Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

token_grant: support client_id so client_credentials works with Microsoft Entra federated credentials

Open Beginner friendly
#4,372 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
70/100
Issue type
Feature
Clarity
Clearly specified
Activity status
Active
Tech stack
azure, rust

Research direction

Start with TokenGrantParams in crates/openshell-core/src/oauth.rs, which builds the form body from client_assertion, client_assertion_type, audience and scope. Add an optional client_id field and include it as a form field only when it is set, leaving existing requests unchanged. Done means a token_grant config with client_id sends it in the body, and a config without it sends the same body as before; look for existing token request tests to extend.

Written by the indexing model from the issue text.

Description

state:triage-needed

We're trying to use token_grant with client_credentials against Microsoft Entra ID, with the sandbox's SPIFFE JWT-SVID as the client assertion. Entra supports this through federated identity credentials (https://learn.microsoft.com/en-us/entra/workload-id/workload-identity-federation-spiffe-spire), but it needs client_id in the request body to pick the app registration.

TokenGrantParams in crates/openshell-core/src/oauth.rs only sends client_assertion, client_assertion_type, audience and scope, so there's no way to set it. We tried two workarounds against Entra:

  • client_id in the token endpoint's query string is ignored.
  • Without client_id in the body, Entra uses the assertion's iss as the app identifier and fails with AADSTS700016.

Could token_grant take an optional client_id that's sent as a form field? Something like:

credentials:
  - name: graph_access_token
    auth_style: bearer
    header_name: Authorization
    token_grant:
      token_endpoint: https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token
      client_id: <app id>
      jwt_svid_audience: api://AzureADTokenExchange
      scopes: [https://graph.microsoft.com/.default]

Without it we need a small broker in front of Entra just to add one field. Happy to send a PR if this sounds reasonable.

Dominant language
Rust
Stars
15.4k
Forks
1.7k
Avg merge
1d 21h
Merged PRs (30d)
366

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/OpenShell

All issues in NVIDIA/OpenShell

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.