You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD B2C JWT令牌签名验证失败问题求助

Azure AD B2C JWT令牌签名验证失败问题求助

各位好,我最近在做Azure AD B2C的JWT令牌验证功能,本地调试的时候一切正常,但部署到Azure Function之后就一直报签名验证失败的错误,折腾了很久都没解决,想请教下大家有没有遇到类似的问题。

错误信息如下:

[Error] IDX10516: Signature validation failed. Unable to match key:
kid: '-KI3Q9nNR7bRofxmeZoXqbHZGew'.
Number of keys in TokenValidationParameters: '1'.
Number of keys in Configuration: '0'.
Exceptions caught:
'[PII of type 'System.Text.StringBuilder' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.
token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'. Valid Lifetime: 'True'. Valid Issuer: 'False'

我已经查了不少相关资料,但还是没定位到问题所在,下面是我的配置和验证代码:

应用配置

"JwtSettings:TenantName": "OSHDev.onmicrosoft.com",
"JwtSettings:TenantId": "5492b240-96ee-44a1-bdcb-fa0ba0200111",
"JwtSettings:AadB2cInstance": "https://OSHDev.b2clogin.com/{0}/v2.0/",
"JwtSettings:OpeinConfigUrl":"https://OSHDev.b2clogin.com/OSHDev.onmicrosoft.com/B2C_1A_SIGNUP_SIGNIN/v2.0/.well-known/openid-configuration"

JWT验证代码

public async Task<ClaimsPrincipal> ValidateAccessToken(string accessToken, JwtSettings jwtSettings, ILogger logger)
{
    var audience = jwtSettings.Audience;
    var tenant = jwtSettings.TenantName;
    var tenantid = jwtSettings.TenantId;
    var aadb2cInstance = jwtSettings.AadB2cInstance;
    var openidconfigurl = jwtSettings.OpeinConfigUrl;

    //Debugging purposes only, set this to false for production
    Microsoft.IdentityModel.Logging.IdentityModelEventSource.ShowPII = false;

    ConfigurationManager<OpenIdConnectConfiguration> configManager =
    new ConfigurationManager<OpenIdConnectConfiguration>(
        openidconfigurl,
        new OpenIdConnectConfigurationRetriever());

    OpenIdConnectConfiguration config;
    config = await configManager.GetConfigurationAsync();

    //Microsoft Identity to override claim names . If we remove below code line, "sub" claim will not be visible. Its visible under "nameidentifier"
    JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();

    JwtSecurityTokenHandler? tokenValidator = new JwtSecurityTokenHandler();

    // Initialize the token validation parameters
    TokenValidationParameters validationParameters = new TokenValidationParameters
    {
        // App Id URI and AppId of this service application are both valid audiences.
        ValidateAudience = true,
        ValidAudiences = new[] { audience },
        ValidateIssuer= true,
        ValidIssuers =  new List<string>()
        {
            string.Format(CultureInfo.InvariantCulture, aadb2cInstance, tenantid),
            string.Format(CultureInfo.InvariantCulture, aadb2cInstance, tenant)
        },
        ValidateIssuerSigningKey = true,
        // Support Azure AD V1 and V2 endpoints.
        IssuerSigningKeys = config.SigningKeys,
        RequireSignedTokens = true,
        //Debugging purposes only, set this to true for production
        ValidateLifetime = true
    };

    try
    {
        //Validate JwTToken and return Claims Prinicpals
        ClaimsPrincipal? claimsPrincipal = tokenValidator.ValidateToken(accessToken, validationParameters, out SecurityToken securityToken);
        return claimsPrincipal;
    }
    catch (Exception ex)
    {
        logger.LogError(ex.Message);
    }

    return null;
}

本地运行的时候验证完全没问题,一部署到Azure Function就报这个错,实在搞不懂哪里出问题了,求各位大佬指点!

备注:内容来源于stack exchange,提问作者PavanKumar GVVS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 14:53:17