On-Behalf-Of (OBO) Flow for web APIs to call downstream APIs while preserving user identity in MSAL.NET

MITAuto-check passedBackend & APIs

Install Msal Obo Flow

skills CLI
$ npx skills add AzureAD/microsoft-authentication-library-for-dotnet --skill msal-obo-flow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install AzureAD/microsoft-authentication-library-for-dotnet msal-obo-flow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/AzureAD/microsoft-authentication-library-for-dotnet.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/msal-obo-flow .claude/skills/msal-obo-flow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
msal-obo-flow
GitHub stars
1.5k
Token cost
~1.2k tokens
SKILL.md length
380 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

On-Behalf-Of (OBO) Flow for web APIs to call downstream APIs while preserving user identity in MSAL.NET

  • Works in 4 steps: Client calls web API with user access… → Web API validates the incoming token → Web API exchanges user token for new… → …
  • Backend & APIs work in your project
  • SKILL.md covers Overview, When to Use, Flow Steps and Important: Token Types, plus 1 more section
  • Reaches login.microsoftonline.com

What it does

Msal Obo Flow is an agent skill from AzureAD/microsoft-authentication-library-for-dotnet. On-Behalf-Of (OBO) Flow for web APIs to call downstream APIs while preserving user identity in MSAL.NET

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Microsoft Entra ID and .NET. The repository describes itself as: Microsoft Authentication Library (MSAL) for .NET. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/msal-obo-flow”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Client calls web API with user access token in Authorization header
  2. Web API validates the incoming token
  3. Web API exchanges user token for new token scoped for downstream API
  4. Web API calls downstream API on behalf of user

What it can do on your machine

Read from SKILL.md and the folder at commit 2d15026. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • login.microsoftonline.com

    Also links to:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Msal Obo Flow loads about 1.2k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 380 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from AzureAD/microsoft-authentication-library-for-dotnet at commit 2d15026, republished under its MIT licence (© AzureAD). 380 words, ~1,169 tokens.

Download SKILL.mdSave it as .claude/skills/msal-obo-flow/SKILL.md (or your agent's skills folder).
name
msal-obo-flow
description
On-Behalf-Of (OBO) Flow for web APIs to call downstream APIs while preserving user identity in MSAL.NET
tags
msal, obo, on-behalf-of, token-exchange, confidential-client, multi-tier, downstream-api, user-assertion

On-Behalf-Of (OBO) Flow Skill

Overview

OBO (On-Behalf-Of) Flow enables a web API to act on behalf of an authenticated user to access downstream APIs. The web API receives a user token, validates it, and exchanges it for a token to call another API while maintaining the user's identity and context.

When to Use

  • Web APIs receiving user tokens from clients
  • Need to access downstream APIs on behalf of authenticated users
  • Multi-tier applications with user context propagation
  • User authorization context must flow through service chain

Flow Steps

  1. Client calls web API with user access token in Authorization header
  2. Web API validates the incoming token
  3. Web API exchanges user token for new token scoped for downstream API
  4. Web API calls downstream API on behalf of user

Important: Token Types

⚠️ Always pass an access token, NOT an ID token to AcquireTokenOnBehalfOf()
ID tokens are for authentication; access tokens are for authorization and API access.

Agent Actions

Generate Code Snippet

Agent can show code for each credential type:

Setup Guidance

Reference appropriate credential setup:

Example: Web API with Certificate
csharp
// In web API controller receiving user token
[HttpGet("api/data")]
public async Task<IActionResult> GetData()
{
    // Extract access token from Authorization header
    var authHeader = Request.Headers["Authorization"].ToString();
    var userToken = authHeader.Replace("Bearer ", "");
    
    // See: with-certificate.cs for credential setup
    var app = ConfidentialClientApplicationBuilder
        .Create(clientId)
        .WithCertificate(cert)
        .WithAuthority($"https://login.microsoftonline.com/{tenantId}/v2.0")
        .Build();

    // Create UserAssertion with access token (not ID token)
    var userAssertion = new UserAssertion(userToken, "urn:ietf:params:oauth:grant-type:jwt-bearer");
    
    var result = await app.AcquireTokenOnBehalfOf(
        new[] { "scope-uri" },
        userAssertion)
        .ExecuteAsync();

    // Use result.AccessToken to call downstream API
    return Ok(result.AccessToken);
}
Error Resolution

Refer to Troubleshooting Guide

Common OBO errors:

  • MsalUiRequiredException: MFA or conditional access required—requires client re-authentication
  • Invalid token: Verify access token (not ID token) is passed
Show full SKILL.md (155 more words)Show less
Best Practices
Explain the Flow
  1. Token Reception: Web API receives user's access token from client
  2. Token Validation: Web API validates token signature and claims
  3. Token Exchange: Web API calls AcquireTokenOnBehalfOf() with user's token + client credentials
  4. Scoped Token: AAD returns new token scoped for downstream API
  5. Downstream Call: Web API calls downstream service with new token
Decision Help

Choose OBO if:

  • Building multi-tier web API architecture
  • Receiving user tokens in web API
  • Need to maintain user context through service chain
  • Authenticating with downstream APIs on behalf of user

Avoid if:

  • Direct client-to-API communication (use Auth Code Flow)
  • Service-to-service with no user context (use Client Credentials)

© AzureAD, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/msal-obo-flow of AzureAD/microsoft-authentication-library-for-dotnet.

Open the folder on GitHubat commit 2d15026

Compare with similar skills

Msal Obo Flow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Msal Obo Flow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Msal Obo Flow this skillAzureAD/microsoft-authentication-library-for-dotnet1.5k—~1.2kAutomated safety check: PassMIT
Microsoft Azure Webjobs Extensions Authentication Events Dotnetmicrosoft/skills3.1k5 repos~3.8kAutomated safety check: PassMIT
Azure RelayMicrosoftDocs/Agent-Skills776—~1.1kAutomated safety check: PassCC-BY-4.0
Maui Aspiredavidortinau/maui-skills175—~1.3kAutomated safety check: PassMIT
Azure Identity Dotnetmicrosoft/skills3.1k5 repos~2.5kAutomated safety check: PassMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Relay

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Relay development including troubleshooting, security, configuration, and integrations & coding patterns.

    776 GitHub stars~1.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Maui Aspire

    davidortinau/maui-skills

    Guide for .NET MAUI apps consuming .NET Aspire-hosted backend services.

    175 GitHub stars~1.3k tokensUpdated 3 mo ago
    MobileAuto-check passed
  • Azure Identity Dotnet

    microsoft/skills

    Official

    Azure Identity library for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Aspnet Core

    fanslead/ReverseProxy.Store

    Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development.

    161 GitHub starsUsed in 2 repos~1.4k tokens
    Backend & APIsAuto-check passed

More from AzureAD/microsoft-authentication-library-for-dotnet

  • Msal Auth Code Flow

    AzureAD/microsoft-authentication-library-for-dotnet

    Authorization Code Flow for web applications using MSAL.NET confidential client to sign in users and access APIs on their behalf

    1.5k GitHub stars~917 tokensUpdated 3 days ago
    Auto-check passed
  • Msal Client Credentials

    AzureAD/microsoft-authentication-library-for-dotnet

    Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement

    1.5k GitHub stars~1.1k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Msal Obo Flow

What does Msal Obo Flow do?

On-Behalf-Of (OBO) Flow for web APIs to call downstream APIs while preserving user identity in MSAL.NET. Msal Obo Flow is an agent skill from AzureAD/microsoft-authentication-library-for-dotnet.

When should I use Msal Obo Flow?

Msal Obo Flow fits situations like: backend & APIs work in your project.

How do I install Msal Obo Flow in Claude Code?

Run `npx skills add AzureAD/microsoft-authentication-library-for-dotnet --skill msal-obo-flow -a claude-code`. Or copy the skill folder (.github/skills/msal-obo-flow in AzureAD/microsoft-authentication-library-for-dotnet) into .claude/skills/msal-obo-flow in your project. Claude Code loads it when a task matches its description.

How do I install Msal Obo Flow in Codex?

Run `npx skills add AzureAD/microsoft-authentication-library-for-dotnet --skill msal-obo-flow -a codex`. Or copy the skill folder (.github/skills/msal-obo-flow in AzureAD/microsoft-authentication-library-for-dotnet) into .agents/skills/msal-obo-flow in your project. Codex loads it when a task matches its description.

Can I use Msal Obo Flow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AzureAD/microsoft-authentication-library-for-dotnet --skill msal-obo-flow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/msal-obo-flow, .gemini/skills/msal-obo-flow, .github/skills/msal-obo-flow and .opencode/skills/msal-obo-flow in your project.

What does Msal Obo Flow need to run?

SKILL.md names no scripts, command-line tools or credentials: Msal Obo Flow is instructions for the agent only.

Does Msal Obo Flow access the network?

SKILL.md names 2 domains. In commands or code: login.microsoftonline.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Msal Obo Flow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Msal Obo Flow use?

Msal Obo Flow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Msal Obo Flow use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Msal Obo Flow?

Skills that share tags, products or a category with Msal Obo Flow: Microsoft Azure Webjobs Extensions Authentication Events Dotnet (microsoft/skills, 3.1k stars), Azure Relay (MicrosoftDocs/Agent-Skills, 776 stars), Maui Aspire (davidortinau/maui-skills, 175 stars) and Azure Identity Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Msal Obo Flow?

AzureAD (a GitHub organization) maintains it in AzureAD/microsoft-authentication-library-for-dotnet, which has 1,504 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: AzureAD/microsoft-authentication-library-for-dotnet on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.