Skip to content

API Reference

Croesus Demo edited this page Jul 6, 2026 · 2 revisions

API reference — Croesus mock SaaS OBO API

The Croesus middle-tier API is an ASP.NET Core (.NET 8) confidential client that demonstrates the Microsoft Entra On-Behalf-Of (OBO) flow. It exposes an interactive Swagger UI and an OpenAPI document so the surface is visible and testable.

Live endpoints

Operations

Method Path Purpose Auth
GET /api/me Correct OBO good path. Validates the inbound API-audienced token, performs the On-Behalf-Of exchange for a distinct Microsoft Graph token, calls Graph /me, and returns claims-only evidence for both legs. Bearer, scope access_as_user
POST /api/replay Gated Tier 2 token-replay anti-pattern. Re-presents a client-forwarded Graph token server-side to a fixed Graph target and returns claims-only evidence. Present only when Demo:EnableReplay is true; otherwise the route is absent (404). Bearer, scope access_as_user

Authentication

All operations require an API-audienced bearer token carrying the access_as_user scope (api://<api-client-id>/access_as_user). The Swagger UI is wired with an OAuth2 authorization-code + PKCE flow against the tenant, so the Authorize button acquires a real user token and the OBO good path can be exercised directly from the UI.

Wrong versus right

  • Wrong (replay): the same user token is re-sent to Microsoft Graph. Graph rejects a token whose audience is not Graph with HTTP 401, and a replayed token cannot satisfy device-bound token protection.
  • Right (OBO): the middle tier authenticates its own confidential-client certificate and mints a distinct Graph token with a fresh audience, jti, and iat. The two tokens carry different audiences — the behavioral signature of a real OBO rather than token replay.

Source

Clone this wiki locally