Skip to main content

Azure Storage

Azure Storage services (Blob, Queue, File) authenticating with account shared keys, SAS tokens, or Microsoft Entra ID bearer tokens.

Shared KeySAS tokenEntra ID bearer token✓ header signing✓ query / presign✓ WASMdocs.rs/reqsign-azure-storage ↗

SAS credentials authenticate through the query string; shared keys and bearer tokens sign headers.

Get started​

cargo add reqsign --features azure
use reqsign::azure;

// Shared key, SAS, or Entra ID (client secrets, workload identity,
// managed identity, Azure CLI) — resolved by the default chain.
let signer = azure::default_signer();

let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://myaccount.blob.core.windows.net/my-container/my-blob")
.body(())?
.into_parts()
.0;

// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;

Credentials

Default credential chain

The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:

  1. Environment variables
  2. Azure CLI
  3. Entra ID client certificate
  4. Entra ID client secret
  5. Azure Pipelines federation
  6. Workload identity federation
  7. Managed identity (IMDS)

Credential providers

Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:

Credential granting

This provider can exchange credentials for downscoped ones before any request is signed — see Granting scoped access:

  • User Delegation SAS — Exchanges an Entra ID bearer token for a user delegation key and derives scoped SAS tokens from it.