Microsoft Entra ID
Security

Credential Management Api

In brief

The article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.

What Entra admins need to know

Run the sample only in a test tenant and do not deploy it to production.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.service: identity-platform ms.subservice: external ms.topic: reference ms.date: 10/02/05/2026 ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1030 #Customer intent: As an identity developer, I want to learn how to integrate the credential management API into my customer-facing app so that customers can list and register their own credential methods.

The credential management API complements Microsoft Entra native authentication, where your application hosts the sign-in experience instead of delegating it to a browser. Use the credential management API after a customer signs in.

Successful resource responsesTo support passkey management in your app, use HAL+JSON (application/hal+json)the passkey credential management sample app. Activation requestsThe sample demonstrates the listing and errors use JSON (application/json).registration flows in this article by using delegated permissions. Follow the sample's README to configure and run the app.

Prerequisites

Successful resource responses use HAL+JSON (application/hal+json). Activation requests and errors use JSON (application/json).

Prerequisites

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…