An Azure Function app runs your code and, when one is configured, carries a managed identity. Code execution in the app (through a deploy, a dependency, or an injection) mints that identity's token; separately, the app's function and host keys authorize invoking protected functions and the admin endpoints.
What folds in here#
- Managed identity: minting and using the function app's managed-identity token.
- Function keys: recovering host and function keys to invoke protected endpoints.