You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAUTH2 Proxy报错‘id token issued by a different provider’求助

问题

已在AKS中部署OAuth2 Proxy,采用OIDC作为身份提供商,部署参数如下:

- --http-address=0.0.0.0:4180
- --metrics-address=0.0.0.0:44180
- --azure-tenant=xxx
- --cookie-refresh=5m
- --email-domain=*
- --oidc-issuer-url=https://login.microsoftonline.com/xxx/v2.0
- --pass-authorization-header=true
- --provider=oidc
- --skip-jwt-bearer-tokens=true
- --set-authorization-header=true
- --upstream=file:///dev/null
- --config=/etc/oauth2_proxy/oauth2_proxy.cfg

通过以下命令从Azure应用注册获取token:

curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d 'client_id=xxxx&scope=xxxx/.default&client_secret=xxxx&grant_type=client_credentials' 'https://login.microsoftonline.com/xxx/oauth2/v2.0/token'

但OAuth2 Proxy中出现如下错误:

Error retrieving session from token in Authorization header: [unable to verify bearer token, oidc: id token issued by a different provider, expected "https://login.microsoftonline.com/xxx/v2.0" got "https://sts.windows.net/xxxx/"]

原因分析

这个错误的核心是token中的issuer(发行方)地址与OAuth2 Proxy配置的oidc-issuer-url不匹配。

具体细节:

  • Azure AD的v2令牌端点返回的client_credentials模式token中,iss字段值固定为旧格式的https://sts.windows.net/xxx/,而非你配置的v2端点地址https://login.microsoftonline.com/xxx/v2.0。
  • OAuth2 Proxy在验证token时会严格校验issuer的一致性,两者不匹配就会触发验证失败。

解决方向:

  • 修改OAuth2 Proxy的oidc-issuer-url参数为https://sts.windows.net/xxx/;
  • 或者添加--oidc-allowed-issuers参数,同时允许https://login.microsoftonline.com/xxx/v2.0和https://sts.windows.net/xxx/两个issuer地址。

内容的提问来源于stack exchange,提问作者Container-Man

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 09:37:14