Stack SpendDocs

Azure

Connect your Azure subscriptions to StackSpend via the Cost Management Query API.

What StackSpend tracks

StackSpend connects to the Azure Cost Management Query API and pulls spend daily at the subscription, service, and resource-group level. Tag-based attribution is included where tags are present on resources. Up to 90 days of history is loaded on first sync.

LatencyHistoricalSetup time
Daily90 days5 min

What's included

StackSpend uses Azure's Actual Cost, summed daily by subscription, service, and resource group at your negotiated/effective prices (including reservation and savings-plan effects). This matches the Azure portal's Cost Analysis → Actual cost view. Figures are pre-tax and exclude tax, support charges, and credits. A connection can cover a single subscription, a management group (all subscriptions in the tenant), or a billing account.

Spend is pre-tax.

Like the Azure portal's Cost Analysis, StackSpend reports pre-tax costs. Tax isn't available from Azure's cost API — it appears only on the monthly invoice — so StackSpend's Azure total reads lower than a tax-inclusive invoice by the amount of tax.

Authentication

StackSpend reads cost data with the Cost Management Reader role — read-only, with no access to your resources or data. You authorize the StackSpend app in your tenant and assign it that role: there is no app registration to create and no client secret to manage or rotate.

1

Authorize the StackSpend app

In StackSpend, go to SettingsIntegrations Azure, leave the method on Authorize StackSpend (recommended), and click Connect.

Sign in as a tenant administrator and approve the consent screen. This adds StackSpend as a service principal in your tenant — there is nothing to create, and nothing that expires. After approving, you'll be shown your Tenant ID; copy it.

Admin consent is required once.A Microsoft Entra administrator must approve the consent screen the first time. After that, the StackSpend service principal exists in your tenant permanently (until you remove it).
2

Assign the Cost Management Reader role

Open Subscriptions in the Azure Portal, select your subscription, then go to Access control (IAM)Add role assignment.

Search for the Cost Management Reader role, select it, and click Next. Click Select members, search for StackSpend Azure Provider, select the record, click Select, then Review + assign. Assign it at the subscription scope (a resource-group assignment won't make the subscription discoverable).

Confirm the assignment landed.You can verify the role reached the right app under Enterprise applications → StackSpend. Role assignments can take a minute or two to propagate.
3

Connect in StackSpend

Back in StackSpend, your Tenant ID is filled in automatically from the consent step. Pick your subscription from the Subscription dropdown (StackSpend lists the ones it can read) — or paste a Subscription ID — then click Test and Connect to begin the first sync.

Your Tenant ID is also available any time in Microsoft Entra ID → Overview.

Any issues? Contact support@stackspend.app.

Frequently asked questions

What Azure access does StackSpend need?

StackSpend needs a read-only service principal assigned the Cost Management Reader role, which lets it read cost data through the Cost Management Query API. You authorize the StackSpend app in your tenant rather than creating an app registration or managing a client secret.

Is the Azure connection read-only?

Yes, the Cost Management Reader role is strictly read-only and grants no access to your resources or data. StackSpend only reads cost figures and never writes to your Azure environment.

Can StackSpend track multiple subscriptions?

Yes, a connection can cover a single subscription, a management group spanning all subscriptions in the tenant, or a billing account. Setup takes about 5 minutes and the first sync loads up to 90 days of history.

Why don't I see cost data yet?

Role assignments can take a minute or two to propagate after you assign Cost Management Reader, so a subscription may not be discoverable immediately. Make sure the role was assigned at the subscription scope rather than a resource group, then re-test the connection.

StackSpend Docs