-
Notifications
You must be signed in to change notification settings - Fork 0
API Reference
Croesus Demo edited this page Jul 6, 2026
·
2 revisions
The Croesus middle-tier API is an ASP.NET Core (.NET 8) confidential client that demonstrates the Microsoft Entra On-Behalf-Of (OBO) flow. It exposes an interactive Swagger UI and an OpenAPI document so the surface is visible and testable.
- Swagger UI: https://croesus-api.azurewebsites.net/swagger
- OpenAPI document: https://croesus-api.azurewebsites.net/swagger/v1/swagger.json
- SPA (front end): https://croesus-spa.azurewebsites.net
| Method | Path | Purpose | Auth |
|---|---|---|---|
| GET | /api/me | Correct OBO good path. Validates the inbound API-audienced token, performs the On-Behalf-Of exchange for a distinct Microsoft Graph token, calls Graph /me, and returns claims-only evidence for both legs. |
Bearer, scope access_as_user
|
| POST | /api/replay | Gated Tier 2 token-replay anti-pattern. Re-presents a client-forwarded Graph token server-side to a fixed Graph target and returns claims-only evidence. Present only when Demo:EnableReplay is true; otherwise the route is absent (404). |
Bearer, scope access_as_user
|
All operations require an API-audienced bearer token carrying the access_as_user scope (api://<api-client-id>/access_as_user). The Swagger UI is wired with an OAuth2 authorization-code + PKCE flow against the tenant, so the Authorize button acquires a real user token and the OBO good path can be exercised directly from the UI.
- Wrong (replay): the same user token is re-sent to Microsoft Graph. Graph rejects a token whose audience is not Graph with HTTP 401, and a replayed token cannot satisfy device-bound token protection.
- Right (OBO): the middle tier authenticates its own confidential-client certificate and mints a distinct Graph token with a fresh audience,
jti, andiat. The two tokens carry different audiences — the behavioral signature of a real OBO rather than token replay.
- Repository: https://github.com/devopsabcs-engineering/croesus
- API source: api/
- Demo guide: docs/obo-demo-guide.md