✨ Create Azure export storage with SPI authentication
Create an Azure export storage connection with Service Principal or workload-identity authentication to store annotations. Supports auth_mode=service_principal (default; requires tenant_id, client_id, and client_secret) and auth_mode=workload_identity (secretless; client_secret must be omitted, tenant_id is not required, optional client_id selects a user-assigned managed identity). GET responses never include client_secret.
Authentication
The token (or API key) must be passed as a request header. You can find your user token on the User Account page in Label Studio. Example:
curl https://label-studio-host/api/projects -H “Authorization: Token [your-token]”Request
Authentication mode. service_principal uses a client secret. workload_identity uses constrained DefaultAzureCredential (workload identity + managed identity only). Defaults to service_principal.
service_principal- Service Principalworkload_identity- Workload identity
For service_principal: Azure app registration client ID. For workload_identity: optional user-assigned managed identity client ID.
Azure Blob Service Principal client secret. Required when auth_mode is service_principal (or omitted). Must be omitted when auth_mode is workload_identity.
initialized- Initializedqueued- Queuedin_progress- In progressfailed- Failedcompleted- Completedcompleted_with_errors- Completed with errors
Azure Tenant ID. Required for service_principal; not used for workload_identity.
User Delegation Key (Backend)
Response
Authentication mode. service_principal uses a client secret. workload_identity uses constrained DefaultAzureCredential (workload identity + managed identity only). Defaults to service_principal.
service_principal- Service Principalworkload_identity- Workload identity
For service_principal: Azure app registration client ID. For workload_identity: optional user-assigned managed identity client ID.
Azure Blob Service Principal client secret. Required when auth_mode is service_principal (or omitted). Must be omitted when auth_mode is workload_identity.
initialized- Initializedqueued- Queuedin_progress- In progressfailed- Failedcompleted- Completedcompleted_with_errors- Completed with errors
Azure Tenant ID. Required for service_principal; not used for workload_identity.
User Delegation Key (Backend)