Credential Management Api
In brief
The article now links to a sample app demonstrating passkey listing and registration with delegated permissions and warns that its deletion flow uses high-privilege application permissions and a client secret in browser code.
What Entra admins need to know
Run the sample only in a test tenant and do not deploy it to production.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
ms.service: identity-platform
ms.subservice: external
ms.topic: reference
ms.date: 10/02/05/2026
ai-usage: ai-assisted
ms.custom: msecd-doc-authoring-1030
#Customer intent: As an identity developer, I want to learn how to integrate the credential management API into my customer-facing app so that customers can list and register their own credential methods.
The credential management API complements Microsoft Entra native authentication, where your application hosts the sign-in experience instead of delegating it to a browser. Use the credential management API after a customer signs in.
Successful resource responsesTo support passkey management in your app, use HAL+JSON (application/hal+json)the passkey credential management sample app. Activation requestsThe sample demonstrates the listing and errors use JSON (application/json).registration flows in this article by using delegated permissions. Follow the sample's README to configure and run the app.
Prerequisites
Successful resource responses use HAL+JSON (application/hal+json). Activation requests and errors use JSON (application/json).
Prerequisites
@@ -7,7 +7,7 @@ ms.author: marshmacy ms.service: identity-platform ms.subservice: external ms.topic: reference-ms.date: 10/02/2026+ms.date: 10/05/2026 ai-usage: ai-assisted ms.custom: msecd-doc-authoring-1030 #Customer intent: As an identity developer, I want to learn how to integrate the credential management API into my customer-facing app so that customers can list and register their own credential methods.@@ -21,6 +21,11 @@ The Microsoft Entra External ID credential management API lets your application The credential management API complements Microsoft Entra [native authentication](concept-native-authentication.md), where your application hosts the sign-in experience instead of delegating it to a browser. Use the credential management API after a customer signs in. +To support passkey management in your app, use the [passkey credential management sample app](https://github.com/Azure-Samples/ms-identity-ciam-native-javascript-samples/tree/main/passkey-sample). The sample demonstrates the listing and registration flows in this article by using delegated permissions. Follow the sample's README to configure and run the app.++> [!IMPORTANT]+> The sample's deletion flow still uses Microsoft Graph with high-privilege application permissions and a client secret in browser code. Run the sample only in a test tenant. Don't deploy it to production.+ Successful resource responses use HAL+JSON (`application/hal+json`). Activation requests and errors use JSON (`application/json`). ## Prerequisites 