azure_ad
Injects an Azure AD (Entra ID) bearer token into outbound requests.
On this page
Injects an Azure AD (Entra ID) bearer token into outbound requests.
Configuration Notes
Experimental: requires the azure-ad-filter cargo feature, which is off by default and activates the experimental marker. This filter is a work in progress and its configuration surface may change between releases.
See the module docs for scope (client-secret only), the routing-vs-authentication separation, and the fail-closed behavior.
Example
filter: azure_ad
tenant_id: 00000000-0000-0000-0000-000000000000
client_id: 11111111-1111-1111-1111-111111111111
scope: https://cognitiveservices.azure.com/.default
client_secret_env_var: AZURE_CLIENT_SECRET
authority_host: login.microsoftonline.com # optional, for sovereign clouds
allow_private_authority: false # opt in only for a trusted private authority