Microsoft Entra ID (formerly Azure AD) Applications.federated Identity Credential API
The applications.federatedIdentityCredential API from Microsoft Entra ID (formerly Azure AD) — 4 operation(s) for applications.federatedidentitycredential.
The applications.federatedIdentityCredential API from Microsoft Entra ID (formerly Azure AD) — 4 operation(s) for applications.federatedidentitycredential.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/azure-ad-applications-federatedidentitycredential-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Applications.federated Identity Credential API
version: v1.0
servers:
- url: https://graph.microsoft.com/v1.0/
description: Core
security:
- azureaadv2: []
tags:
- name: applications.federatedIdentityCredential
paths:
/applications/{application-id}/federatedIdentityCredentials:
get:
tags:
- applications.federatedIdentityCredential
summary: List federatedIdentityCredential objects
description: Get a list of the federatedIdentityCredential objects and their properties assigned to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-list?view=graph-rest-1.0
operationId: application_ListFederatedIdentityCredential
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- $ref: '#/components/parameters/top'
- $ref: '#/components/parameters/skip'
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
- $ref: '#/components/parameters/count'
- name: $orderby
in: query
description: Order items by property values
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
$ref: '#/components/responses/microsoft.graph.federatedIdentityCredentialCollectionResponse'
default:
$ref: '#/components/responses/error'
x-ms-pageable:
nextLinkName: '@odata.nextLink'
operationName: listMore
x-ms-docs-operation-type: operation
post:
tags:
- applications.federatedIdentityCredential
summary: Create federatedIdentityCredential
description: Create a new federatedIdentityCredential object for an application. By configuring a trust relationship between your Microsoft Entra application registration and the identity provider for your compute platform, you can use tokens issued by that platform to authenticate with Microsoft identity platform and call APIs in the Microsoft ecosystem. Maximum of 20 objects can be added to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-post?view=graph-rest-1.0
operationId: application_CreateFederatedIdentityCredential
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
requestBody:
description: New navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
required: true
responses:
2XX:
description: Created navigation property.
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/applications/{application-id}/federatedIdentityCredentials/{federatedIdentityCredential-id}:
get:
tags:
- applications.federatedIdentityCredential
summary: Get federatedIdentityCredential
description: Read the properties and relationships of a federatedIdentityCredential object assigned to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-get?view=graph-rest-1.0
operationId: application_GetFederatedIdentityCredential
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: federatedIdentityCredential-id
in: path
description: The unique identifier of federatedIdentityCredential
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: federatedIdentityCredential
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- applications.federatedIdentityCredential
summary: Upsert federatedIdentityCredential
description: Create a new federatedIdentityCredential object for an application if it doesn't exist, or update the properties of an existing federatedIdentityCredential object. By configuring a trust relationship between your Microsoft Entra application registration and the identity provider for your compute platform, you can use tokens issued by that platform to authenticate with Microsoft identity platform and call APIs in the Microsoft ecosystem. Maximum of 20 objects can be added to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-upsert?view=graph-rest-1.0
operationId: application_UpdateFederatedIdentityCredential
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: federatedIdentityCredential-id
in: path
description: The unique identifier of federatedIdentityCredential
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: federatedIdentityCredential
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- applications.federatedIdentityCredential
summary: Delete federatedIdentityCredential
description: Delete a federatedIdentityCredential object from an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-delete?view=graph-rest-1.0
operationId: application_DeleteFederatedIdentityCredential
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: federatedIdentityCredential-id
in: path
description: The unique identifier of federatedIdentityCredential
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: federatedIdentityCredential
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/applications/{application-id}/federatedIdentityCredentials(name='{name}'):
get:
tags:
- applications.federatedIdentityCredential
summary: Get federatedIdentityCredential
description: Read the properties and relationships of a federatedIdentityCredential object assigned to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-get?view=graph-rest-1.0
operationId: application.federatedIdentityCredential_GetGraphBPreName
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: name
in: path
description: Alternate key of federatedIdentityCredential
required: true
style: simple
schema:
type: string
- name: $select
in: query
description: Select properties to be returned
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
- name: $expand
in: query
description: Expand related entities
style: form
explode: false
schema:
uniqueItems: true
type: array
items:
type: string
responses:
2XX:
description: Retrieved navigation property
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
patch:
tags:
- applications.federatedIdentityCredential
summary: Upsert federatedIdentityCredential
description: Create a new federatedIdentityCredential object for an application if it doesn't exist, or update the properties of an existing federatedIdentityCredential object. By configuring a trust relationship between your Microsoft Entra application registration and the identity provider for your compute platform, you can use tokens issued by that platform to authenticate with Microsoft identity platform and call APIs in the Microsoft ecosystem. Maximum of 20 objects can be added to an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-upsert?view=graph-rest-1.0
operationId: application.federatedIdentityCredential_UpdateGraphBPreName
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: name
in: path
description: Alternate key of federatedIdentityCredential
required: true
style: simple
schema:
type: string
requestBody:
description: New navigation property values
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
required: true
responses:
2XX:
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
delete:
tags:
- applications.federatedIdentityCredential
summary: Delete federatedIdentityCredential
description: Delete a federatedIdentityCredential object from an application.
externalDocs:
description: Find more info here
url: https://learn.microsoft.com/graph/api/federatedidentitycredential-delete?view=graph-rest-1.0
operationId: application.federatedIdentityCredential_DeleteGraphBPreName
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- name: name
in: path
description: Alternate key of federatedIdentityCredential
required: true
style: simple
schema:
type: string
- name: If-Match
in: header
description: ETag
style: simple
schema:
type: string
responses:
2XX:
description: Success
default:
$ref: '#/components/responses/error'
x-ms-docs-operation-type: operation
/applications/{application-id}/federatedIdentityCredentials/$count:
get:
tags:
- applications.federatedIdentityCredential
summary: Get the number of the resource
operationId: application.federatedIdentityCredential_GetCount
parameters:
- name: application-id
in: path
description: The unique identifier of application
required: true
style: simple
schema:
type: string
x-ms-docs-key-type: application
- $ref: '#/components/parameters/search'
- $ref: '#/components/parameters/filter'
responses:
2XX:
$ref: '#/components/responses/ODataCountResponse'
default:
$ref: '#/components/responses/error'
components:
responses:
error:
description: error
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ODataError'
microsoft.graph.federatedIdentityCredentialCollectionResponse:
description: Retrieved collection
content:
application/json:
schema:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredentialCollectionResponse'
ODataCountResponse:
description: The count of the resource
content:
text/plain:
schema:
$ref: '#/components/schemas/ODataCountResponse'
schemas:
microsoft.graph.ODataErrors.MainError:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
x-ms-primary-error-message: true
target:
type:
- string
- 'null'
details:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.ErrorDetails'
innerError:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.InnerError'
additionalProperties:
type: object
ODataCountResponse:
type: integer
format: int32
microsoft.graph.ODataErrors.ODataError:
required:
- error
type: object
properties:
error:
$ref: '#/components/schemas/microsoft.graph.ODataErrors.MainError'
additionalProperties:
type: object
microsoft.graph.entity:
title: entity
type: object
properties:
id:
type: string
description: The unique identifier for an entity. Read-only.
additionalProperties:
type: object
microsoft.graph.federatedIdentityCredentialCollectionResponse:
title: Collection of federatedIdentityCredential
type: object
properties:
value:
type: array
items:
$ref: '#/components/schemas/microsoft.graph.federatedIdentityCredential'
'@odata.nextLink':
type:
- string
- 'null'
additionalProperties:
type: object
microsoft.graph.ODataErrors.InnerError:
type: object
additionalProperties:
type: object
description: The structure of this object is service-specific
microsoft.graph.federatedIdentityCredential:
allOf:
- $ref: '#/components/schemas/microsoft.graph.entity'
- title: federatedIdentityCredential
type: object
properties:
audiences:
type: array
items:
type: string
description: The audience that can appear in the external token. This field is mandatory and should be set to api://AzureADTokenExchange for Microsoft Entra ID. It says what Microsoft identity platform should accept in the aud claim in the incoming token. This value represents Microsoft Entra ID in your external identity provider and has no fixed value across identity providers - you might need to create a new application registration in your identity provider to serve as the audience of this token. This field can only accept a single value and has a limit of 600 characters. Required.
description:
type:
- string
- 'null'
description: The unvalidated description of the federated identity credential, provided by the user. It has a limit of 600 characters. Optional.
issuer:
type: string
description: The URL of the external identity provider, which must match the issuer claim of the external token being exchanged. The combination of the values of issuer and subject must be unique within the app. It has a limit of 600 characters. Required.
name:
type: string
description: The unique identifier for the federated identity credential, which has a limit of 120 characters and must be URL friendly. The string is immutable after it's created. Alternate key. Required. Not nullable. Supports $filter (eq).
subject:
type:
- string
- 'null'
description: Required. The identifier of the external software workload within the external identity provider. Like the audience value, it has no fixed format; each identity provider uses their own - sometimes a GUID, sometimes a colon delimited identifier, sometimes arbitrary strings. The value here must match the sub claim within the token presented to Microsoft Entra ID. The combination of issuer and subject must be unique within the app. It has a limit of 600 characters. Supports $filter (eq).
additionalProperties:
type: object
microsoft.graph.ODataErrors.ErrorDetails:
required:
- code
- message
type: object
properties:
code:
type: string
message:
type: string
target:
type:
- string
- 'null'
additionalProperties:
type: object
parameters:
count:
name: $count
in: query
description: Include count of items
style: form
explode: false
schema:
type: boolean
filter:
name: $filter
in: query
description: Filter items by property values
style: form
explode: false
schema:
type: string
search:
name: $search
in: query
description: Search items by search phrases
style: form
explode: false
schema:
type: string
top:
name: $top
in: query
description: Show only the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
example: 50
skip:
name: $skip
in: query
description: Skip the first n items
style: form
explode: false
schema:
minimum: 0
type: integer
securitySchemes:
azureaadv2:
type: oauth2
flows:
authorizationCode:
authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
scopes: {}