Skip to main content

loaders.principal

Principal Objects​

class Principal()

Obtains Entra ID access tokens for a service principal.

Wraps the client-credentials flow, so it authenticates an application rather than a user. Used where a notebook has to call an api with an identity of its own instead of the identity the notebook runs as.

get_bearer_token​

@classmethod
def get_bearer_token(cls, tenant_id: str, app_client_id: str, app_secret: str,
scope: str)

Requests an access token with the client-credentials grant.

Posts to https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token and wraps the answer in a ServicePrincipal.

Arguments:

  • tenant_id str - Entra ID tenant the application is registered in.
  • app_client_id str - Application (client) id of the service principal.
  • app_secret str - Client secret for that application.
  • scope str - Scope the token is requested for, for example https://vault.azure.net/.default.

Returns:

  • ServicePrincipal - The client id together with the token type and the access token. A rejected request yields None for both token fields rather than an exception, so the caller checks access_token before using it.