Azure Identity library for Rust
Microsoft Entra ID authentication for Azure SDK clients.
Use this skill when:
- An app needs to authenticate to Azure services from Rust
- You need
DeveloperToolsCredentialfor local development - You need
ManagedIdentityCredentialfor Azure-hosted workloads - You need service principal auth with secret or certificate
IMPORTANT: Only use official
azure_*crates published by the azure-sdk crates.io user. Do NOT use the deprecatedazure_sdk_*crates (MindFlavor/AzureSDKForRust) or community crates. Official crates use underscores in names and none have version 0.21.0.
Note: The Rust SDK does not have
DefaultAzureCredential. UseDeveloperToolsCredentialfor local development andManagedIdentityCredentialfor production.
Installation
If your code uses
azure_coretypes directly, addazure_coretoCargo.toml. If you only use service-crate re-exports, directazure_coredependency is optional.
Environment Variables
Authentication
DeveloperToolsCredential (Local Development)
Tries Azure CLI then Azure Developer CLI:
Ensure you are logged in:
ManagedIdentityCredential (Production)
For Azure-hosted resources (VMs, App Service, Functions, AKS):
ClientSecretCredential (Service Principal)
For CI/CD pipelines and service accounts:
Credential Types
Best Practices
- Use
cargo addto manage dependencies, never editCargo.tomldirectly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits. - Add
azure_coreonly when importingazure_coretypes directly. If your code importsazure_core::http::Url,azure_core::http::RequestContent, orazure_core::error::ErrorKind, includeazure_core; otherwise a direct dependency is optional. - Use
DeveloperToolsCredentialfor local dev,ManagedIdentityCredentialfor production — Rust does not provide a singleDefaultAzureCredentialtype - Never hardcode credentials — use environment variables for service principals
- Clone credentials — pass
credential.clone()when constructing multiple clients; credentials areArc-wrapped - Reuse clients — clients are thread-safe; create once, share across tasks
- Assign RBAC roles — ensure the identity has appropriate roles for the target service (e.g., "Key Vault Secrets User" for secret reads)
- Run
cargo clippy -- -D warningswhen the prompt, eval, or CI expects lint-clean output; Rust trajectory graders can fail on style lints even after compiler errors are fixed - Future-proof
#[non_exhaustive]SDK models — when constructing SDK model/options structs, end the initializer with..Default::default()(add#[allow(clippy::needless_update)]) and use a_wildcard arm when matching SDK enums, so new service-added fields/variants don't break your build


