Official agent skill

Azure Identity TS

by microsoft in microsoft/skills

Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity).

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Identity TS

skills CLI
$ npx skills add microsoft/skills --skill azure-identity-ts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-identity-ts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-typescript/skills/azure-identity-ts .claude/skills/azure-identity-ts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-identity-ts
GitHub stars
3.1k
Token cost
~2k tokens
SKILL.md length
157 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity).

  • Works in 6 steps: Use DefaultAzureCredential for local… → Never hardcode credentials - Use… → Prefer managed identity - No secrets to… → …
  • Configuring authentication with DefaultAzureCredential
  • SKILL.md covers Installation, Environment Variables, DefaultAzureCredential… and Managed Identity, plus 10 more sections
  • Calls npm; reaches learn.microsoft.com and cognitiveservices.azure.com; needs AZURE_TOKEN_CREDENTIALS and AZURE_CLIENT_SECRET

What it does

Azure Identity TS is an agent skill from microsoft/skills, published by the product's own GitHub organization. Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity). Use when configuring authentication with DefaultAzureCredential, managed identity, service principals, or interactive browser login.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/browser-auth.md` and `references/credential-types.md`).

It sits in DevOps & Cloud, covering Authentication. It works with Microsoft Azure, Visual Studio Code, TypeScript and JavaScript. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Configuring authentication with DefaultAzureCredential
  • Managed identity
  • Service principals
  • Interactive browser login

Example prompts

  • “/azure-identity-ts”

Requirements

  • Node.js
  • A credential in AZURE_CLIENT_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Use DefaultAzureCredential for local development; use ManagedIdentityCredential or WorkloadIdentityCredential for production
  2. Never hardcode credentials - Use environment variables or managed identity
  3. Prefer managed identity - No secrets to manage in production
  4. Scope credentials appropriately - Use user-assigned identity for multi-tenant scenarios
  5. Handle token refresh - Azure SDK handles this automatically
  6. Use ChainedTokenCredential - For custom fallback scenarios

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com
    • cognitiveservices.azure.com

    Also links to:

    • aka.ms

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS
    • AZURE_CLIENT_SECRET
    • AZURE_CLIENT_CERTIFICATE_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Identity TS loads about 2k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 157 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 157 words, ~1,989 tokens.

Download SKILL.mdSave it as .claude/skills/azure-identity-ts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-identity-ts
description
Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity). Use when configuring authentication with DefaultAzureCredential, managed identity, service principals, or interactive browser login.
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
@azure/identity

Azure Identity library for TypeScript

Authentication library for Azure SDK clients using Microsoft Entra ID.

Installation

bash
npm install @azure/identity

# For Visual Studio Code credential support
npm install @azure/identity-vscode

Environment Variables

Service Principal (Secret)
bash
AZURE_TENANT_ID=<tenant-id>
AZURE_CLIENT_ID=<client-id>
AZURE_CLIENT_SECRET=<client-secret>
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production
Service Principal (Certificate)
bash
AZURE_TENANT_ID=<tenant-id>
AZURE_CLIENT_ID=<client-id>
AZURE_CLIENT_CERTIFICATE_PATH=/path/to/cert.pem
AZURE_CLIENT_CERTIFICATE_PASSWORD=<optional-password>
Workload Identity (Kubernetes)
bash
AZURE_TENANT_ID=<tenant-id>
AZURE_CLIENT_ID=<client-id>
AZURE_FEDERATED_TOKEN_FILE=/var/run/secrets/tokens/azure-identity
typescript
import { DefaultAzureCredential, ManagedIdentityCredential } from "@azure/identity";

// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
const credential = new DefaultAzureCredential({requiredEnvVars: ["AZURE_TOKEN_CREDENTIALS"]});
// Or use a specific credential directly in production:
// See https://learn.microsoft.com/javascript/api/overview/azure/identity-readme?view=azure-node-latest#credential-classes
// const credential = new ManagedIdentityCredential();

// Use with any Azure SDK client
import { BlobServiceClient } from "@azure/storage-blob";
const blobClient = new BlobServiceClient(
  "https://<account>.blob.core.windows.net",
  credential
);

See DefaultAzureCredential overview for the current credential chain order and defaults.

Managed Identity

System-Assigned
typescript
import { ManagedIdentityCredential } from "@azure/identity";

const credential = new ManagedIdentityCredential();
User-Assigned (by Client ID)
typescript
const credential = new ManagedIdentityCredential({
  clientId: "<user-assigned-client-id>"
});
User-Assigned (by Resource ID)
typescript
const credential = new ManagedIdentityCredential({
  resourceId: "/subscriptions/<sub>/resourceGroups/<rg>/providers/Microsoft.ManagedIdentity/userAssignedIdentities/<name>"
});
User-Assigned (by Object ID)
typescript
const credential = new ManagedIdentityCredential({
  objectId: "<user-assigned-object-id>"
});

Service Principal

Client Secret
typescript
import { ClientSecretCredential } from "@azure/identity";

const credential = new ClientSecretCredential(
  "<tenant-id>",
  "<client-id>",
  "<client-secret>"
);
Client Certificate
typescript
import { ClientCertificateCredential } from "@azure/identity";

const credential = new ClientCertificateCredential(
  "<tenant-id>",
  "<client-id>",
  { certificatePath: "/path/to/cert.pem" }
);

// With password
const credentialWithPwd = new ClientCertificateCredential(
  "<tenant-id>",
  "<client-id>",
  { 
    certificatePath: "/path/to/cert.pem",
    certificatePassword: "<password>"
  }
);

Interactive Authentication

Browser-Based Login
typescript
import { InteractiveBrowserCredential } from "@azure/identity";

const credential = new InteractiveBrowserCredential({
  clientId: "<client-id>",
  tenantId: "<tenant-id>",
  loginHint: "user@example.com"
});
Device Code Flow
typescript
import { DeviceCodeCredential } from "@azure/identity";

const credential = new DeviceCodeCredential({
  clientId: "<client-id>",
  tenantId: "<tenant-id>",
  userPromptCallback: (info) => {
    console.log(info.message);
    // "To sign in, use a web browser to open..."
  }
});

Custom Credential Chain

typescript
import { 
  ChainedTokenCredential,
  ManagedIdentityCredential,
  AzureCliCredential
} from "@azure/identity";

// Try managed identity first, fall back to CLI
const credential = new ChainedTokenCredential(
  new ManagedIdentityCredential(),
  new AzureCliCredential()
);

Developer Credentials

Visual Studio Code
typescript
import { useIdentityPlugin, VisualStudioCodeCredential } from "@azure/identity";
import { vsCodePlugin } from "@azure/identity-vscode";

useIdentityPlugin(vsCodePlugin);

const credential = new VisualStudioCodeCredential();
Azure CLI
typescript
import { AzureCliCredential } from "@azure/identity";

const credential = new AzureCliCredential();
// Uses: az login
Azure Developer CLI
typescript
import { AzureDeveloperCliCredential } from "@azure/identity";

const credential = new AzureDeveloperCliCredential();
// Uses: azd auth login
Azure PowerShell
typescript
import { AzurePowerShellCredential } from "@azure/identity";

const credential = new AzurePowerShellCredential();
// Uses: Connect-AzAccount

Sovereign Clouds

typescript
import { ClientSecretCredential, AzureAuthorityHosts } from "@azure/identity";

// Azure Government
const credential = new ClientSecretCredential(
  "<tenant>", "<client>", "<secret>",
  { authorityHost: AzureAuthorityHosts.AzureGovernment }
);

// Azure China
const credentialChina = new ClientSecretCredential(
  "<tenant>", "<client>", "<secret>",
  { authorityHost: AzureAuthorityHosts.AzureChina }
);

Bearer Token Provider

typescript
import { DefaultAzureCredential, getBearerTokenProvider } from "@azure/identity";

const credential = new DefaultAzureCredential({requiredEnvVars: ["AZURE_TOKEN_CREDENTIALS"]});

// Create a function that returns tokens
const getAccessToken = getBearerTokenProvider(
  credential,
  "https://cognitiveservices.azure.com/.default"
);

// Use with APIs that need bearer tokens
const token = await getAccessToken();

Key Types

typescript
import type { 
  TokenCredential, 
  AccessToken, 
  GetTokenOptions 
} from "@azure/core-auth";

import {
  DefaultAzureCredential,
  DefaultAzureCredentialOptions,
  ManagedIdentityCredential,
  ClientSecretCredential,
  ClientCertificateCredential,
  InteractiveBrowserCredential,
  ChainedTokenCredential,
  AzureCliCredential,
  AzurePowerShellCredential,
  AzureDeveloperCliCredential,
  DeviceCodeCredential,
  AzureAuthorityHosts
} from "@azure/identity";

Custom Credential Implementation

typescript
import type { TokenCredential, AccessToken, GetTokenOptions } from "@azure/core-auth";

class CustomCredential implements TokenCredential {
  async getToken(
    scopes: string | string[],
    options?: GetTokenOptions
  ): Promise<AccessToken | null> {
    // Custom token acquisition logic
    return {
      token: "<access-token>",
      expiresOnTimestamp: Date.now() + 3600000
    };
  }
}

Debugging

typescript
import { setLogLevel, AzureLogger } from "@azure/logger";

setLogLevel("verbose");

// Custom log handler
AzureLogger.log = (...args) => {
  console.log("[Azure]", ...args);
};

Best Practices

  1. Use DefaultAzureCredential for local development; use ManagedIdentityCredential or WorkloadIdentityCredential for production
  2. Never hardcode credentials - Use environment variables or managed identity
  3. Prefer managed identity - No secrets to manage in production
  4. Scope credentials appropriately - Use user-assigned identity for multi-tenant scenarios
  5. Handle token refresh - Azure SDK handles this automatically
  6. Use ChainedTokenCredential - For custom fallback scenarios

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-typescript/skills/azure-identity-ts of microsoft/skills.

  • SKILL.md
  • references/browser-auth.md
  • references/credential-types.md

Open the folder on GitHubat commit 3898ec8

Compare with similar skills

Azure Identity TS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Identity TS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Identity TS this skillmicrosoft/skills3.1k—~2kAutomated safety check: PassMIT
Security Sensitive Path InstrumenterArabelaTso/Skills-4-SE253—~1.1kAutomated safety check: PassApache-2.0
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Create Auth Skilldeadlock-mod-manager/deadlock-mod-manager4774 repos~3.4kAutomated safety check: PassGPL-3.0
Debug CIweb-infra-dev/rslint461—~2.8kAutomated safety check: PassMIT
Sasjs Adaptersasjs/core132—~2.6kAutomated safety check: PassMIT

Similar skills

  • Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

    253 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Create Auth Skill

    deadlock-mod-manager/deadlock-mod-manager

    Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.

    477 GitHub starsUsed in 4 repos~3.4k tokens
    DatabasesAuto-check passed
  • Debug CI

    web-infra-dev/rslint

    Reproduce Linux CI failures locally using Docker when the same tests pass on the host, especially Go platform differences and VS Code extension tests requiring xvfb.

    461 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Sasjs Adapter

    sasjs/core

    Frontend/Node integration with SAS backends using @sasjs/adapter - configuring the SASjs class, the exact request() inputs and response shape, authentication, file upload, and session management.

    132 GitHub stars~2.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Azure Identity Rust

    aiskillstore/marketplace

    Azure Identity SDK for Rust authentication. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~952 tokens
    DevOps & CloudAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Questions about Azure Identity TS

What does Azure Identity TS do?

Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity). Azure Identity TS is an agent skill from microsoft/skills, published by the product's own GitHub organization. Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity).

When should I use Azure Identity TS?

Azure Identity TS fits situations like: configuring authentication with DefaultAzureCredential; managed identity; service principals; interactive browser login.

How do I install Azure Identity TS in Claude Code?

Run `npx skills add microsoft/skills --skill azure-identity-ts -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-typescript/skills/azure-identity-ts in microsoft/skills) into .claude/skills/azure-identity-ts in your project. Claude Code loads it when a task matches its description.

How do I install Azure Identity TS in Codex?

Run `npx skills add microsoft/skills --skill azure-identity-ts -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-typescript/skills/azure-identity-ts in microsoft/skills) into .agents/skills/azure-identity-ts in your project. Codex loads it when a task matches its description.

Can I use Azure Identity TS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-identity-ts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-identity-ts, .gemini/skills/azure-identity-ts, .github/skills/azure-identity-ts and .opencode/skills/azure-identity-ts in your project.

What does Azure Identity TS need to run?

Going by SKILL.md and its folder, Azure Identity TS needs the command-line tools its instructions call (npm) and credentials named AZURE_TOKEN_CREDENTIALS, AZURE_CLIENT_SECRET and AZURE_CLIENT_CERTIFICATE_PASSWORD. Our summary lists: Node.js; A credential in AZURE_CLIENT_SECRET.

Does Azure Identity TS access the network?

SKILL.md names 3 domains. In commands or code: learn.microsoft.com and cognitiveservices.azure.com; the agent is likely to contact these when it follows the instructions. As links in the text: aka.ms. This is read from the text; nothing was executed.

Is Azure Identity TS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Identity TS use?

Azure Identity TS is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Identity TS use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to Azure Identity TS?

Skills that share tags, products or a category with Azure Identity TS: Security Sensitive Path Instrumenter (ArabelaTso/Skills-4-SE, 253 stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars), Create Auth Skill (deadlock-mod-manager/deadlock-mod-manager, 477 stars) and Debug CI (web-infra-dev/rslint, 461 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Identity TS?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.