You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

从Streamlit调用Power Automate Http触发流时遇401签名无效错误

问题

我尝试用以下Python代码从Streamlit应用触发HTTP触发的Power Automate流:

def get_access_token_powerAutomate():
    tenant_id = os.getenv("TENANT_ID")
    client_id = os.getenv("CLIENT_ID")
    client_secret = os.getenv("CLIENT_SECRET")
    scope = 'https://graph.microsoft.com/.default'
   
    url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token"
   
    headers = {
        'Content-Type': 'application/x-www-form-urlencoded'
    }
   
    body = {
        'grant_type': 'client_credentials',
        'client_id': client_id,
        'client_secret': client_secret,
        'scope': scope
    }
   
    response = requests.post(url, headers=headers, data=body)
   
    if response.status_code == 200:
        access_token = response.json().get('access_token')
        if not access_token:
            st.error("Access token not found in the response.")
            return None
        return access_token
    else:
        st.error("Failed to obtain access token.")
        st.error(f"Response status: {response.status_code}")
        st.error(f"Response content: {response.content}")
        return None
 
def power_automateflow(organizer_upn, attendee_upns, meeting_notes, selected_subject, transcript_date):
    access_token = get_access_token_powerAutomate()
    st.write("access_token",access_token)
    if not access_token:
        st.error("Access token retrieval failed.")
        return
   
    mail_subject = f" Notes of {selected_subject} on {transcript_date}"
    # Data to be sent
    transcript_data = {
        'organizer_upn': organizer_upn,
        'attendee_upns': attendee_upns,
        'meeting_notes': meeting_notes,
        'mail_subject': mail_subject
    }
 
    # Set the headers with the access token
    headers = {
        'Authorization': f'Bearer {access_token}',
        'Content-Type': 'application/json'
    }
 
    # Power Automate flow endpoint URL
    power_automate_url = os.getenv("POWER_AUTOMATE_URL")
    if not power_automate_url:
        st.error("Power Automate URL is not set.")
        return
 
    # Making the POST request to Power Automate flow
    response = requests.post(power_automate_url, headers=headers, json=transcript_data)
 
    if response.status_code == 200:
        st.success("Meeting Notes sent successfully for organizer's approval!")
        st.success("Check your mail once they approve.")
    else:
        st.error(f"Failed to send Meeting Notes. Status code: {response.status_code}")
        st.error(f"Response content: {response.content}")

已在Azure注册应用中添加对应权限,但触发时出现401错误:

Failed to send Meeting Notes. Status code: 401 Response content: b'{"error":{"code":"SecurityTokenInvalidSignature","message":"The provided authentication token is not valid, token signature is not properly formatted."}}'

需要解决这个问题。

解决方案

1. 修正权限范围

当前请求的scope是https://graph.microsoft.com/.default,但Power Automate HTTP触发器需要的是Power Automate服务的权限范围,而非Graph API。将scope替换为:

scope = 'https://service.flow.microsoft.com/.default'

替换后需确保Azure AD应用已添加Power Automate相关权限(如Flow.Manage.All),并完成管理员同意。

2. 验证Token格式与有效性

  • 拿到access_token后,用JWT解析工具(本地操作)检查:
    • aud(受众)字段是否为https://service.flow.microsoft.com,若为Graph的地址则说明scope错误;
    • 确认token无截断、无多余空格或换行,确保请求头中Bearer {access_token}的token是完整字符串。

3. 检查Power Automate触发器配置

  • 确认HTTP触发器的认证方式为Azure Active Directory,而非API密钥等其他方式;
  • 在触发器设置中,确保Azure AD应用的服务主体被允许访问该流,或设置为允许所有已授权的Azure AD应用访问。

4. 核对环境变量准确性

  • 检查TENANT_ID、CLIENT_ID、CLIENT_SECRET是否存在拼写错误或多余空格,特殊字符需正确读取;
  • 确认POWER_AUTOMATE_URL是完整的触发器地址,无遗漏或多余斜杠。

5. 手动测试Token请求

用Postman或curl手动请求token(使用修正后的scope),拿到token后直接调用Power Automate接口:

  • 若手动请求成功,排查代码中token处理逻辑;
  • 若手动请求失败,重点检查Azure AD权限配置或Power Automate流的访问权限。

内容的提问来源于stack exchange,提问作者Pmd

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 08:05:22