How can I test the OAuth 2.0 authorization code flow with PKCE in a Delphi desktop app using a test Azure AD tenant without production credentials?
0 reputation · 19 Aug 2026, 08:37 UTC
0 reputation · 19 Aug 2026, 08:37 UTC
I need to verify that my Delphi VCL application can successfully obtain an access token from the Microsoft identity platform using the OAuth 2.0 authorization code flow with PKCE, while avoiding any use of production Azure AD credentials or real user data.
The test environment must use a dedicated Azure AD test tenant, a localhost redirect URI that matches the app registration, and a temporary user account solely for testing. I am uncertain how to configure the Delphi REST client to handle the redirect listener securely and how to validate the token response without persisting sensitive information.
Specific questions: How should I register the test Azure AD application to allow the localhost redirect URI with PKCE for a Delphi desktop client? What is the recommended approach to keep the authorization code and resulting tokens in memory only during automated tests? How can I confirm that the token acquisition succeeds without relying on production credentials?
http://localhost:/ (or use the generic https://login.microsoftonline.com/common/oauth2/nativeclient if you prefer the broker). Enable the Public client (mobile & desktop) option and grant the desired delegated permissions (e.g., User.Read) for Microsoft Graph.code_verifier (43‑128 characters) and derive the code_challenge using SHA‑256 (Base64URL‑encoded, no padding). Keep both values only in memory (e.g., as string variables).TIdHTTPServer) bound to the redirect URI port. The listener should capture the GET request that the browser returns after the user signs in, extract the code and state query parameters, verify that the returned state matches the one you sent, then stop the listener.https://login.microsoftonline.com/<tenant>/oauth2/v2.0/authorize?client_id=<appId>&response_type=code&redirect_uri=<URL‑encoded redirect URI>&response_mode=query&scope=User.Read&state=<randomState>&code_challenge=<codeChallenge>&code_challenge_method=S256. The user signs in with the temporary test account you created in the tenant.https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token with form‑encoded body: client_id=<appId>&grant_type=authorization_code&code=<authCode>&redirect_uri=<redirectURI>&code_verifier=<codeVerifier>. Keep the resulting access_token, expires_in, and optional refresh_token in memory only; do not write them to disk or the registry.GET https://graph.microsoft.com/v1.0/me) with the header Authorization: Bearer <accessToken>. A successful response containing the test user’s profile confirms that the flow worked.Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.