Skip to main content

On-behalf-of flow with Entra ID and FastMCP

Blog post: https://baeke.info/2025/07/29/end-to-end-authorization-with-entra-id-and-mcp/

Instructions

1. Create and activate a Python virtual environment

python3 -m venv .venv
source .venv/bin/activate

2. Install dependencies

pip install -r requirements.txt

3. Set up environment variables

Create a .env file in the project root with the required Azure and API credentials (see example files for required variables).

4. Start the MCP server

python -m mcp.main

5. Run the MCP client

In a new terminal (with the virtual environment activated):

python mcp_client.py

Diagrams

sequenceDiagram
    autonumber
    participant User
    participant Client
    participant AzureAD as "Azure Entra ID"
    participant MCP
    participant MSGraph

    User->>Client: Initiate Device Flow
    Client->>AzureAD: Start Device Code Flow
    AzureAD-->>Client: Device Code + Verification URL
    Client->>User: Show Code + URL

    User->>AzureAD: Authenticates via browser
    AzureAD-->>Client: Returns Access Token (for MCP)

    Client->>MCP: Call tool with Bearer Access Token
    MCP->>AzureAD: OBO request for token to call MS Graph\n(include access token as assertion)
    AzureAD-->>MCP: Returns new Access Token (for MS Graph)

    MCP->>MSGraph: Call Graph API with new token
    MSGraph-->>MCP: Graph data
    MCP-->>Client: Return tool result

Metadata

Release files for iflow-mcp_gbaeke_mcp-obo 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for iflow-mcp_gbaeke_mcp-obo 0.1.1
File Size Uploaded
iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz 9.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for iflow-mcp_gbaeke_mcp-obo 0.1.1
File Interpreter ABI Platform
iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 13.6 kB

Release files / iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz

Download URL iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz
Size 9.3 kB
Tags Source
SHA-256 checksum
How to use checksums
0302d7d100c3f09d918a58b149683a3501ee7de8992931923075ee67afa113a4
BLAKE2b-256 checksum
How to use checksums
9d67b8321c5d85b7501b3d91e67c84868cae9e08ab4786228b8225d0bf3b167a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl

Download URL iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl
Size 4.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3bc9d437707f77175dfd8ff34bb0a5c7183e9527e61e71a0f3b597080486e247
BLAKE2b-256 checksum
How to use checksums
b83d6f259f3a1559abbaf0e21ebafb593b6352730989324dcab0ae33a54c1075
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page