Azure Cost Management · Authentication Profile
Microsoft Azure Cost Management Authentication
Authentication
Azure Cost Management secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit flow(s).
Cost ManagementFinOpsCloud CostBillingBudgetsExportCost AnalysisForecastingChargebacksFocusAzureReservations
Methods: oauth2
Schemes: 1
OAuth flows: implicit
API key in:
Security Schemes
azure_auth oauth2
· flows: implicit
Source
Authentication Profile
generated: '2026-09-17'
method: searched
source: openapi/microsoft-azure-cost-management-alerts-api-openapi.yml, openapi/microsoft-azure-cost-management-budgets-api-openapi.yml,
openapi/microsoft-azure-cost-management-costallocationruledefinitions-api-openapi.yml, openapi/microsoft-azure-cost-management-exports-api-openapi.yml,
openapi/microsoft-azure-cost-management-generatecostdetailsreport-api-openapi.yml, openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationresults-api-openapi.yml,
openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationstatus-api-openapi.yml,
openapi/microsoft-azure-cost-management-markuprules-api-openapi.yml, openapi/microsoft-azure-cost-management-operations-api-openapi.yml,
openapi/microsoft-azure-cost-management-providers-api-openapi.yml, openapi/microsoft-azure-cost-management-scheduledactionoperationgroup-api-openapi.yml,
openapi/microsoft-azure-cost-management-scheduledactions-api-openapi.yml ...
summary:
types:
- oauth2
oauth2_flows:
- implicit
schemes:
- name: azure_auth
type: oauth2
flows:
- flow: implicit
authorizationUrl: https://login.microsoftonline.com/common/oauth2/authorize
scopes: 1
description: Azure Active Directory OAuth2 Flow.
sources:
- openapi/microsoft-azure-cost-management-alerts-api-openapi.yml
- openapi/microsoft-azure-cost-management-budgets-api-openapi.yml
- openapi/microsoft-azure-cost-management-costallocationruledefinitions-api-openapi.yml
- openapi/microsoft-azure-cost-management-exports-api-openapi.yml
- openapi/microsoft-azure-cost-management-generatecostdetailsreport-api-openapi.yml
- openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationresults-api-openapi.yml
- openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationstatus-api-openapi.yml
- openapi/microsoft-azure-cost-management-markuprules-api-openapi.yml
- openapi/microsoft-azure-cost-management-operations-api-openapi.yml
- openapi/microsoft-azure-cost-management-providers-api-openapi.yml
- openapi/microsoft-azure-cost-management-scheduledactionoperationgroup-api-openapi.yml
- openapi/microsoft-azure-cost-management-scheduledactions-api-openapi.yml
- openapi/microsoft-azure-cost-management-settings-api-openapi.yml
- openapi/microsoft-azure-cost-management-viewoperationgroup-api-openapi.yml
- openapi/microsoft-azure-cost-management-views-api-openapi.yml
docs:
- https://learn.microsoft.com/en-us/rest/api/azure/
- https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow
- https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/assign-access-acm-data
- https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/management-and-governance
discovery: https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
discovery_artifact: well-known/microsoft-azure-cost-management-openid-configuration.json
provider: Microsoft Entra ID
resource: https://management.azure.com
token_header: 'Authorization: Bearer <token>'
docs_note: >-
The contract declares one securityScheme, azure_auth, with the implicit flow and the single
delegated scope user_impersonation. That is the Azure Resource Manager boilerplate every ARM
swagger carries; it is not how a service principal or an agent actually authenticates. Microsoft
Entra ID also issues client-credentials tokens for the resource https://management.azure.com
(scope https://management.azure.com/.default), which is the unattended path, and
authorization-code tokens for delegated user access. The OpenID Provider metadata was fetched
and saved; the implicit flow the swagger names is not the only option and should not be read as
a constraint.
authorization_model:
style: azure-rbac
note: >-
Cost Management does not authorize by OAuth scope. Once a token is accepted, what it can see
and change is decided by Azure RBAC role assignments at the {scope} in the request path.
roles:
- name: Cost Management Reader
grants: read cost data, budgets, views, alerts and exports at the assigned scope
- name: Cost Management Contributor
grants: read plus create, update and delete budgets, exports, views and scheduled actions
source: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/management-and-governance
scope_paths:
note: >-
Billing-account and billing-profile scopes use billing-account roles (Enterprise Agreement
enrollment roles, or Microsoft Customer Agreement billing roles) rather than Azure RBAC.
source: https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/understand-work-scopes
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/microsoft-azure-cost-management-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.