Skip to content
Emmanuel Knafo edited this page Oct 1, 2026 · 6 revisions

Croesus — On-Behalf-Of flow demo

Croesus is a mock SaaS demo of the Microsoft Entra On-Behalf-Of (OBO) flow. A public-client SPA acquires a token for a middle-tier API; the API exchanges that token for a distinct Microsoft Graph token by authenticating its own confidential-client credential. The SPA never holds a Graph token, and the two tokens carry different audiences — the behavioral signature of a real OBO rather than token replay.

Backend-for-Frontend (BFF) demo

Evidence pages

  • Live application evidence — screenshots of the deployed SPA, the Entra sign-in, and the API enforcing bearer authentication.
  • Pipeline execution evidence — the latest green CI run, job and step results, and how the MFA constraint is handled.
  • Token Protection 1008 evidence — captured sign-in logs showing the bound (0) versus unbound (1008) Token Protection signature reproduced on the Croesus app, with the KQL to reproduce.
  • Live demo state — durable record of the live demo objects (replay gate, Conditional Access policy, SPA to Graph grant) with identifiers, screenshots, and reversible teardown commands.

API reference

  • API reference — live Swagger UI, the OpenAPI document, the /api/me (OBO good path) and gated /api/replay operations, and the wrong-versus-right framing.

Source

Clone this wiki locally