Redgate Flyway

Microsoft Entra Interactive Resolver

This is a property resolver which applies when trying to connect to Microsoft Azure SQL Server databases using interactive authentication. Connections made using this form of authentication without this resolver will have the default behavior of prompting for login on every database call. When using this resolver, with the appropriate Azure setup, documented here, you can connect once and your token will be cached and reused for a period of time.

This resolver can be referenced as either entraId or azureAdInteractive; the two names are interchangeable.

The initial sign-in is interactive and opens a browser for you to authenticate, so this resolver is not recommended for use in CI systems or other non-interactive workflows. Use one of the non-interactive Microsoft Entra methods instead, such as a service principal or a managed identity, described in Connecting to environments. Those methods are handled by the database driver and do not use the token cache described below.

Token cache requirements

So that it does not prompt for login on every database call, this resolver caches your token using the operating system's secure credential storage, by way of the Microsoft Authentication Library (MSAL). That storage has to be present and working, otherwise the resolver fails when it initializes the cache.

The cache is written to flyway_msal_tokenCache.dat in the Redgate/flyway folder of your home directory. If a cached token stops working, deleting this file forces a fresh sign-in.

Windows

The Data Protection API (DPAPI) is used. No additional setup is required.

Mac

The Mac keychain is used. No additional setup is required.

Linux

Libsecret is used, and it must be able to reach a working Secret Service implementation. All of the following are required:

  • the Libsecret library is installed (for example, the libsecret-1-0 package on Debian and Ubuntu)
  • a Secret Service provider, such as gnome-keyring, is installed and running
  • a D-Bus session bus is available for Libsecret to reach that provider over
  • the keyring it stores into is unlocked

Installing Libsecret by itself is not enough, because without a running, unlocked keyring on a session bus there is nothing for it to talk to. This is the usual failure on headless machines and CI agents, which by default tend to have neither a D-Bus session nor a keyring daemon. Getting it working there generally means installing a keyring daemon, starting it under a D-Bus session that lasts for the duration of the Flyway invocation, and unlocking it with a known password.

Settings

Setting Required Type Description
tenantId Yes String The Microsoft Entra tenant id.
clientId Yes String The Microsoft Entra client id.

Usage

Flyway Desktop

This can be set from the connection dialog.

TOML Configuration File

[environments.development]
url = "jdbc:sqlserver://mfa-testing.database.windows.net:1433;databaseName=MyDatabase"

[environments.development.jdbcProperties]
accessToken = "${entraId.token}"

[environments.development.resolvers.entraId]
tenantId = "{some GUID}"
clientId = "{some other GUID}"

This documentation contains proprietary information and is protected by copyright law.
Copyright © 2026 Red Gate Software Limited. All rights reserved


Didn't find what you were looking for?