SidecarAuthProvider class

Authentication provider that delegates token acquisition to the Microsoft Entra Agent ID sidecar (agent container). This replaces MSAL at the connection layer, using the sidecar's /AuthorizationHeaderUnauthenticated/{serviceName} endpoint for app-only and agentic identity flows. The sidecar performs the full Blueprint→Instance→User chain internally; no MSAL exchange is performed in-process.

Properties

connectionSettings

The AuthConfiguration used for token acquisition.

Methods

acquireTokenOnBehalfOf(AuthConfiguration, string[], string)
acquireTokenOnBehalfOf(string[], string)

On-behalf-of token exchange — not supported by the sidecar provider in Phase 1.

getAccessToken(AuthConfiguration, string)

Acquires an app-only access token from the sidecar.

getAccessToken(string)

Acquires an app-only access token from the sidecar.

getAgenticApplicationToken(string, string)

Acquires the Blueprint (agent application) token from the sidecar.

getAgenticInstanceToken(string, string)

Acquires the autonomous agent (instance) token from the sidecar for the configured resource.

getAgenticUserToken(string, string, string, string[])

Acquires the agentic user token from the sidecar for the configured resource.

isHealthy()

Checks sidecar availability via the /healthz endpoint.

Constructor Details

SidecarAuthProvider(AuthConfiguration)

Creates a new SidecarAuthProvider.

new SidecarAuthProvider(connectionSettings?: AuthConfiguration)

Parameters

connectionSettings
AuthConfiguration

The connection authentication configuration.

Property Details

connectionSettings

The AuthConfiguration used for token acquisition.

connectionSettings?: AuthConfiguration

Property Value

Method Details

acquireTokenOnBehalfOf(AuthConfiguration, string[], string)

function acquireTokenOnBehalfOf(authConfig: AuthConfiguration, scopes: string[], oboAssertion: string): Promise<string>

Parameters

authConfig
AuthConfiguration
scopes

string[]

oboAssertion

string

Returns

Promise<string>

acquireTokenOnBehalfOf(string[], string)

On-behalf-of token exchange — not supported by the sidecar provider in Phase 1.

function acquireTokenOnBehalfOf(scopes: string[], oboAssertion: string): Promise<string>

Parameters

scopes

string[]

oboAssertion

string

Returns

Promise<string>

getAccessToken(AuthConfiguration, string)

Acquires an app-only access token from the sidecar.

function getAccessToken(authConfig: AuthConfiguration, scope: string): Promise<string>

Parameters

authConfig
AuthConfiguration

The authentication configuration. Ignored by the sidecar provider, which owns the credential and derives the token from its configured service name; accepted only to satisfy the AuthProvider overload.

scope

string

The scope for the token.

Returns

Promise<string>

getAccessToken(string)

Acquires an app-only access token from the sidecar.

function getAccessToken(scope: string): Promise<string>

Parameters

scope

string

The scope for the token.

Returns

Promise<string>

getAgenticApplicationToken(string, string)

Acquires the Blueprint (agent application) token from the sidecar.

function getAgenticApplicationToken(tenantId: string, agentAppInstanceId: string): Promise<string>

Parameters

tenantId

string

The tenant ID.

agentAppInstanceId

string

The agent instance ID (from the inbound activity); maps to AgentIdentity.

Returns

Promise<string>

getAgenticInstanceToken(string, string)

Acquires the autonomous agent (instance) token from the sidecar for the configured resource.

function getAgenticInstanceToken(tenantId: string, agentAppInstanceId: string): Promise<string>

Parameters

tenantId

string

The tenant ID.

agentAppInstanceId

string

The agent instance ID (from the inbound activity); maps to AgentIdentity.

Returns

Promise<string>

getAgenticUserToken(string, string, string, string[])

Acquires the agentic user token from the sidecar for the configured resource.

function getAgenticUserToken(tenantId: string, agentAppInstanceId: string, upn: string, scopes: string[]): Promise<string>

Parameters

tenantId

string

The tenant ID.

agentAppInstanceId

string

The agent instance ID (from the inbound activity); maps to AgentIdentity.

upn

string

The agentic user identifier. A GUID is sent as AgentUserId; otherwise as AgentUsername.

scopes

string[]

The OAuth scopes to request.

Returns

Promise<string>

isHealthy()

Checks sidecar availability via the /healthz endpoint.

function isHealthy(): Promise<boolean>

Returns

Promise<boolean>

true when the sidecar is reachable and healthy.