Agent skill

Azure Auth

by LeoYeAI in LeoYeAI/openclaw-master-skills

Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library.

MITAuto-check: notesBackend & APIs

Install Azure Auth

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill azure-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills azure-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-auth .claude/skills/azure-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-auth
GitHub stars
2.2k
Token cost
~4.9k tokens
SKILL.md length
822 words
Files
11 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library.

  • Works in 10 steps: Install Dependencies → Azure Portal Setup → AADSTS50058 - Silent Sign-In Loop → …
  • : implementing Microsoft SSO
  • SKILL.md covers Architecture Overview, Quick Start, Frontend: MSAL React Setup and Backend: Cloudflare Workers…, plus 4 more sections
  • Runs TypeScript scripts from its folder; calls npm; reaches login.microsoftonline.com and graph.microsoft.com

What it does

Azure Auth is an agent skill from LeoYeAI/openclaw-master-skills. Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library. Full-stack pattern with Authorization Code Flow + PKCE. Prevents 8 documented errors. Use when: implementing Microsoft SSO, troubleshooting AADSTS50058 loops, AADSTS700084 refresh token errors, React Router redirects, setActiveAccount re-render issues, or validating Entra ID tokens in Workers.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including reference files (for example `.claude-plugin/plugin.json`, `README.md` and `_meta.json`).

It sits in Backend & APIs, covering Authentication and OAuth and OpenID Connect. It works with Microsoft Entra ID, Microsoft Azure, Cloudflare Workers and React. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • : implementing Microsoft SSO
  • Troubleshooting AADSTS50058 loops
  • AADSTS700084 refresh token errors
  • React Router redirects

Example prompts

  • “/azure-auth”

Requirements

  • Node.js

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Install Dependencies
  2. Azure Portal Setup
  3. AADSTS50058 - Silent Sign-In Loop
  4. AADSTS700084 - Refresh Token Expired
  5. React Router v6 Redirect Loop
  6. NextJS Dynamic Route Error
  7. Safari/Edge Cookie Issues
  8. JWKS URL Not Found (Workers)
  9. React Router Loader State Conflict
  10. setActiveAccount Doesn't Trigger Re-render (Community-sourced)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • login.microsoftonline.com
    • graph.microsoft.com

    Also links to:

    • learn.microsoft.com
    • github.com
    • hajekj.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Auth loads about 4.9k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 822 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:545
    ### Frontend (.env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 822 words, ~4,934 tokens.

Download SKILL.mdSave it as .claude/skills/azure-auth/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
azure-auth
description
Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library. Full-stack pattern with Authorization Code Flow + PKCE. Prevents 8 documented errors. Use when: implementing Microsoft SSO, troubleshooting AADSTS50058 loops, AADSTS700084 refresh token errors, React Router redirects, setActiveAccount re-render issues, or validating Entra ID tokens in Workers.
user-invocable
true

Azure Auth - Microsoft Entra ID for React + Cloudflare Workers

Package Versions: @azure/msal-react@5.0.2, @azure/msal-browser@5.0.2, jose@6.1.3 Breaking Changes: MSAL v4→v5 migration (January 2026), Azure AD B2C sunset (May 2025 - new signups blocked, existing until 2030), ADAL retirement (Sept 2025 - complete) Last Updated: 2026-01-21


Architecture Overview

┌─────────────────────┐     ┌──────────────────────┐     ┌─────────────────────┐
│   React SPA         │────▶│  Microsoft Entra ID  │────▶│  Cloudflare Worker  │
│   @azure/msal-react │     │  (login.microsoft)   │     │  jose JWT validation│
└─────────────────────┘     └──────────────────────┘     └─────────────────────┘
        │                                                          │
        │  Authorization Code + PKCE                               │
        │  (access_token, id_token)                                │
        └──────────────────────────────────────────────────────────┘
                    Bearer token in Authorization header

Key Constraint: MSAL.js does NOT work in Cloudflare Workers (relies on browser/Node.js APIs). Use jose library for backend token validation.


Quick Start

1. Install Dependencies
bash
# Frontend (React SPA)
npm install @azure/msal-react @azure/msal-browser

# Backend (Cloudflare Workers)
npm install jose
2. Azure Portal Setup
  1. Go to Microsoft Entra ID → App registrations → New registration
  2. Set Redirect URI to http://localhost:5173 (SPA type)
  3. Note the Application (client) ID and Directory (tenant) ID
  4. Under Authentication:
    • Enable Access tokens and ID tokens
    • Add production redirect URI
  5. Under API permissions:
    • Add User.Read (Microsoft Graph)
    • Grant admin consent if required

Frontend: MSAL React Setup

Configuration (src/auth/msal-config.ts)
typescript
import { Configuration, LogLevel } from "@azure/msal-browser";

export const msalConfig: Configuration = {
  auth: {
    clientId: import.meta.env.VITE_AZURE_CLIENT_ID,
    authority: `https://login.microsoftonline.com/${import.meta.env.VITE_AZURE_TENANT_ID}`,
    redirectUri: window.location.origin,
    postLogoutRedirectUri: window.location.origin,
    navigateToLoginRequestUrl: true,
  },
  cache: {
    cacheLocation: "localStorage", // or "sessionStorage"
    storeAuthStateInCookie: true, // Required for Safari/Edge issues
  },
  system: {
    loggerOptions: {
      logLevel: LogLevel.Warning,
      loggerCallback: (level, message) => {
        if (level === LogLevel.Error) console.error(message);
      },
    },
  },
};

// Scopes for token requests
export const loginRequest = {
  scopes: ["User.Read", "openid", "profile", "email"],
};

// Scopes for API calls (add your API scope here)
export const apiRequest = {
  scopes: [`api://${import.meta.env.VITE_AZURE_CLIENT_ID}/access_as_user`],
};
MsalProvider Setup (src/main.tsx)
typescript
import React from "react";
import ReactDOM from "react-dom/client";
import { PublicClientApplication, EventType } from "@azure/msal-browser";
import { MsalProvider } from "@azure/msal-react";
import { msalConfig } from "./auth/msal-config";
import App from "./App";

// CRITICAL: Initialize MSAL outside component tree to prevent re-instantiation
const msalInstance = new PublicClientApplication(msalConfig);

// Handle redirect promise on page load
msalInstance.initialize().then(() => {
  // Set active account after redirect
  // IMPORTANT: Use getAllAccounts() (returns array), NOT getActiveAccount() (returns single account or null)
  const accounts = msalInstance.getAllAccounts();
  if (accounts.length > 0) {
    msalInstance.setActiveAccount(accounts[0]);
  }

  // Listen for sign-in events
  msalInstance.addEventCallback((event) => {
    if (event.eventType === EventType.LOGIN_SUCCESS && event.payload) {
      const account = (event.payload as { account: any }).account;
      msalInstance.setActiveAccount(account);
    }
  });

  ReactDOM.createRoot(document.getElementById("root")!).render(
    <React.StrictMode>
      <MsalProvider instance={msalInstance}>
        <App />
      </MsalProvider>
    </React.StrictMode>
  );
});
Protected Route Component
typescript
import { useMsal, useIsAuthenticated } from "@azure/msal-react";
import { InteractionStatus } from "@azure/msal-browser";
import { loginRequest } from "./msal-config";

export function ProtectedRoute({ children }: { children: React.ReactNode }) {
  const { instance, inProgress } = useMsal();
  const isAuthenticated = useIsAuthenticated();

  // Wait for MSAL to finish any in-progress operations
  if (inProgress !== InteractionStatus.None) {
    return <div>Loading...</div>;
  }

  if (!isAuthenticated) {
    // Trigger login redirect
    instance.loginRedirect(loginRequest);
    return <div>Redirecting to login...</div>;
  }

  return <>{children}</>;
}
Acquiring Tokens for API Calls
typescript
import { useMsal } from "@azure/msal-react";
import { InteractionRequiredAuthError } from "@azure/msal-browser";
import { apiRequest } from "./msal-config";

export function useApiToken() {
  const { instance, accounts } = useMsal();

  async function getAccessToken(): Promise<string | null> {
    if (accounts.length === 0) return null;

    const request = {
      ...apiRequest,
      account: accounts[0],
    };

    try {
      // Try silent token acquisition first
      const response = await instance.acquireTokenSilent(request);
      return response.accessToken;
    } catch (error) {
      if (error instanceof InteractionRequiredAuthError) {
        // Silent acquisition failed, need interactive login
        // This handles expired refresh tokens (AADSTS700084)
        await instance.acquireTokenRedirect(request);
        return null;
      }
      throw error;
    }
  }

  return { getAccessToken };
}

Backend: Cloudflare Workers JWT Validation

Why jose Instead of MSAL

MSAL.js relies on browser APIs (localStorage, sessionStorage) and Node.js crypto modules that don't exist in Cloudflare Workers' V8 isolate runtime. The jose library is pure JavaScript and works perfectly in Workers.

JWT Validation (src/auth/validate-token.ts)
typescript
import * as jose from "jose";

interface EntraTokenPayload {
  aud: string;       // Audience (your client ID or API URI)
  iss: string;       // Issuer (https://login.microsoftonline.com/{tenant}/v2.0)
  sub: string;       // Subject (user's unique ID)
  oid: string;       // Object ID (user's Azure AD object ID)
  preferred_username: string;
  name: string;
  email?: string;
  roles?: string[];  // App roles if configured
  scp?: string;      // Scopes (space-separated)
}

// Cache JWKS to avoid fetching on every request
let jwksCache: jose.JWTVerifyGetKey | null = null;
let jwksCacheTime = 0;
const JWKS_CACHE_DURATION = 3600000; // 1 hour

async function getJWKS(tenantId: string): Promise<jose.JWTVerifyGetKey> {
  const now = Date.now();

  if (jwksCache && now - jwksCacheTime < JWKS_CACHE_DURATION) {
    return jwksCache;
  }

  // CRITICAL: Azure AD JWKS is NOT at .well-known/jwks.json
  // Must fetch from openid-configuration first
  const configUrl = `https://login.microsoftonline.com/${tenantId}/v2.0/.well-known/openid-configuration`;
  const configResponse = await fetch(configUrl);
  const config = await configResponse.json() as { jwks_uri: string };

  // Now fetch JWKS from the correct URL
  jwksCache = jose.createRemoteJWKSet(new URL(config.jwks_uri));
  jwksCacheTime = now;

  return jwksCache;
}

export async function validateEntraToken(
  token: string,
  env: {
    AZURE_TENANT_ID: string;
    AZURE_CLIENT_ID: string;
  }
): Promise<EntraTokenPayload | null> {
  try {
    const jwks = await getJWKS(env.AZURE_TENANT_ID);

    const { payload } = await jose.jwtVerify(token, jwks, {
      issuer: `https://login.microsoftonline.com/${env.AZURE_TENANT_ID}/v2.0`,
      audience: env.AZURE_CLIENT_ID, // or your API URI: api://{client_id}
    });

    return payload as unknown as EntraTokenPayload;
  } catch (error) {
    console.error("Token validation failed:", error);
    return null;
  }
}
Worker Middleware Pattern
typescript
import { validateEntraToken } from "./auth/validate-token";

export default {
  async fetch(request: Request, env: Env): Promise<Response> {
    // Skip auth for public routes
    const url = new URL(request.url);
    if (url.pathname === "/" || url.pathname.startsWith("/public")) {
      return handlePublicRoute(request, env);
    }

    // Extract Bearer token
    const authHeader = request.headers.get("Authorization");
    if (!authHeader?.startsWith("Bearer ")) {
      return new Response(JSON.stringify({ error: "Missing authorization" }), {
        status: 401,
        headers: { "Content-Type": "application/json" },
      });
    }

    const token = authHeader.slice(7);
    const user = await validateEntraToken(token, env);

    if (!user) {
      return new Response(JSON.stringify({ error: "Invalid token" }), {
        status: 401,
        headers: { "Content-Type": "application/json" },
      });
    }

    // Add user to request context
    const requestWithUser = new Request(request);
    // Pass user info downstream (e.g., via headers or context)

    return handleProtectedRoute(request, env, user);
  },
};

Common Errors & Fixes

1. AADSTS50058 - Silent Sign-In Loop

Error: "A silent sign-in request was sent but no user is signed in"

Cause: acquireTokenSilent called when no cached user exists.

Fix:

typescript
// Always check for accounts before silent acquisition
const accounts = instance.getAllAccounts();
if (accounts.length === 0) {
  // No cached user, trigger interactive login
  await instance.loginRedirect(loginRequest);
  return;
}
2. AADSTS700084 - Refresh Token Expired

Error: "The refresh token was issued to a single page app (SPA), and therefore has a fixed, limited lifetime of 1.00:00:00"

Cause: SPA refresh tokens expire after 24 hours. Cannot be extended.

Fix:

typescript
try {
  const response = await instance.acquireTokenSilent(request);
} catch (error) {
  if (error instanceof InteractionRequiredAuthError) {
    // Refresh token expired, need fresh login
    await instance.acquireTokenRedirect(request);
  }
}
3. React Router v6 Redirect Loop

Error: Infinite redirects between login page and app.

Cause: React Router v6 may strip the hash fragment containing auth response.

Fix: Use custom NavigationClient:

typescript
import { NavigationClient } from "@azure/msal-browser";
import { useNavigate } from "react-router-dom";

class CustomNavigationClient extends NavigationClient {
  private navigate: ReturnType<typeof useNavigate>;

  constructor(navigate: ReturnType<typeof useNavigate>) {
    super();
    this.navigate = navigate;
  }

  async navigateInternal(url: string, options: { noHistory: boolean }) {
    const relativePath = url.replace(window.location.origin, "");
    if (options.noHistory) {
      this.navigate(relativePath, { replace: true });
    } else {
      this.navigate(relativePath);
    }
    return false; // Prevent MSAL from doing its own navigation
  }
}

// In your App component:
const navigate = useNavigate();
useEffect(() => {
  const navigationClient = new CustomNavigationClient(navigate);
  instance.setNavigationClient(navigationClient);
}, [instance, navigate]);
4. NextJS Dynamic Route Error

Error: no_cached_authority_error in dynamic routes.

Cause: MSAL instance not properly initialized before component renders.

Fix: Initialize MSAL in _app.tsx before any routing:

typescript
// pages/_app.tsx
import { PublicClientApplication } from "@azure/msal-browser";
import { MsalProvider } from "@azure/msal-react";
import { msalConfig } from "../auth/msal-config";

// Initialize outside component
const msalInstance = new PublicClientApplication(msalConfig);

// Ensure initialization completes before render
export default function App({ Component, pageProps }) {
  const [isInitialized, setIsInitialized] = useState(false);

  useEffect(() => {
    msalInstance.initialize().then(() => setIsInitialized(true));
  }, []);

  if (!isInitialized) return <div>Loading...</div>;

  return (
    <MsalProvider instance={msalInstance}>
      <Component {...pageProps} />
    </MsalProvider>
  );
}

Error: Auth state lost, infinite loop on Safari or Edge. On iOS 18 Safari specifically, silent token refresh fails with AADSTS50058 even when third-party cookies are enabled.

Source: GitHub Issue #7384

Cause: These browsers have stricter cookie policies affecting session storage. iOS 18 Safari doesn't store the required session cookies for login.microsoftonline.com, even with third-party cookies explicitly allowed in settings.

Testing Note: Works in Chrome on iOS 18, but fails in Safari on iOS 18.

Fix: Enable cookie storage in MSAL config:

typescript
cache: {
  cacheLocation: "localStorage",
  storeAuthStateInCookie: true, // REQUIRED for Safari/Edge
}

iOS 18 Safari Limitation: If users still experience issues on iOS 18 Safari after enabling cookie storage, this is a known browser limitation with no current workaround. Recommend using Chrome on iOS or desktop browser.

6. JWKS URL Not Found (Workers)

Error: Failed to fetch JWKS from .well-known/jwks.json.

Cause: Azure AD doesn't serve JWKS at the standard OpenID Connect path.

Fix: Fetch openid-configuration first, then use jwks_uri:

typescript
// WRONG - Azure AD doesn't use this path
const jwks = createRemoteJWKSet(
  new URL(`https://login.microsoftonline.com/${tenantId}/.well-known/jwks.json`)
);

// CORRECT - Fetch config first
const config = await fetch(
  `https://login.microsoftonline.com/${tenantId}/v2.0/.well-known/openid-configuration`
).then(r => r.json());
const jwks = createRemoteJWKSet(new URL(config.jwks_uri));
7. React Router Loader State Conflict

Error: React warning about updating state during render when using acquireTokenSilent in React Router loaders.

Source: GitHub Issue #7068

Cause: Using the same PublicClientApplication instance in both the router loader and MsalProvider causes state updates during rendering.

Fix: Call initialize() again in the loader:

typescript
const protectedLoader = async () => {
  await msalInstance.initialize(); // Prevents state conflict
  const response = await msalInstance.acquireTokenSilent(request);
  return { data };
};
Show full SKILL.md (304 more words)Show less
8. setActiveAccount Doesn't Trigger Re-render (Community-sourced)

Error: Components using useMsal() don't update after calling setActiveAccount().

Source: GitHub Issue #6989

Verified: Multiple users confirmed in GitHub issue

Cause: setActiveAccount() updates the MSAL instance but doesn't notify React of the change.

Fix: Force re-render with state:

typescript
const [accountKey, setAccountKey] = useState(0);

const switchAccount = (newAccount) => {
  msalInstance.setActiveAccount(newAccount);
  setAccountKey(prev => prev + 1); // Force update
};

Multi-Tenant vs Single-Tenant

typescript
authority: `https://login.microsoftonline.com/${TENANT_ID}`,
  • Only users from your organization can sign in
  • Token issuer: https://login.microsoftonline.com/{tenant_id}/v2.0
Multi-Tenant
typescript
authority: "https://login.microsoftonline.com/common",
// or for work/school accounts only:
authority: "https://login.microsoftonline.com/organizations",
  • Users from any Azure AD tenant can sign in
  • Token issuer varies by user's tenant
  • Backend validation must handle multiple issuers:
typescript
// Multi-tenant issuer validation
const tenantId = payload.tid; // Tenant ID from token
const expectedIssuer = `https://login.microsoftonline.com/${tenantId}/v2.0`;
if (payload.iss !== expectedIssuer) {
  throw new Error("Invalid issuer");
}

Environment Variables

Frontend (.env)
bash
VITE_AZURE_CLIENT_ID=your-client-id-guid
VITE_AZURE_TENANT_ID=your-tenant-id-guid
Backend (wrangler.jsonc)
jsonc
{
  "name": "my-api",
  "vars": {
    "AZURE_TENANT_ID": "your-tenant-id-guid",
    "AZURE_CLIENT_ID": "your-client-id-guid"
  }
}

Azure AD B2C Sunset

Timeline:

  • May 1, 2025: Azure AD B2C no longer available for new customer signups
  • March 15, 2026: Azure AD B2C P2 discontinued for all customers
  • May 2030: Microsoft will continue supporting existing B2C customers with standard support

Source: Microsoft Q&A

Existing B2C Customers: Can continue using B2C until 2030, but should plan migration to Entra External ID.

New Projects: Use Microsoft Entra External ID for consumer/customer identity scenarios.

Migration Status: As of January 2026, automated migration tools are in testing phase. Manual migration guidance available at Microsoft Learn.

Migration Path:

  • Different authority URL format ({tenant}.ciamlogin.com vs {tenant}.b2clogin.com)
  • Updated SDK support (same MSAL libraries)
  • New pricing model (consumption-based)
  • Self-Service Password Reset (SSPR) approach available for user migration
  • Seamless migration samples on GitHub (preview)

See: https://learn.microsoft.com/en-us/entra/external-id/ Migration Guide: https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-migrate-users


ADAL Retirement (Complete)

Status: Azure AD Authentication Library (ADAL) was retired on September 30, 2025. Apps using ADAL no longer receive security updates.

If you're migrating from ADAL:

  1. ADAL → MSAL migration is required
  2. ADAL used v1.0 endpoints; MSAL uses v2.0 endpoints
  3. Token cache format differs - users must re-authenticate
  4. Scopes replace "resources" in token requests

Key Migration Changes:

typescript
// ADAL (deprecated) - resource-based
acquireToken({ resource: "https://graph.microsoft.com" })

// MSAL (current) - scope-based
acquireTokenSilent({ scopes: ["https://graph.microsoft.com/User.Read"] })

See: https://learn.microsoft.com/en-us/entra/msal/javascript/migration/msal-net-migration


Resources

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (references) in skills/azure-auth of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • .claude-plugin/plugin.json
  • README.md
  • _meta.json
  • references/aadsts-error-codes.md
  • rules/azure-auth.md
  • templates/msal-config.ts
  • templates/msal-provider.tsx
  • templates/protected-route.tsx
  • templates/use-api-token.ts
  • templates/workers-jwt-validation.ts

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Azure Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Auth this skillLeoYeAI/openclaw-master-skills2.2k—~4.9kAutomated safety check: NotesMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills413—~3.1kAutomated safety check: NotesMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Entra Idvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2552 repos~4kAutomated safety check: PassMIT

Similar skills

  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    413 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Entra Id

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra ID (formerly Azure AD) — cloud identity and access management and the control plane for Zero Trust.

    175 GitHub stars~2.3k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Azure Auth

What does Azure Auth do?

Microsoft Entra ID (Azure AD) authentication for React SPAs with MSAL.js and Cloudflare Workers JWT validation using jose library. Azure Auth is an agent skill from LeoYeAI/openclaw-master-skills.js and Cloudflare Workers JWT validation using jose library.

When should I use Azure Auth?

Azure Auth fits situations like: : implementing Microsoft SSO; troubleshooting AADSTS50058 loops; AADSTS700084 refresh token errors; React Router redirects.

How do I install Azure Auth in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-auth -a claude-code`. Or copy the skill folder (skills/azure-auth in LeoYeAI/openclaw-master-skills) into .claude/skills/azure-auth in your project. Claude Code loads it when a task matches its description.

How do I install Azure Auth in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-auth -a codex`. Or copy the skill folder (skills/azure-auth in LeoYeAI/openclaw-master-skills) into .agents/skills/azure-auth in your project. Codex loads it when a task matches its description.

Can I use Azure Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill azure-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-auth, .gemini/skills/azure-auth, .github/skills/azure-auth and .opencode/skills/azure-auth in your project.

What does Azure Auth need to run?

Going by SKILL.md and its folder, Azure Auth needs TypeScript for the scripts in its folder and the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does Azure Auth access the network?

SKILL.md names 5 domains. In commands or code: login.microsoftonline.com and graph.microsoft.com; the agent is likely to contact these when it follows the instructions. As links in the text: learn.microsoft.com, github.com and hajekj.net. This is read from the text; nothing was executed.

Is Azure Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Azure Auth use?

Azure Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Auth use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Azure Auth?

Skills that share tags, products or a category with Azure Auth: Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars), Iam Audit (briiirussell/cybersecurity-skills, 413 stars), Apex Entra App Registration (jonathan-vella/apex, 217 stars) and Entra Id (vinayaklatthe/microsoft-security-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Auth?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.