Skip to content

API Reference

croesus-agent edited this page Jul 6, 2026 · 2 revisions

API reference — Croesus mock SaaS OBO API

The Croesus middle-tier API is an ASP.NET Core (.NET 8) confidential client that demonstrates the Microsoft Entra On-Behalf-Of (OBO) flow. It exposes an interactive Swagger UI and an OpenAPI document so the surface is visible and testable.

Live endpoints

Live Swagger UI

The deployed API serves an interactive Swagger UI exposing the /api/me (OBO good path) and gated /api/replay operations:

Croesus Swagger UI showing the OBO API with /api/me and /api/replay operations

Operations

Method Path Purpose Auth
GET /api/me Correct OBO good path. Validates the inbound API-audienced token, performs the On-Behalf-Of exchange for a distinct Microsoft Graph token, calls Graph /me, and returns claims-only evidence for both legs. Bearer, scope access_as_user
POST /api/replay Gated Tier 2 token-replay anti-pattern. Re-presents a client-forwarded Graph token server-side to a fixed Graph target and returns claims-only evidence. Present only when Demo:EnableReplay is true; otherwise the route is absent (404). Bearer, scope access_as_user

Authentication

All operations require an API-audienced bearer token carrying the access_as_user scope (api://<api-client-id>/access_as_user). The Swagger UI is wired with an OAuth2 authorization-code + PKCE flow against the tenant, so the Authorize button acquires a real user token and the OBO good path can be exercised directly from the UI.

Wrong versus right

  • Wrong (replay): the same user token is re-sent to Microsoft Graph. Graph rejects a token whose audience is not Graph with HTTP 401, and a replayed token cannot satisfy device-bound token protection.
  • Right (OBO): the middle tier authenticates its own confidential-client certificate and mints a distinct Graph token with a fresh audience, jti, and iat. The two tokens carry different audiences — the behavioral signature of a real OBO rather than token replay.

Source

Clone this wiki locally