Sign inDemoInstall


Package Overview
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies



Version published

Package description

What is @azure/msal-common?

The @azure/msal-common package is a Microsoft library that provides the core functionality for the authentication protocols OAuth 2.0 and OpenID Connect. It is primarily used in the development of applications that require secure access to Microsoft Azure services. The package serves as a common foundation for other Microsoft authentication libraries, enabling developers to implement authentication features efficiently.

What are @azure/msal-common's main functionalities?

Token Acquisition

This feature allows developers to acquire tokens for accessing secured resources. The code sample demonstrates how to acquire a token using a username and password.

const msal = require('@azure/msal-common');
const pca = new msal.PublicClientApplication({ auth: { clientId: 'your-client-id' } });
  scopes: [''],
  username: '',
  password: 'your-password'
}).then(response => console.log(response)).catch(error => console.error(error));

Token Caching

Token caching is crucial for efficient authentication management, reducing the need to request new tokens for each operation. The code sample shows how to read token cache from storage.

const { TokenCache } = require('@azure/msal-common');
const cache = new TokenCache();
cache.readFromStorage('your-storage-key').then(() => {
  const accountInfo = cache.getAccount('');

Account Management

This feature facilitates the management of user accounts in an application. The code sample retrieves account information based on the username.

const msal = require('@azure/msal-common');
const pca = new msal.PublicClientApplication({ auth: { clientId: 'your-client-id' } });
pca.getAccountByUsername('').then(account => {
}).catch(error => console.error(error));

Other packages similar to @azure/msal-common



Microsoft Authentication Library for JavaScript (MSAL.js) Common Protocols Package

npm version npm version codecov

Getting StartedAAD DocsLibrary Reference
  1. About
  2. FAQ
  3. Changelog
  4. Releases
  5. Prerequisites and Usage
  6. Installation
  7. Security Reporting
  8. License
  9. Code of Conduct


The MSAL library for JavaScript enables client-side JavaScript applications to authenticate users using Azure AD work and school accounts (AAD), Microsoft personal accounts (MSA) and social identity providers like Facebook, Google, LinkedIn, Microsoft accounts, etc. through Azure AD B2C service. It also enables your app to get tokens to access Microsoft Cloud services such as Microsoft Graph.

The @azure/msal-common package described by the code in this folder serves as a common package dependency for the @azure/msal-browser package (and in the future, the msal-node package). Be aware that this is an internal library, and is subject to frequent change. It is not meant for production consumption by itself.


See here.


Expect us to detail our major and minor releases moving forward, while leaving out our patch releases. Patch release notes can be found in our change log.

DateReleaseAnnouncementMain features
August 4, 2020@azure/msal-common v1.1.0Release Notes
July 20, 2020@azure/msal-common v1.0.0Release NotesFull release version of the @azure/msal-common
May 11, 2020@azure/msal-common v1.0.0-betaBeta version of the @azure/msal-common package
January 17, 2020@azure/msal-common v1.0.0-alphaNo release notes yetAlpha version of the @azure/msal-common package with authorization code flow for SPAs working in dev.

Prerequisites and Usage

This library is not meant for production use. Please use one of these packages specific to the platform you are developing for:


Via NPM:

npm install @azure/msal-common

Security Reporting

If you find a security issue with our libraries or services please report it to with as much detail as possible. Your submission may be eligible for a bounty through the Microsoft Bounty program. Please do not post security issues to GitHub Issues or any other public site. We will contact you shortly upon receiving the information. We encourage you to get notifications of when security incidents occur by visiting this page and subscribing to Security Advisory Alerts.


Copyright (c) Microsoft Corporation. All rights reserved. Licensed under the MIT License (the "License");

We Value and Adhere to the Microsoft Open Source Code of Conduct

This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact with any additional questions or comments.



Last updated on 12 Sep 2022

Did you know?


Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.


Related posts

SocketSocket SOC 2 Logo


  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap


Stay in touch

Get open source security insights delivered straight into your inbox.

  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc