Azure Active Directory OIDC Node.js Web Sample
This sample demonstrates how to set up OpenId Connect authentication in a web application built using Node.js with Express. The sample is designed to run on any platform.
To run this sample you will need the following:
Install Node.js from http://nodejs.org/
Register the sample
- Copy down the Application Id assigned to your app, you'll need it soon.
- Add the Web platform for your app.
- Enter the correct Redirect URI. The redirect uri indicates to Azure AD where authentication responses should be directed - the default for this sample is
- Add a new Application secret by clicking the Generate new password button. This value will not be displayed again, so save the result in a temporary location as you'll need it in the next step.
Download the sample application and modules
Next, clone the sample repo and install the NPM modules.
From your shell or command line:
$ git clone email@example.com:AzureADQuickStarts/AppModelv2-WebApp-OpenIDConnect-nodejs.git
$ git clone https://github.com/AzureADQuickStarts/AppModelv2-WebApp-OpenIDConnect-nodejs.git
From the project root directory, run the command:
$ npm install
Configure the application
Provide the parameters in
exports.creds in config.js as instructed.
exports.identityMetadatawith the Azure AD tenant name of the format *.onmicrosoft.com.
exports.clientIDwith the Application Id noted from app registration.
exports.clientSecretwith the Application secret noted from app registration.
exports.redirectUrlwith the Redirect URI noted from app registration.
Optional configuration for production apps:
exports.destroySessionUrlin config.js, if you want to use a different
exports.useMongoDBSessionStorein config.js to true, if you want to use use mongoDB or other compatible session stores. The default session store in this sample is
express-session. Note that the default session store is not suitable for production.
exports.databaseUri, if you want to use mongoDB session store and a different database URI.
exports.mongoDBSessionMaxAge. Here you can specify how long you want to keep a session in mongoDB. The unit is second(s).
Build and run the application
Start mongoDB service. If you are using mongoDB session store in this app, you have to install mongoDB and start the service first. If you are using the default session store, you can skip this step.
Run the app using the following command from your command line.
$ node app.js
Is the server output hard to understand?: We use
bunyan for logging in this sample. The console won't make much sense to you unless you also install bunyan and run the server like above but pipe it through the bunyan binary:
$ npm install -g bunyan $ node app.js | bunyan
You will have a server successfully running on
Community Help and Support
We use Stack Overflow with the community to provide support. We highly recommend you ask your questions on Stack Overflow first and browse existing issues to see if someone has asked your question before. Make sure that your questions or comments are tagged with [azure-active-directory].
If you find a bug or issue with this sample, please raise the issue on GitHub Issues.
For issues with the passport-azure-ad library, please raise the issue on the library GitHub repo.
If you'd like to contribute to this sample, please follow the GitHub Fork and Pull request model.
This library controls how users sign-in and access services. We recommend you always take the latest version of our library in your app when possible.
If you find a security issue with our libraries or services please report it to firstname.lastname@example.org with as much detail as possible. Your submission may be eligible for a bounty through the Microsoft Bounty program. Please do not post security issues to GitHub Issues or any other public site. We will contact you shortly upon receiving the information. We encourage you to get notifications of when security incidents occur by visiting this page and subscribing to Security Advisory Alerts.
Copyright (c) Microsoft Corporation. All rights reserved. Licensed under the MIT License (the "License");
We would like to acknowledge the folks who own/contribute to the following projects for their support of Azure Active Directory and their libraries that were used to build this sample. In places where we forked these libraries to add additional functionality, we ensured that the chain of forking remains intact so you can navigate back to the original package. Working with such great partners in the open source community clearly illustrates what open collaboration can accomplish. Thank you!