Authentication

Use import { auth } from "@backifydev/sdk" for application identity. In the application's Authentication page, choose Connect Microsoft and enable. Backify signs in to the selected organization, creates a single-tenant Entra web app registration with the correct callback URL, generates its client secret, and stores the secret encrypted. The signed-in administrator must approve Backify's Microsoft Graph Application.ReadWrite.All delegated permission and have a role allowed to create app registrations and credentials. If automatic setup is unavailable, enter an existing Entra registration manually and add the displayed callback URL as a Web redirect URI.

import { auth } from "@backifydev/sdk";

const user = await auth.currentUser();
if (!user) await auth.signIn(); // redirects to Microsoft Entra
// Later:
await auth.signOut();
const requiredUser = await auth.requireUser();

Backify handles the authorization code exchange and ID token validation. The Entra client secret remains encrypted in Backify. Application sessions use a protected, HttpOnly cookie scoped to the application's Backify host. The portal's application user list records an account after the first successful sign-in and tracks its latest sign-in time.

Application user records are scoped to an application and identified by the Entra tenant ID and object ID. The user's email is optional; an application can reject accounts when Entra does not return an email address.