Azure AD B2C登录自定义策略中是否可调用Rest API?
Azure AD B2C Sign-In Flow: Adding Claims via REST API
Absolutely! The Azure AD B2C sign-in flow does support integrating REST API calls to fetch or add custom attributes to user claims—just like the sign-up flow you’re familiar with. Here’s how to make it work:
Key Implementation Steps
- Define the REST API technical profile: Add a technical profile of type
RestfulProviderto your custom policy, identical to how you set it up for sign-up. This profile will manage API requests, authentication (if required), and response parsing. - Insert the API call into the sign-in journey: Locate the sign-in user journey (usually named
SignIn) in your policy, then add an orchestration step that invokes your REST API technical profile. Place this step after user authentication (so you have access to their user ID or unique identifiers to fetch relevant data) but before the token is issued. - Map API responses to claims: In the REST API technical profile, use
OutputClaimsto map data returned by your API to the claims that will be included in the final ID/access token. Don’t forget to define these claims in theClaimsSchemasection of your policy first.
Quick Example Snippet
Here’s how the orchestration step might look in your custom policy XML:
<OrchestrationStep Order="3" Type="ClaimsExchange"> <ClaimsExchanges> <ClaimsExchange Id="RESTGetCustomAttributes" TechnicalProfileReferenceId="REST-API-CustomAttributes" /> </ClaimsExchanges> </OrchestrationStep>
This step runs right after the user’s credentials are validated (typically step 2 in the sign-up journey) and pulls in additional attributes to attach to the token.
Important Considerations
- Ensure your API is reachable from Azure AD B2C’s network—if you’re using a private API, consider Azure App Service with VNet integration.
- Build error handling into both your API and the technical profile to redirect users properly if the API call fails (e.g., timeout, invalid response).
- Double-check that the claims you’re adding are included in the
OutputClaimsof your relying party technical profile—this ensures they’re actually emitted in the token.
内容的提问来源于stack exchange,提问作者Rocket Singh
相关产品推荐
相关产品推荐

