Official agent skill

Azure Keyvault Certificates Rust

by microsoft in microsoft/skills

Azure Key Vault Certificates library for Rust. An agent skill from microsoft/skills.

OfficialMITAuto-check passedBackend & APIs

Install Azure Keyvault Certificates Rust

skills CLI
$ npx skills add microsoft/skills --skill azure-keyvault-certificates-rust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-keyvault-certificates-rust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-rust/skills/azure-keyvault-certificates-rust .claude/skills/azure-keyvault-certificates-rust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-keyvault-certificates-rust
GitHub stars
3.1k
Token cost
~2k tokens
SKILL.md length
401 words
Files
1
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Key Vault Certificates library for Rust. An agent skill from microsoft/skills.

  • Works in 9 steps: Use cargo add to manage dependencies,… → Add azure_core only when importing… → Use DeveloperToolsCredential for local… → …
  • Backend & APIs work in your project
  • SKILL.md covers Installation, Environment Variables, Authentication and Core Workflow, plus 5 more sections
  • Calls cargo

What it does

Azure Keyvault Certificates Rust is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault Certificates library for Rust. Create, manage, and use X.509 certificates including self-signed and CA-issued. Triggers: "keyvault certificates rust", "CertificateClient rust", "create certificate rust", "self-signed certificate rust", "X.509 rust".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Azure Key Vault, Rust and Microsoft Azure. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “keyvault certificates rust”
  • “CertificateClient rust”
  • “create certificate rust”
  • “/azure-keyvault-certificates-rust”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Use cargo add to manage dependencies, never edit Cargo.toml directly. Add and remove Rust SDK dependencies with cargo commands instead of…
  2. Add azure_core only when importing azure_core types directly. If your code imports azure_core::http::Url…
  3. Use DeveloperToolsCredential for local dev, ManagedIdentityCredential for production — Rust does not provide a single…
  4. Never hardcode credentials — use environment variables or managed identity
  5. Use ..Default::default() with #[allow(clippy::needless_update)] for model struct updates
  6. Use ResourceExt to extract certificate name/version from IDs
  7. LROs — begin_create_certificate returns a Poller; just .await for completion (clients should rarely poll for status)
  8. Reuse clients — CertificateClient is thread-safe; create once, share across tasks
  9. Run cargo clippy -- -D warnings when the prompt, eval, or CI expects lint-clean output

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • crates.io
    • docs.rs
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Keyvault Certificates Rust loads about 2k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 401 words, ~1,964 tokens.

Download SKILL.mdSave it as .claude/skills/azure-keyvault-certificates-rust/SKILL.md (or your agent's skills folder).
name
azure-keyvault-certificates-rust
description
Azure Key Vault Certificates library for Rust. Create, manage, and use X.509 certificates including self-signed and CA-issued. Triggers: "keyvault certificates rust", "CertificateClient rust", "create certificate rust", "self-signed certificate rust", "X.509 rust".
license
MIT
metadata.author
Microsoft
metadata.package
azure_security_keyvault_certificates

Azure Key Vault Certificates library for Rust

Manage X.509 certificates for TLS/SSL, code signing, and authentication.

Use this skill when:

  • An app needs to create or manage X.509 certificates in Key Vault from Rust
  • You need self-signed or CA-issued certificates
  • You need long-running operations (LRO) for certificate issuance
  • You need to sign data using a certificate's key

IMPORTANT: Only use the official azure_security_keyvault_certificates crate published by the azure-sdk crates.io user. Do NOT use unofficial or community crates. Official crates use underscores in names and none have version 0.21.0.

Installation

sh
cargo add azure_security_keyvault_certificates azure_identity tokio futures

If your code uses azure_core types directly, add azure_core to Cargo.toml. If you only use azure_security_keyvault_certificates re-exports, direct azure_core dependency is optional.

Environment Variables

bash
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net/ # Required for all operations

Authentication

Rust Azure SDK code must not use DefaultAzureCredential. The Rust identity crate does not provide that type.

rust
use azure_identity::DeveloperToolsCredential;
use azure_security_keyvault_certificates::CertificateClient;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // Local dev: DeveloperToolsCredential. Production: use ManagedIdentityCredential.
    let credential = DeveloperToolsCredential::new(None)?;
    let client = CertificateClient::new(
        "https://<vault-name>.vault.azure.net/",
        credential.clone(),
        None,
    )?;

    let cert = client
        .get_certificate("cert-name", None)
        .await?
        .into_model()?;
    println!("Certificate: {:?}", cert.id);
    Ok(())
}

Prefer the crate README/examples when checking LRO and poller usage rather than inferring public behavior from generated internal types.

Core Workflow

Create Self-Signed Certificate (LRO)

Creating a certificate is a long-running operation. Poller<T> implements IntoFuture — just .await:

rust
use azure_security_keyvault_certificates::{
    models::{
        CertificatePolicy, CreateCertificateParameters, IssuerParameters,
        X509CertificateProperties,
    },
    ResourceExt,
};

let policy = CertificatePolicy {
    x509_certificate_properties: Some(X509CertificateProperties {
        subject: Some("CN=example.com".into()),
        ..Default::default()
    }),
    issuer_parameters: Some(IssuerParameters {
        name: Some("Self".into()),
        ..Default::default()
    }),
    ..Default::default()
};
let body = CreateCertificateParameters {
    certificate_policy: Some(policy),
    ..Default::default()
};

// Poller implements IntoFuture — await directly for completion
let cert = client
    .begin_create_certificate("cert-name", body.try_into()?, None)?
    .await?
    .into_model()?;

println!(
    "Name: {:?}, Version: {:?}",
    cert.resource_id()?.name,
    cert.resource_id()?.version,
);
Update Certificate Properties
rust
use azure_security_keyvault_certificates::models::UpdateCertificatePropertiesParameters;
use std::collections::HashMap;

#[allow(clippy::needless_update)]
let params = UpdateCertificatePropertiesParameters {
    tags: Some(HashMap::from_iter(vec![("env".into(), "prod".into())])),
    ..Default::default()
};

client
    .update_certificate_properties("cert-name", params.try_into()?, None)
    .await?
    .into_model()?;
Delete Certificate
rust
client.delete_certificate("cert-name", None).await?;
List Certificates (Pagination)

list_certificate_properties returns a Pager<T> — iterate items directly:

rust
use azure_security_keyvault_certificates::ResourceExt;
use futures::TryStreamExt as _;

let mut pager = client.list_certificate_properties(None)?;
while let Some(cert) = pager.try_next().await? {
    println!("Found: {}", cert.resource_id()?.name);
}

Signing with a Certificate's Key

Certificates in Key Vault have an associated key. Use the Key Vault Keys SDK for crypto operations:

rust
use azure_security_keyvault_keys::{
    models::{KeyClientSignOptions, SignParameters, SignatureAlgorithm},
    KeyClient,
};

let key_client = KeyClient::new(
    "https://<vault-name>.vault.azure.net/",
    credential.clone(),
    None,
)?;

// Sign with the certificate's EC key
let digest = vec![0u8; 32]; // SHA-256 digest
let body = SignParameters {
    algorithm: Some(SignatureAlgorithm::Es256),
    value: Some(digest),
};

let result = key_client
    .sign(
        "cert-name",
        body.try_into()?,
        Some(KeyClientSignOptions {
            key_version: Some("<certificate-version>".to_string()),
            ..Default::default()
        }),
    )
    .await?
    .into_model()?;
println!("Signature: {:?}", result.result);

Certificate Formats

FormatContent TypeUse Case
PKCS#12application/x-pkcs12Bundled cert + private key
PEMapplication/x-pem-fileBase64-encoded, common in Linux/web

RBAC Roles

For Entra ID auth, assign one of these roles:

RoleAccess
Key Vault Certificate UserUse certificates
Key Vault Certificates OfficerFull certificate management
Show full SKILL.md (151 more words)Show less

Best Practices

  1. Use cargo add to manage dependencies, never edit Cargo.toml directly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits.
  2. Add azure_core only when importing azure_core types directly. If your code imports azure_core::http::Url, azure_core::http::RequestContent, or azure_core::error::ErrorKind, include azure_core; otherwise a direct dependency is optional.
  3. Use DeveloperToolsCredential for local dev, ManagedIdentityCredential for production — Rust does not provide a single DefaultAzureCredential type
  4. Never hardcode credentials — use environment variables or managed identity
  5. Use ..Default::default() with #[allow(clippy::needless_update)] for model struct updates
  6. Use ResourceExt to extract certificate name/version from IDs
  7. LROs — begin_create_certificate returns a Poller; just .await for completion (clients should rarely poll for status)
  8. Reuse clients — CertificateClient is thread-safe; create once, share across tasks
  9. Run cargo clippy -- -D warnings when the prompt, eval, or CI expects lint-clean output

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/plugins/azure-sdk-rust/skills/azure-keyvault-certificates-rust of microsoft/skills.

Open the folder on GitHubat commit 3898ec8

Compare with similar skills

Azure Keyvault Certificates Rust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Keyvault Certificates Rust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Keyvault Certificates Rust this skillmicrosoft/skills3.1k—~2kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Azure Servicebus Rustsickn33/agentic-awesome-skills47k1 repos~2kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Azure Keyvault Certificates Rustaiskillstore/marketplace4304 repos~1.2kAutomated safety check: PassNone
Azure Keyvault Keys Rustaiskillstore/marketplace4304 repos~1.1kAutomated safety check: PassNone

Similar skills

  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    190 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Azure Servicebus Rust

    sickn33/agentic-awesome-skills

    Azure Service Bus library for Rust. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Azure Keyvault Certificates Rust

    aiskillstore/marketplace

    Azure Key Vault Certificates SDK for Rust. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Azure Keyvault Keys Rust

    aiskillstore/marketplace

    Azure Key Vault Keys SDK for Rust. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.1k tokens
    SecurityAuto-check passed
  • Azure Keyvault Secrets Rust

    aiskillstore/marketplace

    Azure Key Vault Secrets SDK for Rust. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~993 tokens
    Backend & APIsAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Questions about Azure Keyvault Certificates Rust

What does Azure Keyvault Certificates Rust do?

Azure Key Vault Certificates library for Rust. An agent skill from microsoft/skills. Azure Keyvault Certificates Rust is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault Certificates library for Rust.

When should I use Azure Keyvault Certificates Rust?

Azure Keyvault Certificates Rust fits situations like: backend & APIs work in your project.

How do I install Azure Keyvault Certificates Rust in Claude Code?

Run `npx skills add microsoft/skills --skill azure-keyvault-certificates-rust -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-rust/skills/azure-keyvault-certificates-rust in microsoft/skills) into .claude/skills/azure-keyvault-certificates-rust in your project. Claude Code loads it when a task matches its description.

How do I install Azure Keyvault Certificates Rust in Codex?

Run `npx skills add microsoft/skills --skill azure-keyvault-certificates-rust -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-rust/skills/azure-keyvault-certificates-rust in microsoft/skills) into .agents/skills/azure-keyvault-certificates-rust in your project. Codex loads it when a task matches its description.

Can I use Azure Keyvault Certificates Rust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-keyvault-certificates-rust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-keyvault-certificates-rust, .gemini/skills/azure-keyvault-certificates-rust, .github/skills/azure-keyvault-certificates-rust and .opencode/skills/azure-keyvault-certificates-rust in your project.

What does Azure Keyvault Certificates Rust need to run?

Going by SKILL.md and its folder, Azure Keyvault Certificates Rust needs the command-line tools its instructions call (cargo).

Does Azure Keyvault Certificates Rust access the network?

SKILL.md names 3 domains. As links in the text: crates.io, docs.rs and github.com. This is read from the text; nothing was executed.

Is Azure Keyvault Certificates Rust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Keyvault Certificates Rust use?

Azure Keyvault Certificates Rust is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Keyvault Certificates Rust use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Keyvault Certificates Rust?

Skills that share tags, products or a category with Azure Keyvault Certificates Rust: Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Azure Servicebus Rust (sickn33/agentic-awesome-skills, 47k stars), Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Azure Keyvault Certificates Rust (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Keyvault Certificates Rust?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.