Agents-for-net oauth-flows.instructions.md

A set of project instructions explaining how OAuth sign-in works in Microsoft Agents for .NET. OAuth is a standard way for an application to obtain permission and access tokens on a user's behalf.

In plain words
What is it for?
Use it when changing Teams single sign-on, OAuth token exchange, user authorization, continuation activities, or related source files.
Why use it?
It helps developers follow the existing multi-step sign-in process, including saved flow state, consent prompts, token exchange, and failure handling.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/microsoft/agents-for-net/oauth-flows
Clone the repo
git clone --depth 1 https://github.com/microsoft/Agents-for-net

Made for: GitHub Copilot.

Per session 550 This file is loaded in full into every session.
When invoked 550 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00550 $0.00550
Opus 5 $0.00275 $0.00275
Sonnet 5 $0.00110 $0.00110
Haiku 4.5 $0.00055 $0.00055

Measured 2d ago against content hash d5e1d5493d70, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Agents-for-net oauth-flows.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/oauth-flows.instructions.md · 40 lines

How it starts

The opening of the file, as written. The whole thing — 40 lines — stays where its author put it; the contents beside it link to each section on GitHub.

OAuth & User Sign-In Flow Context

When working on OAuth, token exchange, or user sign-in code, reference these sequence diagrams:

  • docs/teams-sso-sequence-diagram.md — High-level Teams SSO scenarios (SignedIn, No Consent, Consent Required, Exchange Failure)
  • docs/oauth-internal-sequence-diagram.md — Detailed internal flow through UserAuthorization → UserAuthorizationDispatcher → AzureBotUserAuthorization → OAuthFlow → IUserTokenClient

Key Design Points

  • Sign-in is a multi-turn operation — flow state is stored between turns and deleted on completion or failure.
  • The Token Service Client caches successful tokens from GetTokenOrSignInResource.
  • If OBO is configured, OBO is performed on the token returned by Token Service prior to setting the Turn Token.
  • A Continuation Activity is stored when sign-in starts and replayed proactively after successful token acquisition.
  • ConsentRequired (412) triggers Teams to prompt the user, followed by a signin/verifyState invoke with a magic code.
  • Non-consent exchange failures return 400 — Teams will NOT retry.
Component Path
UserAuthorization (App-level) src/libraries/Builder/Microsoft.Agents.Builder/App/UserAuth/UserAuthorization.cs
UserAuthorizationDispatcher src/libraries/Builder/Microsoft.Agents.Builder/UserAuth/UserAuthorizationDispatcher.cs
AzureBotUserAuthorization src/libraries/Builder/Microsoft.Agents.Builder/UserAuth/TokenService/AzureBotUserAuthorization.cs
OAuthFlow src/libraries/Builder/Microsoft.Agents.Builder/UserAuth/TokenService/OAuthFlow.cs
UserTokenClientWrapper src/libraries/Builder/Microsoft.Agents.Builder/UserAuth/TokenService/UserTokenClientWrapper.cs
IUserTokenClient src/libraries/Client/Microsoft.Agents.Connector/IUserTokenClient.cs
OBOExchange src/libraries/Builder/Microsoft.Agents.Builder/UserAuth/OBOExchange.cs
Authentication.Msal src/libraries/Authentication/Authentication.Msal/
High-level diagrams docs/teams-sso-sequence-diagram.md
Detailed internal diagrams docs/oauth-internal-sequence-diagram.md

Read the full file on GitHub · 40 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 40 lines · 550 tokens per session scan A d5e1d5493d70

Subscribe to this mod's changes

Agents-for-net oauth-flows.instructions.md is an instructions file published in the GitHub repository microsoft/Agents-for-net (177 stars, last pushed 4d ago), licensed MIT. It adds 550 tokens to every session, about $0.0028 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.