MCP Server with Azure Entra ID Authentication and OBO flow for Microsoft Search
Wellknown found it in public sources; nobody has proven control of it yet. Claiming takes one click if the repository is under your GitHub account, or a small file on your domain otherwise. Verified owners get the badge, 15-minute checks, status alerts, edits that outrank crawled data, and a ranking boost.
Agents can do it too: POST https://wellknown.network/api/v1/claims with {"agent":"iflow-mcp-gbaeke-mcp-obo","method":"well_known_file"} — machine-readable steps at claim.json, guide at /docs/claim.
Everything here was measured by our prober or read from a registry. Nothing is self-reported.
Attributed to the source that supplied each field. Treated as claims, not facts.
# On-behalf-of flow with Entra ID and FastMCP Blog post: https://baeke.info/2025/07/29/end-to-end-authorization-with-entra-id-and-mcp/ ## Instructions ### 1. Create and activate a Python virtual environment ```bash python3 -m venv .venv source .venv/bin/activate ``` ### 2. Install dependencies ```bash pip install -r requirements.txt ``` ### 3. Set up environment variables Create a `.env` file in the project root with the required Azure and API credentials (see example files for required variables). ### 4. Start the MCP server ```bash python -m mcp.main ``` ### 5. Run the MCP client In a new terminal (with the virtual environment activated): ```bash python mcp_client.py ``` ## Diagrams ```mermaid sequenceDiagram autonumber participant User participant Client participant AzureAD as "Azure Entra ID" participant MCP participant MSGraph User->>Client: Initiate Device Flow Client->>AzureAD: Start Device Code Flow AzureAD-->>Client: Device Code + Verification URL Client->>User: Show Code + URL User->>AzureAD: Authenticates via browser AzureAD-->>Client: Returns Access Token (for MCP) Client->>MCP: Call tool with Bearer Access Token MCP->>AzureAD: OBO request for token to call MS Graph\n(include access token as assertion) AzureAD-->>MCP: Returns new Access Token (for MS Graph) MCP->>MSGraph: Call Graph API with new token MSGraph-->>MCP: Graph data MCP-->>Client: Return tool result ```
Mapped onto the structured taxonomy from declared text and observed tool names. Confidence shown for derived entries.
Every source is kept verbatim. Field changes are logged as events.