---
title: Build on Your App
description: Add capabilities to your first Forge application in a guided sequence.
moved_from:
  - guides/tutorials/build-on-your-app.md
---

# Build on Your App

You've created your first Forge application — now add real capabilities. Follow this guided path to evolve your project from a starter API into a production-ready service.

[TOC]

---

## 🛤️ Guided Path

Work through these steps in order. Each builds on the previous, but you can skip ahead if a capability isn't relevant to your project.

---

### 1. Add Authentication

Secure your API with Entra ID (corporate) or Okta (external) authentication.

| | |
|---|---|
| **What you'll do** | Configure authentication providers and protect your endpoints |
| **Guide** | [Security Overview](../../build/identity/index.md) |
| **Deployment config** | [Deployment Workflow](../../build/identity/configuration/deployment-workflow.md) |
| **Difficulty** | Intermediate |

---

### 2. Connect to Data

Add a database or storage backend to persist your application data.

| | |
|---|---|
| **What you'll do** | Provision and connect to Cosmos DB or Azure Blob Storage |
| **Guide (Cosmos DB)** | [Cosmos DB NoSQL](../../build/data/cosmos-nosql.md) |
| **Guide (Blob Storage)** | [Blob Storage](../../build/data/storage-account.md) |
| **Foundry example** | [Blob Storage Integration](../../build/examples/aspire-blobstorage.md) |
| **Difficulty** | Intermediate |

---

### 3. Call External APIs

Integrate with downstream services using generated Kiota clients and proper scope configuration.

| | |
|---|---|
| **What you'll do** | Add a Kiota-generated API client with authentication |
| **Guide** | [Downstream API Calls](../../build/apis/calling-apis.md) |
| **Difficulty** | Intermediate |

---

### 4. Add Eventing

Publish and subscribe to domain events using Azure Service Bus.

| | |
|---|---|
| **What you'll do** | Create an event publisher or subscribe to events from other services |
| **Guide (Publishing)** | [Event Service](../../build/eventing/event-service.md) |
| **Guide (Subscribing)** | [Event Subscriptions](../../build/eventing/event-subscription.md) |
| **Foundry example** | [Event Orchestration Example](../../build/examples/event-orchestration.md) |
| **Difficulty** | Intermediate |

---

### 5. Configure Feature Flags

Control feature rollout at runtime without redeploying your application.

| | |
|---|---|
| **What you'll do** | Define feature flags and gate endpoints or UI behind them |
| **Guide** | [Feature Flags](../../build/config/feature-flags.md) |
| **Foundry example** | `foundry/dotnet/feature-flags/` |
| **Difficulty** | Beginner |

---

### 6. Deploy Your App

If you haven't yet, follow ["From Local to Deployed"](index.md#step-6-from-local-to-deployed) in the tutorial to publish your project and create its Azure DevOps repository and pipelines.

From there, use `aspire publish` to regenerate pipeline YAML whenever you add or change services, security, or infrastructure in your AppHost — then commit and push to deploy.

| | |
|---|---|
| **What you'll do** | Use `aspire publish` to regenerate Azure DevOps pipeline YAML as your AppHost evolves, then commit and push to deploy |
| **Guide** | [Aspire Publish](../../build/deploy/aspire-publish.md) |
| **Guide (Zero-downtime)** | [Blue-Green Deployments](../../build/deploy/blue-green-deployments.md) |
| **Difficulty** | Advanced |

---

### 7. Observe in Production

Monitor your application with OpenTelemetry traces, metrics, and logs in Dynatrace.

| | |
|---|---|
| **What you'll do** | Verify telemetry is flowing and use dashboards for troubleshooting |
| **Guide** | [Observability](../../build/observability/index.md) |
| **Reference (Diagnostics)** | [Diagnostic IDs](../../reference/diagnostics/index.md) |
| **Difficulty** | Beginner |

---

## 💡 Tips

- **Start with authentication** if your API will be accessed by users or other services — it's easier to add early than retrofit later.
- **Feature flags are low-effort** and can be added at any point in your development lifecycle.
- **Observability is automatic** — Forge applications emit OpenTelemetry data by default via Aspire. Focus on learning how to read the dashboards rather than configuration.

---

## 🔭 What's Next

Once you've worked through the capabilities above, there's more of the platform to explore:

- **See the full CLI reference:** [`saif` CLI Reference](../../reference/dotnet/SAIF.Platform.CLI/commands.md) documents the command surface.
- **Discover other Forge services** — Use `saif service search <name>` (or the `search_services` MCP tool if you have `saif agent init` set up) to find existing services and their repositories before building something new from scratch.
- **Browse example implementations:** The [experimental examples](../../build/examples/index.md) demonstrate common integration patterns.

---

## 📚 Related Documentation

- [Your First Forge Application](index.md) — The tutorial that brought you here
- [Build](../../build/index.md) - Development how-to guides
- [Identity](../../build/identity/index.md) - Authentication and authorization
