Connect Azure OpenAI Service
Connect Azure OpenAI Service to see what a subscription spends on it, beside the rest of your AI spend. Flowstate reads it from Azure Cost Management through a federated credential, so you don’t share a client secret.
You need access to connect AI providers. Ask your Flowstate admin. You also need someone who can manage app registrations in Microsoft Entra.
Before you start
- An app registration in Microsoft Entra with a federated credential for Flowstate, and Cost Management Reader on the subscription you want to track. Your technical team sets these up. See For your technical team.
- On an Enterprise Agreement: an Enterprise Administrator must also switch on Account owners can view charges. Without it, Flowstate finds no spend.
Connect Azure OpenAI Service
- Go to Settings → Integrations, select Browse catalog and open Azure OpenAI Service.
- Under How to connect, select Use this route.
- Enter the Directory (tenant) ID, Application (client) ID and Subscription ID.
- Optional: to see spend by team, product or anything else you tag, enter a resource tag name, such as
team, in Split spend by tag (optional). - Select Verify and connect.
Check it’s working
The connection is listed under Connected keys with the status Working. See the spend in Agent insights.
What Flowstate brings in
- Billed cost by resource and service, each day, for the subscription you enter.
- A total for the subscription. Azure doesn’t report cost per person.
- If you chose a tag, each day’s spend split by that tag’s value. Untagged spend stays as one line.
- Flowstate syncs every hour, and brings in your history when you first connect.
If something’s not right
The connection works but no spend appears. On an Enterprise Agreement, check Account owners can view charges is on.
Spend isn’t split by your tag, and the connection shows a warning. Azure didn’t return that tag for the subscription’s spend. Check the tag name is spelt exactly as on your resources. Until it matches, spend stays as one line and the totals are unaffected.
The connection fails. The federated credential or the role assignment is wrong. Select Show what the provider said to see Azure’s error.
For your technical team
- Ask your Flowstate contact for the issuer, subject and audience for your organisation.
- In Microsoft Entra, open the app registration, then Certificates & secrets → Federated credentials, and add a credential with those values.
- In the Azure portal, open the subscription, go to Access control (IAM) and give the app Cost Management Reader.