> For the complete documentation index, see [llms.txt](https://doc.duaer.com/zh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/zh/integrations/builtin/credentials/azureentracognitiveservicesoauth2api.md).

# 在 Duaer 里配置 Azure Entra ID (Azure Active Directory) 凭证

在 Duaer 中保存 Azure Entra ID (Azure Active Directory) 的连接信息，供数字组织节点在运行时使用。密钥经实例加密密钥保护，不会写进节点参数。
## 用 Entra ID 连接 Azure OpenAI <a href="#register-an-app" id="register-an-app"></a>

Duaer 的 Azure Entra ID (Azure Active Directory) API 凭证让 Azure OpenAI Chat Model 节点用应用身份（客户端凭据）调用，不用 API 密钥：

1. 在 [Microsoft Entra 管理中心](https://entra.microsoft.com/) 新建应用注册，复制目录（租户）ID 和应用程序（客户端）ID，填进 Tenant ID 和 Client ID；在 Certificates & secrets 新建客户端密钥，填进 Client Secret。
2. 在 Azure 门户里 Azure OpenAI 资源的 Access control (IAM) 里，把 Cognitive Services OpenAI User 角色分配给这个应用。
3. Endpoint Type 选 Classic 时填 Resource Name 和 API Version（地址是 *.openai.azure.com）；选 Azure AI Foundry 时 Endpoint 填完整地址，例如 https://<资源>.services.ai.azure.com/openai/v1。

## Duaer 里的 Azure Entra ID (Azure Active Directory) API 字段 <a href="#azure-entra-id-azure-active-directory-api" id="azure-entra-id-azure-active-directory-api"></a>

在 Duaer 里新建 Azure Entra ID (Azure Active Directory) API 凭证，填写这些字段：

- Client ID（必填）
- Client Secret（必填，密钥）
- Endpoint Type：Classic 对应 *.openai.azure.com（资源名加按部署区分的地址）。Azure AI Foundry 对应 *.services.ai.azure.com/openai/v1（完整终端地址）。默认 Classic，可选 Classic、Azure AI Foundry。
- Resource Name（必填）：Endpoint Type 为 Classic 时显示。
- API Version（必填）：默认 2025-03-01-preview，Endpoint Type 为 Classic 时显示。
- Endpoint（必填）：完整的 Azure AI Foundry OpenAI 兼容基础地址。Endpoint Type 为 Azure AI Foundry 时显示。
- Endpoint：可选。默认是 https://<资源名>.openai.azure.com。Endpoint Type 为 Classic 时显示。
- Tenant ID（必填）：Entra 应用注册的目录（租户）ID。

Duaer 对这种类型固定使用 OAuth2 Client Credentials（客户端凭据） 授权方式。

所有 Duaer OAuth2 凭证共有的可选设置：Ignore SSL Issues (Insecure)、Token Expired Status Code、Encrypted Tokens (JWE)、JWKS URI。说明见 [OAuth2 API](/zh/integrations/builtin/credentials/httprequest.md#oauth2-api)。

使用它的 Duaer 节点：[Azure AI Foundry Chat Model](/zh/integrations/builtin/cluster-nodes/sub-nodes/n8n-nodes-langchain.lmchatazureopenai.md)。

## 在 Duaer 里保存连接

打开 Credentials，创建 Azure Entra ID (Azure Active Directory)。按字段填写密钥、OAuth 或服务器地址。保存后，数字组织节点引用这份凭证，而不是把密钥写进参数。

凭证内容经实例的加密密钥保护。换密钥或弄丢密钥后，已存凭证会解不开，见托管文档里的加密密钥说明。

## 谁能用这份凭证

能否看到或编辑，取决于项目和角色。不要把密钥贴进聊天或变量。外部密钥库见外部密钥文档。
## Questions

### Duaer 的 Azure Entra ID (Azure Active Directory) 凭证密钥会出现在节点参数里吗？

不会。在 Duaer 里，Azure Entra ID (Azure Active Directory) 的密钥保存在凭证中，节点只引用凭证。执行记录也不应出现明文密钥。

### 在 Duaer 里 Azure Entra ID (Azure Active Directory) 凭证保存失败常见原因是什么？

字段填错、OAuth 回调地址与实例 URL 不一致，或当前角色不能创建凭证。先核对 Azure Entra ID (Azure Active Directory) 服务商要求的字段，再确认你在该项目里有权新建凭证。

