Agent skill

Troubleshooting Authentication

by microsoft-foundry in microsoft-foundry/foundry-agent-webapp

Provides authentication troubleshooting for MSAL, JWT, and Entra ID.

MITAuto-check: notesBackend & APIs

Install Troubleshooting Authentication

skills CLI
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill troubleshooting-authentication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft-foundry/foundry-agent-webapp troubleshooting-authentication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/troubleshooting-authentication .claude/skills/troubleshooting-authentication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
troubleshooting-authentication
GitHub stars
127
Token cost
~682 tokens
SKILL.md length
178 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Provides authentication troubleshooting for MSAL, JWT, and Entra ID.

  • Works in 3 steps: Browser → MSAL.js (PKCE flow) → JWT with… → Frontend → Backend (JWT Bearer token) → Backend → Foundry Agent Service…
  • Debugging 401 errors
  • SKILL.md covers Architecture, Common Issues, Backend: JWT Validation and Backend: Credential Strategy, plus 4 more sections
  • Calls az

What it does

Troubleshooting Authentication is an agent skill from microsoft-foundry/foundry-agent-webapp. Provides authentication troubleshooting for MSAL, JWT, and Entra ID. Use when debugging 401 errors, token issues, MSAL configuration problems, or credential failures in this repository.

Its SKILL.md is about 680 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Microsoft Entra ID and Microsoft Azure. The repository describes itself as: GitHub Copilot enabled repo for building and deploying a web application with Entra ID authentication and integrated with Azure AI Foundry Agents. The licence is MIT.

When your agent uses it

  • Debugging 401 errors
  • MSAL configuration problems
  • Credential failures in this repository

Example prompts

  • “Use the troubleshooting-authentication skill to provide authentication troubleshooting for MSAL, JWT, and Entra ID”
  • “/troubleshooting-authentication”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Browser → MSAL.js (PKCE flow) → JWT with Chat.ReadWrite scope
  2. Frontend → Backend (JWT Bearer token)
  3. Backend → Foundry Agent Service (ManagedIdentityCredential)

What it can do on your machine

Read from SKILL.md and the folder at commit f6cb362. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • jwt.ms

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Troubleshooting Authentication loads about 682 tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 178 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~682

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:75
    **Frontend** (`.env.local`):
  • NoteMentions a .env fileSKILL.md:81
    **Backend** (`.env`):
  • NoteMentions a .env fileSKILL.md:87
    Run `azd up` to recreate Entra app and `.env` files.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft-foundry/foundry-agent-webapp at commit f6cb362, republished under its MIT licence (© microsoft-foundry). 178 words, ~682 tokens.

Download SKILL.mdSave it as .claude/skills/troubleshooting-authentication/SKILL.md (or your agent's skills folder).
name
troubleshooting-authentication
description
Provides authentication troubleshooting for MSAL, JWT, and Entra ID. Use when debugging 401 errors, token issues, MSAL configuration problems, or credential failures in this repository.

Authentication Troubleshooting

Architecture

  1. Browser → MSAL.js (PKCE flow) → JWT with Chat.ReadWrite scope
  2. Frontend → Backend (JWT Bearer token)
  3. Backend → Foundry Agent Service (ManagedIdentityCredential)

Common Issues

IssueCauseFix
401 on /api/*Token missing scopeVerify Chat.ReadWrite scope in token
ManagedIdentityCredential error locallyWrong environmentSet ASPNETCORE_ENVIRONMENT=Development
Token popup blockedBrowser settingsAllow popups for localhost
Silent token failsNo cached tokenFallback to popup (handled by useAuth)

Backend: JWT Validation

Accepts both audience formats:

csharp
options.TokenValidationParameters.ValidAudiences = new[]
{
    builder.Configuration["AzureAd:ClientId"],
    $"api://{builder.Configuration["AzureAd:ClientId"]}"
};

Backend: Credential Strategy

csharp
TokenCredential credential = env.IsDevelopment()
    ? new ChainedTokenCredential(
        new AzureCliCredential(),
        new AzureDeveloperCliCredential())  // Supports 'azd auth login'
    : new ManagedIdentityCredential();

Local development: Requires az login or azd auth login to work.

Why ChainedTokenCredential: Avoids DefaultAzureCredential's unpredictable "fail fast" mode. Provides explicit, debuggable credential chain.

Frontend: MSAL Pattern

typescript
// Always try silent first
try {
  const { accessToken } = await instance.acquireTokenSilent({
    ...tokenRequest,
    account: accounts[0]
  });
  return accessToken;
} catch {
  // Fallback to popup
  const { accessToken } = await instance.acquireTokenPopup(tokenRequest);
  return accessToken;
}

Debugging Steps

  1. Check token contents: https://jwt.ms
  2. Verify scope: Token should have Chat.ReadWrite
  3. Check audience: Should match client ID or api://{clientId}
  4. Verify Entra app: Check redirect URIs in Azure Portal

Environment Variables

Frontend (.env.local):

ini
VITE_ENTRA_SPA_CLIENT_ID=...
VITE_ENTRA_TENANT_ID=...

Backend (.env):

ini
AzureAd__ClientId=...
AzureAd__TenantId=...

Regenerate: Run azd up to recreate Entra app and .env files.

  • writing-csharp-code - Backend JWT validation and credential patterns
  • writing-typescript-code - Frontend MSAL integration and useAuth hook
  • deploying-to-azure - Entra app provisioning and RBAC configuration

© microsoft-foundry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/troubleshooting-authentication of microsoft-foundry/foundry-agent-webapp.

Open the folder on GitHubat commit f6cb362

Compare with similar skills

Troubleshooting Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Troubleshooting Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Troubleshooting Authentication this skillmicrosoft-foundry/foundry-agent-webapp127—~682Automated safety check: NotesMIT
Microsoft Azure Webjobs Extensions Authentication Events Dotnetmicrosoft/skills3.1k5 repos~3.8kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills412—~3.1kAutomated safety check: NotesMIT
Auditing Azure Active Directory Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Azure Identity Pymicrosoft/skills3.1k—~4.4kAutomated safety check: PassMIT

Similar skills

  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    412 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Auditing Azure Active Directory Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Azure Identity Py

    microsoft/skills

    Official

    Azure Identity SDK for Python authentication with Microsoft Entra ID.

    3.1k GitHub stars~4.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed

More from microsoft-foundry/foundry-agent-webapp

All 19 skills in this repo
  • Committing Code

    microsoft-foundry/foundry-agent-webapp

    Provides commit message format and workflow for this repository.

    127 GitHub stars~512 tokensUpdated 5 mo ago
    Auto-check passed
  • Implementing Chat Streaming

    microsoft-foundry/foundry-agent-webapp

    Provides SSE streaming patterns for the chat API and frontend.

    127 GitHub stars~1.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Planning Features

    microsoft-foundry/foundry-agent-webapp

    Provides structured plan template for feature implementation.

    127 GitHub stars~548 tokensUpdated 5 mo ago
    Auto-check passed
  • Researching Azure AI SDK

    microsoft-foundry/foundry-agent-webapp

    Provides research patterns for Foundry Agent Service SDK. An agent skill from microsoft-foundry/foundry-agent-webapp.

    127 GitHub stars~4.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Deploying To Azure

    microsoft-foundry/foundry-agent-webapp

    Provides deployment commands and troubleshooting for Azure Container Apps.

    127 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check: warnings
  • Syncing MCP Servers

    microsoft-foundry/foundry-agent-webapp

    Synchronize MCP server configuration between VS Code (.vscode/mcp.json) and Copilot CLI (~/.copilot/mcp-config.json).

    127 GitHub stars~1.3k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Troubleshooting Authentication

What does Troubleshooting Authentication do?

Provides authentication troubleshooting for MSAL, JWT, and Entra ID. Troubleshooting Authentication is an agent skill from microsoft-foundry/foundry-agent-webapp. Provides authentication troubleshooting for MSAL, JWT, and Entra ID.

When should I use Troubleshooting Authentication?

Troubleshooting Authentication fits situations like: debugging 401 errors; MSAL configuration problems; credential failures in this repository.

How do I install Troubleshooting Authentication in Claude Code?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill troubleshooting-authentication -a claude-code`. Or copy the skill folder (.github/skills/troubleshooting-authentication in microsoft-foundry/foundry-agent-webapp) into .claude/skills/troubleshooting-authentication in your project. Claude Code loads it when a task matches its description.

How do I install Troubleshooting Authentication in Codex?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill troubleshooting-authentication -a codex`. Or copy the skill folder (.github/skills/troubleshooting-authentication in microsoft-foundry/foundry-agent-webapp) into .agents/skills/troubleshooting-authentication in your project. Codex loads it when a task matches its description.

Can I use Troubleshooting Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft-foundry/foundry-agent-webapp --skill troubleshooting-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/troubleshooting-authentication, .gemini/skills/troubleshooting-authentication, .github/skills/troubleshooting-authentication and .opencode/skills/troubleshooting-authentication in your project.

What does Troubleshooting Authentication need to run?

Going by SKILL.md and its folder, Troubleshooting Authentication needs the command-line tools its instructions call (az).

Does Troubleshooting Authentication access the network?

SKILL.md names 1 domain. As links in the text: jwt.ms. This is read from the text; nothing was executed.

Is Troubleshooting Authentication safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Troubleshooting Authentication use?

Troubleshooting Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Troubleshooting Authentication use?

About 682 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Troubleshooting Authentication?

Skills that share tags, products or a category with Troubleshooting Authentication: Microsoft Azure Webjobs Extensions Authentication Events Dotnet (microsoft/skills, 3.1k stars), Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars), Iam Audit (briiirussell/cybersecurity-skills, 412 stars) and Auditing Azure Active Directory Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Troubleshooting Authentication?

microsoft-foundry (a GitHub organization) maintains it in microsoft-foundry/foundry-agent-webapp, which has 127 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on April 21, 2026.

Source: microsoft-foundry/foundry-agent-webapp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.