| Value in Entra | Entered in Ejento as |
|---|---|
| Application (client) ID (for a managed identity, its Client ID) | Application (Client) ID |
| Directory (tenant) ID | Tenant ID |
Use an application that is only used for Ejento. If the same application is also used to
call another API of yours, tokens meant for that API would be accepted by Ejento too.
api://<your-client-id>/.default. Use a different value only if Ejento has given you one.api://<your-client-id>. MSAL caches tokens until they expire, so you can call the acquire method on every request.| Claim | Should be |
|---|---|
aud | api://<your-client-id>, or the bare <your-client-id>. Either is fine. |
scp | Absent. If it is present, the token came from a user sign-in, not the app-only flow. |
tid | Your Directory (tenant) ID |
azp (v2) or appid (v1) | Your Application (client) ID |
AADSTS7000215: Invalid client secret provided, before the request ever reaches Ejento. Set a rotation reminder, or use a managed identity so there is no secret to rotate. Rotating a secret needs no change in Ejento, because the Application ID stays the same.