Runtime
Environment contract
- Environment
- live
- Provider
- azure-entra (simulated)
- Persistence
- redis
- Protocol
- v1
- Media type
application/vnd.mutandae.v1+json
Public demo · configuration and integration
Explore the simulator safely, or open a short-lived session against an Azure / Entra tenant you control. Real-tenant credentials never enter Redis, snapshots, events, logs, or HTML.
Runtime
application/vnd.mutandae.v1+jsonDemo mode
The runtime configuration itself is read-only. The optional integration is an isolated, expiring operator session—not a deployment setting.
Optional · bring your own tenant
Mutandae uses Microsoft Graph application APIs with the least-privileged application permission required for the operations below. It checks Graph ownership before every mutation.
Application.ReadWrite.OwnedBy
Use an existing Azure Key Vault to retrieve a generated secret after Graph's one-time response expires.
Key Vault Secrets Officer (existing vault, data plane)Key Vault Secrets User (read only) or Secrets Officer⚠ The client secret is accepted only over HTTPS and held in memory for a short session.
⚠ Microsoft Graph returns a generated secret only once; without a vault you must copy it immediately.
⚠ Invalidate this integration client secret in Entra ID after the demo and remove its consent if no longer needed.
⚠ Mutandae never stores customer credentials, Graph tokens, or secret plaintext in Redis, snapshots, events, logs, or HTML.
Ephemeral session
Continue the walkthrough
Return to the dashboard to inspect synthetic identities, rotate a credential, and follow the correlated lifecycle events. The API discovery document is available at /api/v1/.