Set Up OAuth for Microsoft Entra IDBeta
Register Microsoft Entra ID as an OAuth provider so users can authorize Microsoft services from Haystack Enterprise Platform and use them in their pipelines.
About This Task
The Microsoft Entra ID template uses the OAuth 2.0 authorization code flow against your tenant. The template pre-fills authorization and token URLs with a {tenant_id} placeholder. Replace it with your Azure AD tenant ID (GUID) or verified domain before you save.
Prerequisites
Before you start, review Configure External Connections.
You need permission to register applications in Microsoft Entra ID, for example the Application Developer or Cloud Application Administrator role.
Create an App Registration in Entra ID
- Sign in to the Microsoft Entra admin center.
- Go to Identity > Applications > App registrations and click New registration.
- Type a name for the application, for example
Haystack PlatformExternal Connection. - Under Supported account types, choose the option that matches who will sign in.
- Under Redirect URI, select Web and paste the redirect URI from Haystack Enterprise Platform.
Redirect URL
Register the redirect URI from the Redirect URL field in the Add OAuth Provider dialog with your identity provider. Keep the default unless you embed the connect flow in your own frontend.
The callback is served by the deepset API, not the web app. On deepset Cloud, the default is
https://api.cloud.deepset.ai/api/v2/connections/callback. On other deployments, use your organization's API base URL with the path/api/v2/connections/callback. - Click Register and record the Application (client) ID. This is your OAuth client ID.
For more detail, see Register an application in Microsoft Entra ID.
Create a Client Secret
- Open the app registration and go to Certificates & secrets.
- Under Client secrets, click New client secret, add a description, and choose an expiry.
- Copy the secret Value immediately. You can't read it again after you leave the page.
Get the Private Key JWT
- Open the app registration and go to Certificates & secrets.
- Under Certificates, upload or create a certificate and note its Thumbprint (SHA-1).
- Export the matching private key in PEM format. Haystack Enterprise Platform expects a PEM block beginning with
-----BEGIN PRIVATE KEY-----or-----BEGIN RSA PRIVATE KEY-----.
For certificate-based client authentication, see Microsoft identity platform certificate credentials.
Configure API Permissions
- Go to API permissions and add the Microsoft Graph delegated permissions that match the scopes you plan to use.
- Grant admin consent if your tenant requires it.
Register the Provider in Haystack Enterprise Platform
- Click your profile icon and choose Settings.
- Go to Organization and open Integrations.
- In External Connections, click Add OAuth Provider.
- Choose the Microsoft Entra ID template.
- Fill in the fields:
- Provider Type — keep the default
microsoftunless you need a unique identifier for a second Entra app. - Display Name — the name users see, for example
Microsoft 365. Choose a name that will make it easy for users to identify the provider. - Client ID — paste the Application (client) ID from Entra ID.
- Authentication Method — choose Client Secret or Private Key JWT, then enter the secret or PEM key and thumbprint.
- Authorization URL and Token URL — replace
{tenant_id}in both URLs with your tenant ID. - Scopes — define the OAuth scopes for the provider. Default scopes include Microsoft Graph access for SharePoint sites and
offline_accessfor refresh tokens. Adjust scopes if your integration needs different permissions.
- Provider Type — keep the default
- Optionally turn on PKCE Required if your Entra app configuration needs PKCE. To learn more about PKCE, see Proof Key for Code Exchange (PKCE).
- Click Create.
The provider in External Connections.
What To Do Next
Was this page helpful?