Client Credential Flow based Authentication in APIM needs a claim based token

Vikas Kumar 0 Reputation points
2026-09-22T05:41:03.9933333+00:00

Hi Community,

An API created in APIM that is based on B2B auth flow (Client Credential Flow). Client calls the API using the token received from Microsoft Token Endpoint using client credential flow (ClientID, secret, scope and grant type).

I have many App registrations and APIM senses the Organisation based on the Appid called the APIM's API. I have a map created in Named Values which is a map of all valid ClientID (App IDs). Through that it senses who called API and accordingly brings the data.

But for a cleaner approach I want to dispose off the Map and want to directly bring the OrganisationCode from the token itself. The token could have claim as App ID. APIM can read that claim and then there is no need to maintain a map of Appids (client Ids).

I researched a lot and get to know that Client Credential flow-based token can't have that claim as it is not associated with a user. It can have application related claims. But I am unable to inject any claims. Any idea?

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

1 answer

Sort by: Newest
  1. Taz 10,126 Reputation points MVP Volunteer Moderator
    2026-09-22T08:27:56.12+00:00

    Hi Vikas,

    Yes, you can do this with Microsoft Entra ID. A client-credentials token does not require a user, but it can contain application claims.

    For your scenario, I would use an App Role on the API. Assign a role such as Org-ABC or OrganizationCode to each calling application. With client credentials, the assigned app roles are included in the access token in the roles claim.

    APIM can then read that claim directly:

    <set-variable name="orgCode"
        value="@(((Jwt)context.Variables["jwt"]).Claims["roles"][0])" />
    

    You can also use Entra claims mapping/custom claims if you specifically need a custom claim such as organizationCode; Microsoft supports adding custom claims to access tokens using claims mapping policies.

    For a simple organisation-to-application mapping, App Roles are usually easier to manage than maintaining an APIM Named Value map. APIM can validate and consume the claim after validating the Entra token.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.