On-behalf-of flow with Entra ID and FastMCP
Blog post: https://baeke.info/2025/07/29/end-to-end-authorization-with-entra-id-and-mcp/
Instructions
1. Create and activate a Python virtual environment
python3 -m venv .venv
source .venv/bin/activate
2. Install dependencies
pip install -r requirements.txt
3. Set up environment variables
Create a .env file in the project root with the required Azure and API credentials (see example files for required variables).
4. Start the MCP server
python -m mcp.main
5. Run the MCP client
In a new terminal (with the virtual environment activated):
python mcp_client.py
Diagrams
sequenceDiagram
autonumber
participant User
participant Client
participant AzureAD as "Azure Entra ID"
participant MCP
participant MSGraph
User->>Client: Initiate Device Flow
Client->>AzureAD: Start Device Code Flow
AzureAD-->>Client: Device Code + Verification URL
Client->>User: Show Code + URL
User->>AzureAD: Authenticates via browser
AzureAD-->>Client: Returns Access Token (for MCP)
Client->>MCP: Call tool with Bearer Access Token
MCP->>AzureAD: OBO request for token to call MS Graph\n(include access token as assertion)
AzureAD-->>MCP: Returns new Access Token (for MS Graph)
MCP->>MSGraph: Call Graph API with new token
MSGraph-->>MCP: Graph data
MCP-->>Client: Return tool result
Metadata
Release files for iflow-mcp_gbaeke_mcp-obo 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz | 9.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 13.6 kB
Release files / iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz
| Download URL | iflow_mcp_gbaeke_mcp_obo-0.1.1.tar.gz |
|---|---|
| Size | 9.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0302d7d100c3f09d918a58b149683a3501ee7de8992931923075ee67afa113a4
|
|
BLAKE2b-256 checksum How to use checksums |
9d67b8321c5d85b7501b3d91e67c84868cae9e08ab4786228b8225d0bf3b167a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl
| Download URL | iflow_mcp_gbaeke_mcp_obo-0.1.1-py3-none-any.whl |
|---|---|
| Size | 4.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3bc9d437707f77175dfd8ff34bb0a5c7183e9527e61e71a0f3b597080486e247
|
|
BLAKE2b-256 checksum How to use checksums |
b83d6f259f3a1559abbaf0e21ebafb593b6352730989324dcab0ae33a54c1075
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.9.26 {"installer":{"name":"uv","version":"0.9.26","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Debian GNU/Linux","version":"13","id":"trixie","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|