使用ADOMD连接PowerBI XMLA端点时遇无效令牌类型错误
Power BI XMLA端点ADOMD连接失败问题
我能通过SSMS和DAX Studio连接目标XMLA端点,但使用C#的ADOMD库无法建立连接。测试用的C#代码如下:
using Microsoft.AnalysisServices.AdomdClient; using Azure.Identity; class Program { static async Task Main(string[] args) { // Configuration string xmlaEndpoint = "powerbi://api.powerbi.com/v1.0/myorg/<my org>"; string scope = "https://analysis.windows.net/powerbi/api/.default"; try { // Step 1: Acquire an access token using DefaultAzureCredential Console.WriteLine("Acquiring access token using Azure Default Credential..."); var credential = new InteractiveBrowserCredential(); var tokenRequestContext = new Azure.Core.TokenRequestContext(new[] { scope }); var accessToken = (await credential.GetTokenAsync(tokenRequestContext)).Token; Console.WriteLine("Access token acquired successfully."); // Step 2: Create connection string using the access token string connectionString = $"Data Source={xmlaEndpoint};Authentication=Bearer;Password={accessToken};"; // Step 3: Connect to the XMLA endpoint and execute a query using (AdomdConnection connection = new AdomdConnection(connectionString)) { Console.WriteLine("Opening connection..."); connection.Open(); string query = "EVALUATE TOPN( 500, Invoices )"; using (AdomdCommand command = new AdomdCommand(query, connection)) { Console.WriteLine("Executing query..."); using (AdomdDataReader reader = command.ExecuteReader()) { while (reader.Read()) { Console.WriteLine(reader["Name"]); } } } connection.Close(); Console.WriteLine("Connection closed successfully."); } } catch (Exception ex) { Console.WriteLine($"Error: {ex.Message}"); } } }
运行代码时抛出异常:Error: MWC token validation failed: Invalid Token type, expected ServiceToken but got AadBasedToken
使用的凭据与SSMS、DAX Studio连接时完全一致,且代码生成的访问令牌可正常调用PowerBI REST API,不清楚SSMS和DAX Studio的处理方式有何不同。
解决方案
核心原因
ADOMD库连接Power BI XMLA端点时,需要的是针对Power BI服务的特定令牌格式,直接使用Azure Identity获取的Bearer令牌不符合要求,而SSMS/DAX Studio内部会自动处理令牌的转换逻辑。
修复步骤
- 替换身份验证方式:不要手动获取令牌后用Bearer认证,改用ADOMD内置的
ActiveDirectoryInteractive认证方式,让库自行处理令牌获取和转换。 - 调整连接字符串:移除手动令牌相关的配置,直接指定认证类型和必要参数。
修改后的代码:
using Microsoft.AnalysisServices.AdomdClient; class Program { static void Main(string[] args) { // Configuration string xmlaEndpoint = "powerbi://api.powerbi.com/v1.0/myorg/<my org>"; try { // 使用ActiveDirectoryInteractive认证,由ADOMD库处理令牌逻辑 string connectionString = $"Data Source={xmlaEndpoint};Authentication=ActiveDirectoryInteractive;"; using (AdomdConnection connection = new AdomdConnection(connectionString)) { Console.WriteLine("Opening connection..."); connection.Open(); string query = "EVALUATE TOPN( 500, Invoices )"; using (AdomdCommand command = new AdomdCommand(query, connection)) { Console.WriteLine("Executing query..."); using (AdomdDataReader reader = command.ExecuteReader()) { while (reader.Read()) { Console.WriteLine(reader["Name"]); } } } connection.Close(); Console.WriteLine("Connection closed successfully."); } } catch (Exception ex) { Console.WriteLine($"Error: {ex.Message}"); } } }
关键说明
ActiveDirectoryInteractive认证会自动弹出交互式登录窗口,和SSMS/DAX Studio的登录流程一致,确保获取到符合要求的服务令牌。- 如果需要非交互式认证(比如服务账号),可以使用
ActiveDirectoryPassword或ActiveDirectoryServicePrincipal认证类型,同样由ADOMD库处理令牌转换。
内容的提问来源于stack exchange,提问作者Bryan Batchelder
相关产品推荐
相关产品推荐

