Password-like credential added to an app registration under Certificates & secrets, with its value displayed just once; public client apps don't have one.
Also called application password.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Client secret in context, with comparison tables and the common traps.
Terms in this definition
- App registration
Object in Microsoft Entra ID describing an app's identity, the permissions it needs and which account types it supports; multi-tenant apps and OpenID Connect sign-in depend on it.
- Public client
An application running in a browser or on a device, such as a single-page, mobile or desktop app, that cannot hold a secret and so can only get tokens for signed-in users. Leave Allow public client flows switched off unless it is required.
Related terms
- ClientSecretCredential
Credential type in the Azure Identity library for signing in as a service principal from three values (tenant ID, client ID, client secret); the secret it depends on needs protecting and regular rotation.
- Confidential client
Because it runs on a server (a daemon, web API or web app, say) it can safely hold a secret, and so it authenticates as itself with a federated credential, certificate or client secret, something no public client can do.
- OAuth 2.0
Standard authorisation protocol through which the Microsoft identity platform hands apps access tokens. In the client credentials flow, an app exchanges its client ID and client secret for a token.