Integrations
Set up Azure Entra ID (Azure Active Directory) credentials in Duaer
Store Azure Entra ID (Azure Active Directory) connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
Connect to Azure OpenAI with Entra ID
The Duaer Azure Entra ID (Azure Active Directory) API credential lets the Azure OpenAI Chat Model node call with an app identity (client credentials) instead of an API key:
- In the Microsoft Entra admin center, create an app registration and put its Directory (tenant) ID and Application (client) ID in Tenant ID and Client ID. Create a client secret under Certificates & secrets and put it in Client Secret.
- In the Azure portal, under Access control (IAM) on the Azure OpenAI resource, assign the Cognitive Services OpenAI User role to the app.
- With Endpoint Type set to Classic, fill in Resource Name and API Version (the address is *.openai.azure.com). With Azure AI Foundry, put the full address, such as https://<resource>.services.ai.azure.com/openai/v1, in Endpoint.
Azure Entra ID (Azure Active Directory) API fields in Duaer
In Duaer, choose Azure Entra ID (Azure Active Directory) API when you create a credential, then fill in these fields:
- Client ID (required)
- Client Secret (required, secret)
- Endpoint Type: Classic targets *.openai.azure.com (resource name + deployment-based URLs). Azure AI Foundry targets *.services.ai.azure.com/openai/v1 (full endpoint URL). Default: Classic. Options: Classic, Azure AI Foundry.
- Resource Name (required): Shown when Endpoint Type is Classic.
- API Version (required): Default: 2025-03-01-preview. Shown when Endpoint Type is Classic.
- Endpoint (required): The full Azure AI Foundry OpenAI-compatible base URL. Shown when Endpoint Type is Azure AI Foundry.
- Endpoint: Optional. Defaults to https://.openai.azure.com. Shown when Endpoint Type is Classic.
- Tenant ID (required): The Directory (tenant) ID of the Entra app registration.
Duaer uses the OAuth2 Client Credentials grant for this type.
Optional settings shared by every Duaer OAuth2 credential: Ignore SSL Issues (Insecure), Token Expired Status Code, Encrypted Tokens (JWE), JWKS URI. They are described under OAuth2 API.
Duaer nodes that use it: Azure AI Foundry Chat Model.
Save the connection in Duaer
Open Credentials and create Azure Entra ID (Azure Active Directory). Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.
Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys.
Who can use this credential
Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
Questions
Do Azure Entra ID (Azure Active Directory) secret values appear in Duaer node parameters?
No. In Duaer, Azure Entra ID (Azure Active Directory) secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.
What usually stops a Azure Entra ID (Azure Active Directory) credential from saving in Duaer?
Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Azure Entra ID (Azure Active Directory) expects, then confirm you can create credentials in that project.
In this section
Built-in integrations in Duaer
Built-in triggers, actions, and credentials in Duaer. Triggers start a digital organization. Actions run a step after it has started.
IntegrationsRisks of community nodes in Duaer
Before you install a community node in Duaer, know the code comes from a source the instance admin trusts, and know what permissions it gets.
IntegrationsTroubleshoot community nodes in Duaer
When a Duaer community node will not install or run, check the version, permissions, and node docs, then the instance logs.
IntegrationsMake custom API calls for an app in Duaer
When a Duaer app node does not expose the API you need, use HTTP Request and reuse that app’s saved authentication.
IntegrationsIntegrations in Duaer
Built-in triggers, actions, and credentials in Duaer. Community nodes are extra packages. Custom operations reuse saved authentication with HTTP Request.
CredentialsBuilt-in credentials in Duaer
Per-service credential notes for Duaer built-ins. The create flow is in the credentials overview; node docs link to the matching service page.
Create nodesCreate a custom node for Duaer
Write a node package for Duaer when built-in nodes and custom operations are not enough and you will reuse the step.