Our situation: We have a API developed in C#/ASP.Net Core together with a separate frontend. Both the API and the frontend have an associated App Registration in Azure AD and whenever the frontend wants to make a request to the backend, it uses MSAL to obtain a token with the scopes that are exposed by the APIs app registrations.
No we want to create an extension for Azure DevOps that calls our API as well, but we are struggling with how to authenticate it. The token that you can get from the SDK is lacking our scopes because it is, as far as I understand it, only really meant to be used for DevOps internal services. I've seen this sample repository, but it seems to me that it just skips verifying the scope and the token also does not contain any user information.
The way we are doing it right now is to use MSAL inside our extension iFrames. That requires the user to sign in twice and brings a few other unwanted downsides, like missing persistence.
How would/did you go about authenticating API calls in DevOps extensions?