How to set up Microsoft.Graph for an ASP.NET core web API using the client credentials flow

Viewed 318

I have an ASP.NET Core web API that needs to access the microsoft graph API authenticated as itself. Not "on behalf" of a signed in user. (i.e. using the client credentials flow)

In the handler for an HTTP request, I need to use the GraphServiceClient object from the Microsoft.Graph NuGet package.

Currently, the way I have it set up is I have an "MsGraphClient" singleton service. In the constructor of that service, I instantiate my GraphServiceClient using the tenantId, clientId, and clientSecret.

    public MsGraphClient(IOptions<AppConfig> config)
    {
        ...

        var clientSecretCredential = new ClientSecretCredential(this.tenantId, this.clientId, this.clientSecret);
        this.graphClient = new GraphServiceClient(clientSecretCredential, scopes);
    }

I then use this.graphClient in my request handlers to interact with with microsoft graph.

I based my setup of the GraphServiceClient off of this example from microsoft. However, that example is console application. My worry is that since I have an API which instantiates the GraphServiceClient in the constructor of a singleton service, the access token will expire at some point and this.graphClient will no longer work.

Does the GraphServiceClient take care of refreshing access tokens? Is there a better way I could set this up?

0 Answers
Related