## graph.Certificate


A certificate authenticates an Entra app registration with a certificate instead of a secret.


Usage

``` python
graph.Certificate(
    tenant_id,
    client_id,
    pfx=None,
    passphrase=None,
    private_key=None,
    thumbprint=None
)
```


It takes one of the two forms `msal` accepts: `pfx` with an optional `passphrase`, or `private_key` and `thumbprint` together. Any other combination raises `TypeError`. Prefer `pfx`, because `msal` deprecates the second form for its SHA-1 thumbprint. See ADR-0011.


## Attributes


`tenant_id: str`  
The directory the app is registered in, as a GUID or a domain.

`client_id: str`  
The app's application ID.

`pfx: Path | None`  
A PKCS \#12 file that holds the private key and the certificate. [connect()](Backend.md#epistole.Backend.connect) reads it.

`passphrase: str | None`  
The passphrase of an encrypted `pfx`. It is not in the `repr`.

`private_key: str | None`  
The private key, in unencrypted PEM. It is not in the `repr`.

`thumbprint: str | None`  
The certificate's SHA-1 thumbprint, in hex.


## Methods

| Name | Description |
|----|----|
| [__post_init__()](#__post_init__) | Raise `TypeError` unless the fields hold exactly one complete form (ADR-0011). |

------------------------------------------------------------------------


#### \_\_post_init\_\_()


Raise `TypeError` unless the fields hold exactly one complete form (ADR-0011).


Usage

``` python
__post_init__()
```
