SidecarAuthProvider class
Authentication provider that delegates token acquisition to the Microsoft Entra Agent ID
sidecar (agent container). This replaces MSAL at the connection layer, using the sidecar's
/AuthorizationHeaderUnauthenticated/{serviceName} endpoint for app-only and agentic identity
flows. The sidecar performs the full Blueprint→Instance→User chain internally; no MSAL exchange is
performed in-process.
Constructors
| Sidecar |
Creates a new SidecarAuthProvider. |
Properties
| connection |
The AuthConfiguration used for token acquisition. |
Methods
| acquire |
|
| acquire |
On-behalf-of token exchange — not supported by the sidecar provider in Phase 1. |
| get |
Acquires an app-only access token from the sidecar. |
| get |
Acquires an app-only access token from the sidecar. |
| get |
Acquires the Blueprint (agent application) token from the sidecar. |
| get |
Acquires the autonomous agent (instance) token from the sidecar for the configured resource. |
| get |
Acquires the agentic user token from the sidecar for the configured resource. |
| is |
Checks sidecar availability via the |
Constructor Details
SidecarAuthProvider(AuthConfiguration)
Creates a new SidecarAuthProvider.
new SidecarAuthProvider(connectionSettings?: AuthConfiguration)
Parameters
- connectionSettings
- AuthConfiguration
The connection authentication configuration.
Property Details
connectionSettings
The AuthConfiguration used for token acquisition.
connectionSettings?: AuthConfiguration
Property Value
Method Details
acquireTokenOnBehalfOf(AuthConfiguration, string[], string)
function acquireTokenOnBehalfOf(authConfig: AuthConfiguration, scopes: string[], oboAssertion: string): Promise<string>
Parameters
- authConfig
- AuthConfiguration
- scopes
-
string[]
- oboAssertion
-
string
Returns
Promise<string>
acquireTokenOnBehalfOf(string[], string)
On-behalf-of token exchange — not supported by the sidecar provider in Phase 1.
function acquireTokenOnBehalfOf(scopes: string[], oboAssertion: string): Promise<string>
Parameters
- scopes
-
string[]
- oboAssertion
-
string
Returns
Promise<string>
getAccessToken(AuthConfiguration, string)
Acquires an app-only access token from the sidecar.
function getAccessToken(authConfig: AuthConfiguration, scope: string): Promise<string>
Parameters
- authConfig
- AuthConfiguration
The authentication configuration. Ignored by the sidecar provider, which owns the credential and derives the token from its configured service name; accepted only to satisfy the AuthProvider overload.
- scope
-
string
The scope for the token.
Returns
Promise<string>
getAccessToken(string)
Acquires an app-only access token from the sidecar.
function getAccessToken(scope: string): Promise<string>
Parameters
- scope
-
string
The scope for the token.
Returns
Promise<string>
getAgenticApplicationToken(string, string)
Acquires the Blueprint (agent application) token from the sidecar.
function getAgenticApplicationToken(tenantId: string, agentAppInstanceId: string): Promise<string>
Parameters
- tenantId
-
string
The tenant ID.
- agentAppInstanceId
-
string
The agent instance ID (from the inbound activity); maps to AgentIdentity.
Returns
Promise<string>
getAgenticInstanceToken(string, string)
Acquires the autonomous agent (instance) token from the sidecar for the configured resource.
function getAgenticInstanceToken(tenantId: string, agentAppInstanceId: string): Promise<string>
Parameters
- tenantId
-
string
The tenant ID.
- agentAppInstanceId
-
string
The agent instance ID (from the inbound activity); maps to AgentIdentity.
Returns
Promise<string>
getAgenticUserToken(string, string, string, string[])
Acquires the agentic user token from the sidecar for the configured resource.
function getAgenticUserToken(tenantId: string, agentAppInstanceId: string, upn: string, scopes: string[]): Promise<string>
Parameters
- tenantId
-
string
The tenant ID.
- agentAppInstanceId
-
string
The agent instance ID (from the inbound activity); maps to AgentIdentity.
- upn
-
string
The agentic user identifier. A GUID is sent as AgentUserId; otherwise as AgentUsername.
- scopes
-
string[]
The OAuth scopes to request.
Returns
Promise<string>
isHealthy()
Checks sidecar availability via the /healthz endpoint.
function isHealthy(): Promise<boolean>
Returns
Promise<boolean>
true when the sidecar is reachable and healthy.