Azure Cost Management · Authentication Profile

Microsoft Azure Cost Management Authentication

Authentication

Azure Cost Management secures its APIs with oauth2 across 1 declared security scheme, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit flow(s).

Cost ManagementFinOpsCloud CostBillingBudgetsExportCost AnalysisForecastingChargebacksFocusAzureReservations
Methods: oauth2 Schemes: 1 OAuth flows: implicit API key in:

Security Schemes

azure_auth oauth2
· flows: implicit

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: openapi/microsoft-azure-cost-management-alerts-api-openapi.yml, openapi/microsoft-azure-cost-management-budgets-api-openapi.yml,
  openapi/microsoft-azure-cost-management-costallocationruledefinitions-api-openapi.yml, openapi/microsoft-azure-cost-management-exports-api-openapi.yml,
  openapi/microsoft-azure-cost-management-generatecostdetailsreport-api-openapi.yml, openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationresults-api-openapi.yml,
  openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationstatus-api-openapi.yml,
  openapi/microsoft-azure-cost-management-markuprules-api-openapi.yml, openapi/microsoft-azure-cost-management-operations-api-openapi.yml,
  openapi/microsoft-azure-cost-management-providers-api-openapi.yml, openapi/microsoft-azure-cost-management-scheduledactionoperationgroup-api-openapi.yml,
  openapi/microsoft-azure-cost-management-scheduledactions-api-openapi.yml ...
summary:
  types:
  - oauth2
  oauth2_flows:
  - implicit
schemes:
- name: azure_auth
  type: oauth2
  flows:
  - flow: implicit
    authorizationUrl: https://login.microsoftonline.com/common/oauth2/authorize
    scopes: 1
  description: Azure Active Directory OAuth2 Flow.
  sources:
  - openapi/microsoft-azure-cost-management-alerts-api-openapi.yml
  - openapi/microsoft-azure-cost-management-budgets-api-openapi.yml
  - openapi/microsoft-azure-cost-management-costallocationruledefinitions-api-openapi.yml
  - openapi/microsoft-azure-cost-management-exports-api-openapi.yml
  - openapi/microsoft-azure-cost-management-generatecostdetailsreport-api-openapi.yml
  - openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationresults-api-openapi.yml
  - openapi/microsoft-azure-cost-management-generatedetailedcostreportoperationstatus-api-openapi.yml
  - openapi/microsoft-azure-cost-management-markuprules-api-openapi.yml
  - openapi/microsoft-azure-cost-management-operations-api-openapi.yml
  - openapi/microsoft-azure-cost-management-providers-api-openapi.yml
  - openapi/microsoft-azure-cost-management-scheduledactionoperationgroup-api-openapi.yml
  - openapi/microsoft-azure-cost-management-scheduledactions-api-openapi.yml
  - openapi/microsoft-azure-cost-management-settings-api-openapi.yml
  - openapi/microsoft-azure-cost-management-viewoperationgroup-api-openapi.yml
  - openapi/microsoft-azure-cost-management-views-api-openapi.yml
docs:
- https://learn.microsoft.com/en-us/rest/api/azure/
- https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-client-creds-grant-flow
- https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/assign-access-acm-data
- https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/management-and-governance
discovery: https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
discovery_artifact: well-known/microsoft-azure-cost-management-openid-configuration.json
provider: Microsoft Entra ID
resource: https://management.azure.com
token_header: 'Authorization: Bearer <token>'
docs_note: >-
  The contract declares one securityScheme, azure_auth, with the implicit flow and the single
  delegated scope user_impersonation. That is the Azure Resource Manager boilerplate every ARM
  swagger carries; it is not how a service principal or an agent actually authenticates. Microsoft
  Entra ID also issues client-credentials tokens for the resource https://management.azure.com
  (scope https://management.azure.com/.default), which is the unattended path, and
  authorization-code tokens for delegated user access. The OpenID Provider metadata was fetched
  and saved; the implicit flow the swagger names is not the only option and should not be read as
  a constraint.
authorization_model:
  style: azure-rbac
  note: >-
    Cost Management does not authorize by OAuth scope. Once a token is accepted, what it can see
    and change is decided by Azure RBAC role assignments at the {scope} in the request path.
  roles:
  - name: Cost Management Reader
    grants: read cost data, budgets, views, alerts and exports at the assigned scope
  - name: Cost Management Contributor
    grants: read plus create, update and delete budgets, exports, views and scheduled actions
  source: https://learn.microsoft.com/en-us/azure/role-based-access-control/built-in-roles/management-and-governance
scope_paths:
  note: >-
    Billing-account and billing-profile scopes use billing-account roles (Enterprise Agreement
    enrollment roles, or Microsoft Customer Agreement billing roles) rather than Azure RBAC.
  source: https://learn.microsoft.com/en-us/azure/cost-management-billing/costs/understand-work-scopes

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/microsoft-azure-cost-management-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.