azuresql-db-auth

Guidance for connecting an application securely to the local Azure SQL Database engine. It replaces the administrator login with a user that has only the permissions the application needs and keeps database secrets out of source code.

In plain words
What is it for?
Create an application database user, choose local or cloud authentication, configure a safe connection string, protect passwords, and avoid using the built-in administrator login.
Why use it?
Using the administrator account in an app gives a stolen credential too much access. The guidance also accounts for different sign-in methods locally and in Azure without requiring application code changes.

Skill for Claude CodeCodex

Part of the azure-sql-database-container plugin — 17 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/microsoft/azure-sql-database-container/azuresql-db-auth
Any agent
npx skills add microsoft/azure-sql-database-container --skill azuresql-db-auth
Clone the repo
git clone --depth 1 https://github.com/microsoft/azure-sql-database-container

Made for: Claude Code, Codex.

Or install azure-sql-database-container, the plugin that ships this one along with the rest of its 17 skills.

Per session 171 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,345 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00171 $0.02345
Opus 5 $0.00086 $0.01172
Sonnet 5 $0.00034 $0.00469
Haiku 4.5 $0.00017 $0.00234

Measured 3d ago against content hash e84831c3c8b0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

azuresql-db-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/azuresql-db-auth/SKILL.md · 149 lines

How it starts

The opening of the file, as written. The whole thing — 149 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Connect securely to the Azure SQL Database container (least-privilege user, auth, secrets)

sa is a bootstrap/admin login for provisioning, not what your application should connect as. This skill wires the app to a least-privilege user, picks the auth method per environment (SQL locally, Microsoft Entra or managed identity in the cloud, changing only the connection string), secures the connection, and keeps the secret out of source control.

Load-bearing facts (inlined; full engine detail in azuresql-db-container)

  • This is the Azure SQL Database engine (Private Preview), not the SQL Server image mcr.microsoft.com/mssql/server. SERVERPROPERTY('EngineEdition') returns 5, Edition returns 'SQL Azure'.
  • Image: sqldbpreview-dpgaeqhmgphzd4bk.azurecr.io/azure-sql/db-dev:latest (x64; on a non-x64 host add --platform linux/amd64). Required env ACCEPT_EULA=Y + a complex MSSQL_SA_PASSWORD. Engine listens on 1433.
  • The engine does NOT auto-create databases. CREATE DATABASE appdb on a master connection first; do not USE to switch databases (a user-database session returns Msg 40508); select the database in the connection string.
  • Apps read one SQL_CONNECTION_STRING env var; strings use User Id= / Password= / Database= and TrustServerCertificate=true for the local self-signed cert.
  • Container-specific and verified: a SQL contained user (CREATE USER ... WITH PASSWORD) does not work on the container today (CREATE USER ... WITH PASSWORD and ALTER DATABASE ... SET CONTAINMENT = PARTIAL both fail: Msg 15007 / Msg 12824). Create a SQL app identity as a server login mapped to a database user instead. This is the inverse of Azure SQL Database in the cloud, where the contained user is the norm.

Step 1: create a least-privilege user (not sa)

Do provisioning as sa, then give the app its own identity with only the roles it needs. The working recipe differs by environment, but the app code does not (the app just connects with a username and password, or an Entra token).

Read the full file on GitHub · 149 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 149 lines · 171 tokens per session scan A e84831c3c8b0

Subscribe to this mod's changes

azuresql-db-auth is a skill published in the GitHub repository microsoft/azure-sql-database-container (16 stars, last pushed yesterday), licensed MIT. It adds 171 tokens to every session and 2,345 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

prisma-upgrade-v7

Complete migration guide from Prisma ORM v6 to v7 covering all breaking changes. Use when upgrading Prisma versions, encountering v7 errors, or migrating existing projects. Triggers on "upgrade to prisma 7", "prisma 7 migration", "prisma-client generator", "driver adapter required".

nitrocloudofficial/nitrostack · 67 tokens

ddia-systems

Design data systems by understanding storage engines, replication, partitioning, transactions, and consistency models. Use when the user mentions "database choice", "which database should I use", "SQL or NoSQL", "replication lag", "partitioning strategy", "consistency vs availability", "stream processing", "ACID…

wondelai/skills · 138 tokens

sqlitecpp-update-sqlite

How to update the bundled SQLite3 amalgamation (sqlite3/sqlite3.c and sqlite3.h), the Meson wrap, README.md, and CHANGELOG.md. Use when upgrading SQLite, refreshing the vendored amalgamation, or bumping the sqlite3 wrap.

SRombauts/SQLiteCpp · 61 tokens

dsql

Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, FK…

awslabs/agent-plugins · 227 tokens

mongodb-natural-language-querying

Generate read-only MongoDB queries (find) or aggregation pipelines using natural language, with collection schema context and sample documents. Use this skill whenever the user asks to write, create, or generate MongoDB queries, wants to filter/query/aggregate data in MongoDB, asks "how do I query...", needs help with…

mongodb/agent-skills · 162 tokens

sql-translate

Translate SQL queries between database dialects (Snowflake, BigQuery, PostgreSQL, MySQL, etc.).

AltimateAI/altimate-code · 26 tokens