为何Azure Graph API拒绝同时含密钥与密码凭据的应用创建请求?
使用Azure Graph API创建应用时同时添加两类凭据触发400错误
在调用POST https://graph.microsoft.com/v1.0/applications/创建Azure应用,同时在请求体中包含passwordCredentials(密码凭据)和keyCredentials(密钥凭据)时,API返回400 Bad Request,错误提示为body should not contain KeyId。
触发错误的请求体示例:
{ "displayname":"sample", "keyCredentials": [ { "customKeyIdentifier": "=", "displayName": "", "endDateTime": "", "key": "", "keyId": "", "startDateTime": "", "type": "", "usage": "" } ], "passwordCredentials": [ { "customKeyIdentifier": "", "displayName": "", "endDateTime": "", "keyId": "", "secretText": "", "startDateTime": "" } ] }
单独添加keyCredentials的请求可以正常返回200,后续也能正常更新密钥凭据,示例如下:
{ "displayName": "abcd", "keyCredentials": [ { // KeyCredentials 相关信息 } ] }
问题原因及解决方法
问题出在passwordCredentials中的keyId字段:
- 对于
keyCredentials,创建时需要指定keyId(这是密钥的唯一标识符,由你生成),所以单独添加时没问题; - 但对于
passwordCredentials,keyId是由Graph API自动生成的,创建请求中不能包含这个字段,否则会触发400错误。
解决方法很简单:移除passwordCredentials数组里的keyId字段,保留其他必填项即可。修改后的请求体示例:
{ "displayname":"sample", "keyCredentials": [ { "customKeyIdentifier": "=", "displayName": "", "endDateTime": "", "key": "", "keyId": "", "startDateTime": "", "type": "", "usage": "" } ], "passwordCredentials": [ { "customKeyIdentifier": "", "displayName": "", "endDateTime": "", "secretText": "", "startDateTime": "" } ] }
这样就能成功创建同时包含两类凭据的Azure应用了。
内容的提问来源于stack exchange,提问作者Janakiram
相关产品推荐
相关产品推荐

