You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

隐式流下从Microsoft Entra ID获取含API Scope的JWT及URL配置

问题描述

Azure中存在一个应用注册,其Client ID为00001111-aaaa-2222-bbbb-3333cccc4444,目标Scope为api://3f4c1d35-3161-4c45-b5ec-ff7be4e89473/access_as_user,重定向URI为https://jwt.ms。需要一个可在浏览器打开、重定向至https://jwt.ms后能显示包含该Scope的JWT的URL。

此前尝试的URL返回的ID Token中不包含目标Scope,原因是使用了response_type=id_token——ID Token仅用于身份认证,不会携带API访问的Scope信息,需获取Access Token才能包含对应Scope。

正确的授权URL

使用OAuth2隐式授权流,将response_type设置为token,即可直接在浏览器中获取包含目标Scope的Access Token:

https://login.microsoftonline.com/{tenant}/oauth2/v2.0/authorize?
client_id=00001111-aaaa-2222-bbbb-3333cccc4444
&response_type=token
&redirect_uri=https%3A%2F%2Fjwt.ms
&scope=api%3A%2F%2F3f4c1d35-3161-4c45-b5ec-ff7be4e89473%2Faccess_as_user
&response_mode=fragment
&state=12345

说明:

  • 将{tenant}替换为你的租户ID或租户域名(如contoso.onmicrosoft.com)
  • response_type=token指定获取Access Token,该Token会包含请求的Scope信息
  • 若需同时获取ID Token和Access Token,可设置response_type=id_token token,此时返回的Access Token仍会包含目标Scope
Azure CLI相关命令

若使用Azure CLI获取包含该Scope的Access Token,可执行以下命令:

az login --scope api://3f4c1d35-3161-4c45-b5ec-ff7be4e89473/access_as_user
az account get-access-token --resource "api://3f4c1d35-3161-4c45-b5ec-ff7be4e89473" --scope "api://3f4c1d35-3161-4c45-b5ec-ff7be4e89473/access_as_user" --query accessToken

内容的提问来源于stack exchange,提问作者Kaarlo Räihä

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 04:34:59