

Azure Active Directory OIDC Web Sample


This sample demonstrates how to set up OpenId Connect authentication in a web application built using Node.js with Express. The sample is designed to run on any platform.


To run this sample you will need the following:

Register the sample in your Azure AD tenant

  1. Sign in to the Azure portal.

  2. On the top bar, click on your account, and then on Switch Directory. Once the Directory + subscription pane opens, choose the Active Directory tenant where you wish to register your application.

  3. Click on All services in the left-hand nav, and choose Azure Active Directory.

  4. Click on App registrations and choose New application registration.

  5. Enter a friendly name for the application, for example 'Webapp-Openidconnect' and select 'Web app / API' as the Application Type.

  6. For the sign-on URL, enter the base URL for this sample which is http://localhost:3000/.

  7. Click Create to create the application.

  8. In the succeeding page, Find the Application ID value and record it for later. You'll need it to configure the client ID in the application.

  9. Under Settings, choose Properties and update the App ID URI which is a unique identifier for your app. It is of the format 'https://<your_tenant_name>/<app_name>' replacing <your_tenant_name> with the name of your Azure AD tenant. For example: https://contoso.onmicrosoft.com/Webapp-Openidconnect

  10. Under Settings, click on Reply URLs and set it to http://localhost:3000/auth/openid/return which this sample uses by default.

  11. From the Settings menu, choose Keys and add a new entry in the Password section:

    • Type a key description (for instance 'app secret'),
    • Select a key duration of either In 1 year, In 2 years, or Never Expires.
    • When you save this page, the key value will be displayed. Copy, and save the value in a safe location.
    • You'll need this key later to configure the client secret in the app. This key value will not be displayed again, nor retrievable by any other means, so record it as soon as it is visible from the Azure portal.

Download the sample application and modules

Next, clone the sample repo and install the NPM modules.

From your shell or command line run:


From the project root directory, run the command:

Configure the application

Provide the parameters in exports.creds in config.js as instructed.

Optional configuration for production apps:

Build and run the application

Is the server output hard to understand?: We use bunyan for logging in this sample. The console won't make much sense to you unless you also install bunyan and run the server like above but pipe it through the bunyan binary:

$ npm install -g bunyan

$ node app.js | bunyan

You're done!

You will have a server successfully running on http://localhost:3000.

About The Code

