Created prompt agents in Foundry (using Azure portal). Having authentication issues trying to connect to these agents (create response) from our frontend ios app.

GenixPRO 206 Reputation points
2026-05-31T03:10:58.8466667+00:00

Hi Team,

Background:

1.0 Earlier we created Assistants using Assistants API in Foundry Classic (azure portal).

2.0 We call these Assistants from our ios App, create threads & manage user conversation. The setup worked.

2.1 We used API key (in foundry classic) for testing - to connect using assistant_id from frontend & create user threads. Worked.

Problem:

3.0 With the announcement of Assistants API retirement, we're testing migration to Prompt Agents in Foundry.

4.0 We Build a prompt agent in Azure Foundry (using model = GPT5.4 mini). We get -> endpoint, agentName, agentVersion

4.1 Foundry Home indicates different {API Key} & 2 endpoints - {Project endpoint} & {Azure OpenAI endpoint}. We assumed we've to use {Project endpoint} to connect to foundry agent from frontend (ios app). Tried connection using API Key (different from the one used in 2.1 above). Seems Foundry Classic and Foundry (new) have their own respective API Key.

4.2 Refer attachment. When trying to connect using project endpoint, we get an error -> aml-user-token header is required. There seems to be some IAM issue that we're unable to resolve. We're redirected to online resource:

https://learn.microsoft.com/en-us/azure/machine-learning/how-to-authenticate-online-endpoint?view=azureml-api-2&tabs=cli%2Cazure-cli#choose-an-authentication-mode

4.3 For initial testing purposes, how can we connect to the agent from frontend and generate response using {Auth Type = API Key}? We don't want to setup Entra ID / other authentication methods for this testing. We could connect to Assistants using API Key. Can't we do the same for agents? Using our JS/TS frontend app.

Appreciate your help.

ThanksAgentsIssue_v1_31May2026.pdf

Azure OpenAI in Foundry Models
0 comments No comments

Answer accepted by question author
Sina Salam 31,456 Reputation points Volunteer Moderator
2026-05-31T10:57:15.6333333+00:00

Hello GenixPRO,

Welcome to the Microsoft Q&A and thank you for posting your questions here.

I understand that you are creating prompt agents in Foundry (using Azure portal). Having authentication issues trying to connect to these agents (create response) from our frontend iOS app.

The issue is that the request is being sent to the wrong runtime surface, which is why you receive the aml-user-token header is required error. In the new Microsoft Foundry architecture, Prompt Agents are not meant to be called directly from a frontend using API key only through that endpoint. Check the associated links below for more reading and implementation steps.

Most of all, things change fast:

  1. A Prompt Agent in the new Microsoft Foundry must not be called through the raw endpoint the you're currently using. The supported Foundry project endpoint is https://<resource>.services.ai.azure.com/api/projects/<project-name>, and published agent applications use .../applications/<app-name>/protocols/openai. Those are the documented runtime surfaces for agents in the new experience. - https://learn.microsoft.com/en-us/azure/foundry/how-to/develop/sdk-overview, https://learn.microsoft.com/azure/foundry/agents/how-to/publish-responses
  2. In the official JavaScript Foundry SDK, Microsoft Entra ID is the only authentication method currently supported for the project client. By contrast, API keys are explicitly documented for the /openai/v1 endpoint, which is for Azure OpenAI / Foundry Models APIs, not for Foundry-specific agent/project operations. - https://learn.microsoft.com/en-us/javascript/api/overview/azure/ai-projects-readme?view=azure-node-latest
  3. Therefore, your requested testing pattern “connect to Prompt Agents from frontend using API key only, without Entra ID” is not the supported solution. The supported options are:

Regarding your questions:

“For initial testing purposes, how can we connect to the agent from frontend and generate response using API Key only?”

By best practices, you cannot do that as a supported JS/TS Prompt Agent integration path in the new Foundry project model. Use a backend with Entra ID, or publish the agent and call the application endpoint with Azure credentials. - https://learn.microsoft.com/en-us/javascript/api/overview/azure/ai-projects-readme?view=azure-node-latest, https://learn.microsoft.com/azure/foundry/agents/how-to/publish-responses

We don’t want to set up Entra ID / other authentication methods for this testing.

Then do not test Prompt Agents directly from the frontend. Either use a lightweight backend/broker now, or switch the test to plain /openai/v1/responses model inference with API key, but that is not equivalent to Prompt Agent runtime testing. - https://learn.microsoft.com/en-us/azure/foundry/how-to/develop/sdk-overview, https://learn.microsoft.com/en-us/azure/foundry/openai/how-to/responses

Can’t we do the same as Assistants using API key?

Not in the same way. The new platform’s documented JS project-agent path requires Entra ID, and published agent apps also use Azure credentials. The architecture changed from Assistants API to Responses API + projects/agent versions/applications. https://learn.microsoft.com/en-us/azure/foundry/what-is-foundry, https://learn.microsoft.com/en-us/javascript/api/overview/azure/ai-projects-readme?view=azure-node-latest, https://learn.microsoft.com/azure/foundry/agents/how-to/publish-responses

I hope this is helpful! Do not hesitate to let me know if you have any other questions, steps or clarifications.


Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.