You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用API访问SharePoint文件触发AudienceUriValidationFailedException错误

问题原因及解决办法

核心问题:Token受众不匹配

你遇到的AudienceUriValidationFailedException错误,本质是获取的Access Token受众(aud字段)和SharePoint REST API要求的受众不匹配:

  • 你当前用scope: "https://graph.microsoft.com/.default"获取的是Microsoft Graph的Token,其aud字段值为https://graph.microsoft.com
  • 而你调用的是SharePoint传统REST API(/_api/web/...),它要求Token的受众是你的SharePoint租户/站点的资源标识符,不是Graph的地址

解决步骤

  1. 修改Token获取请求的Scope
    将payload里的scope替换为你的SharePoint租户根URL后缀.default,示例:

    payload = {
    "client_id": "CLIENT-ID",
    "client_secret": "CLIENT-SECRET",
    "grant_type": "client_credentials",
    "scope": "https://{tenant-name}.sharepoint.com/.default" 
    }
    

    (把{tenant-name}替换为你的实际租户名称,比如contoso对应contoso.sharepoint.com)

  2. 确认应用权限配置正确
    你之前配置的是Graph权限,需要改成SharePoint的应用权限:

    • 进入Azure AD应用的「API权限」页面
    • 添加「SharePoint」的应用权限(比如测试用的Sites.FullControl.All),并完成管理员同意
  3. 重新获取Token并调用API
    用修改后的请求重新获取Access Token,再发起SharePoint REST API请求即可。

补充说明

如果要通过Microsoft Graph操作SharePoint文件,应该使用Graph的专属端点(比如GET https://graph.microsoft.com/v1.0/sites/{site-id}/drive/items/{folder-id}/children),而非SharePoint传统REST API。两种API的Token受众和权限体系相互独立,不能混用。

内容的提问来源于stack exchange,提问作者Muhammad Arsal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 21:12:33