myapp.azurewebsites.net). Polysync builds the invoke URL
as https://{Function App URL}/api/{route-or-function-name}.Function Key is optional: set it only when the Authentication Method is
Function Key. It is sent as the x-functions-key header on invokes when
present and ignored otherwise — store it in a Secret Vault and reference it
rather than entering it directly.
The three identity-based auth methods (Polysync Service Principal, Service Principal, Certificate) can perform management operations — list/import functions (Get Jobs), Sync Parameters and Test Connectivity — because they can obtain a management-plane (ARM) token.
Function Key and Anonymous are execution-only: they have no ARM credential, so Get Jobs, Sync Parameters and the platform-job dropdown are unavailable and Test Connectivity fails by design with:
Function Key and Anonymous authentication cannot be used for management operations. Use Service Principal, Certificate, or Polysync Service Principal authentication to manage Azure Function App via the Management API.
Executions (Execute Now and scheduled runs) still work on those platforms — create their jobs manually (name → platform → job type → External Id). Their Test Connectivity runs an invoke-path reachability probe instead of the management check: any HTTP response from the app host — even 401/404 — proves DNS/TLS/host reachability before the first run.
Polysync's multi-tenant SaaS runs in its own Entra tenant, and a managed
identity is bound to the customer's tenant — it cannot be assumed
trans-tenant. The product's identity story is the Polysync Service
Principal, which the customer grants per resource; Service Principal and
Certificate cover the customer-managed alternatives. A Managed Identity Client Id attribute that older environments may still show has been removed
by migration 014_Remove_AzureFunctions_ManagedIdentityClientId_Attribute.sql.
Timer, queue, blob, Event Hub and Service Bus triggered functions are
discovered alongside HTTP triggers and can be run on demand through the
Functions admin API (POST /admin/functions/{name}). Polysync resolves a
job's trigger from the function's bindings at dispatch on management-capable
auth methods; execution-only platforms fall back to the job's HTTP Method
attribute. Two things to know:
Orchestration triggers cannot be invoked directly — start them through
your Durable client (HTTP starter) function, which returns the
statusQueryGetUri protocol Polysync polls. A running Durable orchestration
can be terminated by the provider (Durable HTTP management API); the
operator-facing Cancel wiring is still pending platform-wide (ENH-050).
Azure Functions exposes a single Polysync job type. See the dedicated page for parameter handling, output binding, execution flow, monitor URL, and troubleshooting: