azure-mgmt-apimanagement-py
Azure API Management SDK for Python. Use for managing APIM services, APIs, products, subscriptions, and policies. Triggers: "azure-mgmt-apimanagement", "ApiManagementClient", "APIM", "API gateway", "API Management".
Install
npx skills add https://github.com/microsoft/skills/tree/main/.github/plugins/azure-sdk-python/skills/azure-mgmt-apimanagement-py
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install microsoft-skills@llmmart
git clone https://github.com/microsoft/skills.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole microsoft/skills collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Azure API Management SDK for Python
Manage Azure API Management services, APIs, products, and policies.
Installation
pip install azure-mgmt-apimanagement
pip install azure-identity
Environment Variables
AZURE_SUBSCRIPTION_ID=your-subscription-id # Required for all auth methods
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production
Authentication & Lifecycle
🔑 Two rules apply to every code sample below:
- Prefer
DefaultAzureCredential. It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.
- Local dev:
DefaultAzureCredentialworks as-is.- Production: set
AZURE_TOKEN_CREDENTIALS=prod(orAZURE_TOKEN_CREDENTIALS=<specific_credential>) to constrain the credential chain to production-safe credentials.- Wrap every client in a context manager so HTTP transports, sockets, and token caches are released deterministically:
- Sync:
with <Client>(...) as client:- Async:
async with <Client>(...) as client:andasync with DefaultAzureCredential() as credential:(fromazure.identity.aio)Snippets may abbreviate this setup, but production code should always follow both rules.
from azure.identity import DefaultAzureCredential
from azure.mgmt.apimanagement import ApiManagementClient
import os
with ApiManagementClient(
credential=DefaultAzureCredential(),
subscription_id=os.environ["AZURE_SUBSCRIPTION_ID"]
) as client:
# Use `client` for all subsequent operations (see examples below)
...
Create APIM Service
from azure.mgmt.apimanagement.models import (
ApiManagementServiceResource,
ApiManagementServiceSkuProperties,
SkuType
)
service = client.api_management_service.begin_create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
parameters=ApiManagementServiceResource(
location="eastus",
publisher_email="admin@example.com",
publisher_name="My Organization",
sku=ApiManagementServiceSkuProperties(
name=SkuType.DEVELOPER,
capacity=1
)
)
).result()
print(f"Created APIM: {service.name}")
Import API from OpenAPI
from azure.mgmt.apimanagement.models import (
ApiCreateOrUpdateParameter,
ContentFormat,
Protocol
)
api = client.api.begin_create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
api_id="my-api",
parameters=ApiCreateOrUpdateParameter(
display_name="My API",
path="myapi",
protocols=[Protocol.HTTPS],
format=ContentFormat.OPENAPI_JSON,
value='{"openapi": "3.0.0", "info": {"title": "My API", "version": "1.0"}, "paths": {"/health": {"get": {"responses": {"200": {"description": "OK"}}}}}}'
)
).result()
print(f"Imported API: {api.display_name}")
Import API from URL
api = client.api.begin_create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
api_id="petstore",
parameters=ApiCreateOrUpdateParameter(
display_name="Petstore API",
path="petstore",
protocols=[Protocol.HTTPS],
format=ContentFormat.OPENAPI_LINK,
value="https://petstore.swagger.io/v2/swagger.json"
)
).result()
List APIs
apis = client.api.list_by_service(
resource_group_name="my-resource-group",
service_name="my-apim"
)
for api in apis:
print(f"{api.name}: {api.display_name} - {api.path}")
Create Product
from azure.mgmt.apimanagement.models import ProductContract
product = client.product.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
product_id="premium",
parameters=ProductContract(
display_name="Premium",
description="Premium tier with unlimited access",
subscription_required=True,
approval_required=False,
state="published"
)
)
print(f"Created product: {product.display_name}")
Add API to Product
client.product_api.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
product_id="premium",
api_id="my-api"
)
Create Subscription
from azure.mgmt.apimanagement.models import SubscriptionCreateParameters
subscription = client.subscription.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
sid="my-subscription",
parameters=SubscriptionCreateParameters(
display_name="My Subscription",
scope=f"/products/premium",
state="active"
)
)
print(f"Subscription key: {subscription.primary_key}")
Set API Policy
from azure.mgmt.apimanagement.models import PolicyContract
policy_xml = """
<policies>
<inbound>
<rate-limit calls="100" renewal-period="60" />
<set-header name="X-Custom-Header" exists-action="override">
<value>CustomValue</value>
</set-header>
</inbound>
<backend>
<forward-request />
</backend>
<outbound />
<on-error />
</policies>
"""
client.api_policy.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
api_id="my-api",
policy_id="policy",
parameters=PolicyContract(
value=policy_xml,
format="xml"
)
)
Create Named Value (Secret)
from azure.mgmt.apimanagement.models import NamedValueCreateContract
named_value = client.named_value.begin_create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
named_value_id="backend-api-key",
parameters=NamedValueCreateContract(
display_name="Backend API Key",
value="secret-key-value",
secret=True
)
).result()
Create Backend
from azure.mgmt.apimanagement.models import BackendContract
backend = client.backend.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
backend_id="my-backend",
parameters=BackendContract(
url="https://api.backend.example.com",
protocol="http",
description="My backend service"
)
)
Create User
from azure.mgmt.apimanagement.models import UserCreateParameters
user = client.user.create_or_update(
resource_group_name="my-resource-group",
service_name="my-apim",
user_id="newuser",
parameters=UserCreateParameters(
email="user@example.com",
first_name="John",
last_name="Doe"
)
)
Operation Groups
| Group | Purpose |
|---|---|
api_management_service |
APIM instance management |
api |
API operations |
api_operation |
API operation details |
api_policy |
API-level policies |
product |
Product management |
product_api |
Product-API associations |
subscription |
Subscription management |
user |
User management |
named_value |
Named values/secrets |
backend |
Backend services |
certificate |
Certificates |
gateway |
Self-hosted gateways |
Best Practices
- Pick sync OR async and stay consistent. Do not mix
azure.xxxsync clients withazure.xxx.aioasync clients in the same call path. Choose one mode per module. - Always use context managers for clients and async credentials. Wrap every client in
with Client(...) as client:(sync) orasync with Client(...) as client:(async). For asyncDefaultAzureCredentialfromazure.identity.aio, also useasync with credential:so tokens and transports are cleaned up. - Use named values for secrets and configuration
- Apply policies at appropriate scopes (global, product, API, operation)
- Use products to bundle APIs and manage access
- Enable Application Insights for monitoring
- Use backends to abstract backend services
- Version your APIs using APIM's versioning features
Reference Files
| File | Contents |
|---|---|
| references/capabilities.md | Additional non-hero capabilities, operation-group coverage, and production checklists. |
| references/non-hero-scenarios.md | Dedicated non-hero examples for secondary/advanced scenarios. |
Files (skills)
-
references
-
capabilities.md 2.2 KB
# azure-mgmt-apimanagement-py capability coverage **SDK/package**: `azure-mgmt-apimanagement` This index maps hero scenarios in `SKILL.md` and links non-hero scenarios documented in dedicated reference files. ## Hero scenarios covered in SKILL.md - `Create APIM Service` - `Import API from OpenAPI` - `Import API from URL` - `List APIs` ## Non-hero scenarios - `Create Product`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#create-product`](non-hero-scenarios.md#create-product) - `Add API to Product`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#add-api-to-product`](non-hero-scenarios.md#add-api-to-product) - `Create Subscription`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#create-subscription`](non-hero-scenarios.md#create-subscription) - `Set API Policy`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#set-api-policy`](non-hero-scenarios.md#set-api-policy) - `Create Named Value (Secret)`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#create-named-value-secret`](non-hero-scenarios.md#create-named-value-secret) - `Create Backend`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#create-backend`](non-hero-scenarios.md#create-backend) - `Create User`: Dedicated example and implementation notes. See: [`non-hero-scenarios.md#create-user`](non-hero-scenarios.md#create-user) - `Operation Groups`: | Group | Purpose | See: [`non-hero-scenarios.md#operation-groups`](non-hero-scenarios.md#operation-groups) ## Related deep-dive references - [`non-hero-scenarios.md`](non-hero-scenarios.md): Dedicated non-hero examples and implementation notes. ## API breadth checklist - Verify client/auth mode for the environment before coding. - Confirm operation-group/method names against current Microsoft Learn API reference. - For Python SDKs with both sync and async clients, document both forms without a blanket preference. - Include cleanup/delete paths for created resources in examples. - Prefer idempotent create/update operations where available. - Validate paging/LRO/error-handling patterns for production paths. -
non-hero-scenarios.md 3.7 KB
# azure-mgmt-apimanagement-py non-hero scenarios These scenarios are intentionally separate from hero flows in `SKILL.md`. They cover secondary/advanced patterns typically used after the primary end-to-end path is working. ## Create Product ```python from azure.mgmt.apimanagement.models import ProductContract product = client.product.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", product_id="premium", parameters=ProductContract( display_name="Premium", description="Premium tier with unlimited access", subscription_required=True, approval_required=False, state="published" ) ) print(f"Created product: {product.display_name}") ``` ## Add API to Product ```python client.product_api.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", product_id="premium", api_id="my-api" ) ``` ## Create Subscription ```python from azure.mgmt.apimanagement.models import SubscriptionCreateParameters subscription = client.subscription.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", sid="my-subscription", parameters=SubscriptionCreateParameters( display_name="My Subscription", scope=f"/products/premium", state="active" ) ) print("Subscription created") ``` ## Set API Policy ```python from azure.mgmt.apimanagement.models import PolicyContract policy_xml = """ <policies> <inbound> <rate-limit calls="100" renewal-period="60" /> <set-header name="X-Custom-Header" exists-action="override"> <value>CustomValue</value> </set-header> </inbound> <backend> <forward-request /> </backend> <outbound /> <on-error /> </policies> """ client.api_policy.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", api_id="my-api", policy_id="policy", parameters=PolicyContract( value=policy_xml, format="xml" ) ) ``` ## Create Named Value (Secret) ```python import os from azure.mgmt.apimanagement.models import NamedValueCreateContract named_value = client.named_value.begin_create_or_update( resource_group_name="my-resource-group", service_name="my-apim", named_value_id="backend-api-key", parameters=NamedValueCreateContract( display_name="Backend API Key", value=os.environ["BACKEND_API_KEY"], secret=True ) ).result() ``` ## Create Backend ```python from azure.mgmt.apimanagement.models import BackendContract backend = client.backend.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", backend_id="my-backend", parameters=BackendContract( url="https://api.backend.example.com", protocol="http", description="My backend service" ) ) ``` ## Create User ```python from azure.mgmt.apimanagement.models import UserCreateParameters user = client.user.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", user_id="newuser", parameters=UserCreateParameters( email="user@example.com", first_name="John", last_name="Doe" ) ) ``` ## Operation Groups | Group | Purpose | |-------|---------| | `api_management_service` | APIM instance management | | `api` | API operations | | `api_operation` | API operation details | | `api_policy` | API-level policies | | `product` | Product management | | `product_api` | Product-API associations | | `subscription` | Subscription management | | `user` | User management | | `named_value` | Named values/secrets | | `backend` | Backend services | | `certificate` | Certificates | | `gateway` | Self-hosted gateways |
-
-
SKILL.md 8.7 KB
--- name: azure-mgmt-apimanagement-py description: | Azure API Management SDK for Python. Use for managing APIM services, APIs, products, subscriptions, and policies. Triggers: "azure-mgmt-apimanagement", "ApiManagementClient", "APIM", "API gateway", "API Management". license: MIT metadata: author: Microsoft version: "1.0.0" package: azure-mgmt-apimanagement --- # Azure API Management SDK for Python Manage Azure API Management services, APIs, products, and policies. ## Installation ```bash pip install azure-mgmt-apimanagement pip install azure-identity ``` ## Environment Variables ```bash AZURE_SUBSCRIPTION_ID=your-subscription-id # Required for all auth methods AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production ``` ## Authentication & Lifecycle > **🔑 Two rules apply to every code sample below:** > > 1. **Prefer `DefaultAzureCredential`.** It works locally (Azure CLI / VS Code / Developer CLI) and in Azure (managed identity, workload identity) with no code change. Avoid connection strings, account/API keys — they bypass Entra audit and rotation. > - Local dev: `DefaultAzureCredential` works as-is. > - Production: set `AZURE_TOKEN_CREDENTIALS=prod` (or `AZURE_TOKEN_CREDENTIALS=<specific_credential>`) to constrain the credential chain to production-safe credentials. > 2. **Wrap every client in a context manager** so HTTP transports, sockets, and token caches are released deterministically: > - Sync: `with <Client>(...) as client:` > - Async: `async with <Client>(...) as client:` **and** `async with DefaultAzureCredential() as credential:` (from `azure.identity.aio`) > > Snippets may abbreviate this setup, but production code should always follow both rules. ```python from azure.identity import DefaultAzureCredential from azure.mgmt.apimanagement import ApiManagementClient import os with ApiManagementClient( credential=DefaultAzureCredential(), subscription_id=os.environ["AZURE_SUBSCRIPTION_ID"] ) as client: # Use `client` for all subsequent operations (see examples below) ... ``` ## Create APIM Service ```python from azure.mgmt.apimanagement.models import ( ApiManagementServiceResource, ApiManagementServiceSkuProperties, SkuType ) service = client.api_management_service.begin_create_or_update( resource_group_name="my-resource-group", service_name="my-apim", parameters=ApiManagementServiceResource( location="eastus", publisher_email="admin@example.com", publisher_name="My Organization", sku=ApiManagementServiceSkuProperties( name=SkuType.DEVELOPER, capacity=1 ) ) ).result() print(f"Created APIM: {service.name}") ``` ## Import API from OpenAPI ```python from azure.mgmt.apimanagement.models import ( ApiCreateOrUpdateParameter, ContentFormat, Protocol ) api = client.api.begin_create_or_update( resource_group_name="my-resource-group", service_name="my-apim", api_id="my-api", parameters=ApiCreateOrUpdateParameter( display_name="My API", path="myapi", protocols=[Protocol.HTTPS], format=ContentFormat.OPENAPI_JSON, value='{"openapi": "3.0.0", "info": {"title": "My API", "version": "1.0"}, "paths": {"/health": {"get": {"responses": {"200": {"description": "OK"}}}}}}' ) ).result() print(f"Imported API: {api.display_name}") ``` ## Import API from URL ```python api = client.api.begin_create_or_update( resource_group_name="my-resource-group", service_name="my-apim", api_id="petstore", parameters=ApiCreateOrUpdateParameter( display_name="Petstore API", path="petstore", protocols=[Protocol.HTTPS], format=ContentFormat.OPENAPI_LINK, value="https://petstore.swagger.io/v2/swagger.json" ) ).result() ``` ## List APIs ```python apis = client.api.list_by_service( resource_group_name="my-resource-group", service_name="my-apim" ) for api in apis: print(f"{api.name}: {api.display_name} - {api.path}") ``` ## Create Product ```python from azure.mgmt.apimanagement.models import ProductContract product = client.product.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", product_id="premium", parameters=ProductContract( display_name="Premium", description="Premium tier with unlimited access", subscription_required=True, approval_required=False, state="published" ) ) print(f"Created product: {product.display_name}") ``` ## Add API to Product ```python client.product_api.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", product_id="premium", api_id="my-api" ) ``` ## Create Subscription ```python from azure.mgmt.apimanagement.models import SubscriptionCreateParameters subscription = client.subscription.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", sid="my-subscription", parameters=SubscriptionCreateParameters( display_name="My Subscription", scope=f"/products/premium", state="active" ) ) print(f"Subscription key: {subscription.primary_key}") ``` ## Set API Policy ```python from azure.mgmt.apimanagement.models import PolicyContract policy_xml = """ <policies> <inbound> <rate-limit calls="100" renewal-period="60" /> <set-header name="X-Custom-Header" exists-action="override"> <value>CustomValue</value> </set-header> </inbound> <backend> <forward-request /> </backend> <outbound /> <on-error /> </policies> """ client.api_policy.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", api_id="my-api", policy_id="policy", parameters=PolicyContract( value=policy_xml, format="xml" ) ) ``` ## Create Named Value (Secret) ```python from azure.mgmt.apimanagement.models import NamedValueCreateContract named_value = client.named_value.begin_create_or_update( resource_group_name="my-resource-group", service_name="my-apim", named_value_id="backend-api-key", parameters=NamedValueCreateContract( display_name="Backend API Key", value="secret-key-value", secret=True ) ).result() ``` ## Create Backend ```python from azure.mgmt.apimanagement.models import BackendContract backend = client.backend.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", backend_id="my-backend", parameters=BackendContract( url="https://api.backend.example.com", protocol="http", description="My backend service" ) ) ``` ## Create User ```python from azure.mgmt.apimanagement.models import UserCreateParameters user = client.user.create_or_update( resource_group_name="my-resource-group", service_name="my-apim", user_id="newuser", parameters=UserCreateParameters( email="user@example.com", first_name="John", last_name="Doe" ) ) ``` ## Operation Groups | Group | Purpose | |-------|---------| | `api_management_service` | APIM instance management | | `api` | API operations | | `api_operation` | API operation details | | `api_policy` | API-level policies | | `product` | Product management | | `product_api` | Product-API associations | | `subscription` | Subscription management | | `user` | User management | | `named_value` | Named values/secrets | | `backend` | Backend services | | `certificate` | Certificates | | `gateway` | Self-hosted gateways | ## Best Practices 1. **Pick sync OR async and stay consistent.** Do not mix `azure.xxx` sync clients with `azure.xxx.aio` async clients in the same call path. Choose one mode per module. 2. **Always use context managers for clients and async credentials.** Wrap every client in `with Client(...) as client:` (sync) or `async with Client(...) as client:` (async). For async `DefaultAzureCredential` from `azure.identity.aio`, also use `async with credential:` so tokens and transports are cleaned up. 3. **Use named values** for secrets and configuration 4. **Apply policies** at appropriate scopes (global, product, API, operation) 5. **Use products** to bundle APIs and manage access 6. **Enable Application Insights** for monitoring 7. **Use backends** to abstract backend services 8. **Version your APIs** using APIM's versioning features ## Reference Files | File | Contents | |------|----------| | [references/capabilities.md](references/capabilities.md) | Additional non-hero capabilities, operation-group coverage, and production checklists. | | [references/non-hero-scenarios.md](references/non-hero-scenarios.md) | Dedicated non-hero examples for secondary/advanced scenarios. |
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.