another framework, and then deploy it to the Power Platform, which hosts it and provides the identity and governance layer. Microsoft announced their general availability on its blog at Power Platform.
A single-page application written locally and hosted by the platform
A code app is a single-page web application that you write, build, and run locally, and that the Power Platform then hosts. Microsoft states that code apps support single-page applications, and that when running, a code app consists of three components: your code, the Power Apps client library—sometimes called the “Power Apps SDK”—which is included in the npm package @microsoft/power-apps — and the host Power Apps, which handles end-user authentication and application loading.
What it offers compared to self-hosting:
- Microsoft Entra authentication and authorization—no authentication codes to write or maintain.
- Access to Power Platform data sources and more than 1,500 connectors, which can be called directly from JavaScript.
- Compliance with the organization's managed platform strategies: application sharing restrictions, conditional access, and data loss prevention.
- Simplified deployment and application lifecycle management.
In terms of tools, Microsoft requires an IDE, Node.js, npm, Git, and the Power Apps CLI.
What a code app doesn't change: you remain responsible for the code, its dependencies, and its quality.
Activation by Environment and License Power Apps , Premium
Environment-based activation. This is not a creator setting: Microsoft states that Power Platform administrators and environment administrators can configure this option. In the administration center Power Platform, for the target environment, navigate to Settings, then, in the Product subsection, Features: the “Power Apps code apps” feature includes an “Enable code apps” toggle. In a deployment with multiple environments, an administrator can enable this in bulk along with the environment groups and their rules.
The feature is not enabled by default; an administrator must enable it on a per-environment basis.
The License. Every end user who runs an app needs a Power Apps s Premium license. This license must be purchased before building the application, as it determines whether end users can use it.
These two requirements are not the same: in a managed environment, any active use requires either one of the qualifying standalone licenses or a pay-per-use meter; a code app requires its own Power Apps Premium license per end user, regardless of whether the environment is managed or not.
The CLI is called pa, and the commands pac code will be replaced
Two tools coexist. pac, the CLI- Power Platform , is the long-standing, general-purpose tool; its group code It includes ten commands dedicated to code apps, and the documentation still lists this group as a preview. pa, the CLI Power Apps, is the new tool designed for code apps. It can be installed via npm — npm install --global @microsoft/power-apps-cli — and its commands follow the format pa <groupe> <commande>, across five groups: pa app, pa auth, pa connector, pa connection and pa telemetry.
Be careful not to get this mixed up: @microsoft/power-apps It's not the CLI; it's the client library. The CLI is the package @microsoft/power-apps-cli, and it is invoked pa.
Microsoft states that the new CLI interface “will replace these commands, which will be deprecated in a future release.” The verb is in the future tense: the commands pac code are not yet discouraged, and Microsoft has not announced a date.
| Task | With pac code | Using the CLI pa |
|---|---|---|
| Initialize an app code | pac code init | pa app init |
| Start the local host | pac code run | pa app run |
| Publish to an environment | pac code push | pa app push |
| Add a data source | pac code add-data-source | pa app add data-source |
| Add a feed Power Automate | No orders | pa app add flow |
| List the feeds in the environment | No orders | pa app list-flows |
| Log In | pac auth create | pa auth login |
The two unique lines are not different ways of writing the same thing: the group pac code does not contain any flow control commands. The CLI pa adds others that also have no counterpart, including pa app share, who shares the app with other users or service providers, and pa app add dataverse-api, which adds an action or a function Dataverse.
A team that set up a continuous integration pipeline on pac code So there’s a rework job to plan. Our take: this is the kind of rework that doesn’t cost much as long as it’s done proactively, but becomes very costly when the depreciation occurs in the middle of something else.
Things to Know Before You Commit
Microsoft documents five of them. Two relate to the architecture: the public endpoint with no IP address restrictions, and the lack of support for the platform's Git integration.
- The compiled resources are served from a publicly accessible endpoint that does not support IP address restrictions. Therefore, the IP binding and SAS firewall environment settings do not apply. To restrict access by IP address, Microsoft recommends using conditional access based on location, since code apps authenticate with Microsoft Entra ID. The system configuration page advises against storing sensitive data in the application; instead, it should be kept in a data source that is read after authentication and authorization checks.
- Power Platform 's Git integration is not supported. Note for teams working with code: The team's source code management system remains, of course, their own, but the platform's Git functionality does not cover code apps.
- Code apps are not supported in Power Apps for Windows.
- They do not yet support data integration Power BI — the function
PowerBIIntegration— but they can be incorporated into a report Power BI via the visual Power Apps. - They do not support the integration of SharePoint forms.
When to Use a Code App, and When a Web low-code Is Enough
The right case. An interface that requires fine-grained control over rendering or a third-party library that the low-code cannot replicate, but which must operate within the organization’s governance framework, in line with the Entra identity and existing data strategies. It’s also the right choice when the team building it is a development team, with its own source control system and integration pipeline.
The worst-case scenario. A form, a list, an approval process. A canvas-based or template-driven application does this faster, requires no developer to maintain, and doesn't require anyone to know React.
A scenario to watch out for: A team that chooses a particular code because they’re familiar with it, even though the web low-code would meet the need. Our take: This cost isn’t apparent during development, but it becomes evident the day the application’s author is no longer around to maintain it.
Once published, an app code adheres to the sharing restrictions for canvas apps and may be quarantined; data loss prevention policies apply when it is launched, and conditional access applies to the individual app. These are controls applied on a case-by-case basis, not a general veto over publication.
These trade-offs between low-code, pro-code, and governance are exactly the ones we consider at the start of a project; our page Power Apps describes the framework.
Microsoft Sources
- Overview of Code Applications Power Apps —Microsoft Learn
- Power Apps Code Apps Overview — Microsoft Learn, reference text
- Reference Information on the CLI Command ` Power Apps ` — Microsoft Learn
- Quick Start: Create a code app using the CLI Power Apps — Microsoft Learn
- Control group
codefrom the CLI Power Platform — Microsoft Learn - Control group
authfrom the CLI Power Platform — Microsoft Learn - Code Application Architecture — Microsoft Learn
- System Requirements for Code Applications — Microsoft Learn
- Licenses — Managed Environments — Microsoft Learn
- Generally Available: Host and Run Code Apps in Power Apps — Microsoft Blog Power Platform
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 149 articles, all of which are freely accessible.

