从Streamlit调用Power Automate Http触发流时遇401签名无效错误
问题
我尝试用以下Python代码从Streamlit应用触发HTTP触发的Power Automate流:
def get_access_token_powerAutomate(): tenant_id = os.getenv("TENANT_ID") client_id = os.getenv("CLIENT_ID") client_secret = os.getenv("CLIENT_SECRET") scope = 'https://graph.microsoft.com/.default' url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/token" headers = { 'Content-Type': 'application/x-www-form-urlencoded' } body = { 'grant_type': 'client_credentials', 'client_id': client_id, 'client_secret': client_secret, 'scope': scope } response = requests.post(url, headers=headers, data=body) if response.status_code == 200: access_token = response.json().get('access_token') if not access_token: st.error("Access token not found in the response.") return None return access_token else: st.error("Failed to obtain access token.") st.error(f"Response status: {response.status_code}") st.error(f"Response content: {response.content}") return None def power_automateflow(organizer_upn, attendee_upns, meeting_notes, selected_subject, transcript_date): access_token = get_access_token_powerAutomate() st.write("access_token",access_token) if not access_token: st.error("Access token retrieval failed.") return mail_subject = f" Notes of {selected_subject} on {transcript_date}" # Data to be sent transcript_data = { 'organizer_upn': organizer_upn, 'attendee_upns': attendee_upns, 'meeting_notes': meeting_notes, 'mail_subject': mail_subject } # Set the headers with the access token headers = { 'Authorization': f'Bearer {access_token}', 'Content-Type': 'application/json' } # Power Automate flow endpoint URL power_automate_url = os.getenv("POWER_AUTOMATE_URL") if not power_automate_url: st.error("Power Automate URL is not set.") return # Making the POST request to Power Automate flow response = requests.post(power_automate_url, headers=headers, json=transcript_data) if response.status_code == 200: st.success("Meeting Notes sent successfully for organizer's approval!") st.success("Check your mail once they approve.") else: st.error(f"Failed to send Meeting Notes. Status code: {response.status_code}") st.error(f"Response content: {response.content}")
已在Azure注册应用中添加对应权限,但触发时出现401错误:
Failed to send Meeting Notes. Status code: 401 Response content: b'{"error":{"code":"SecurityTokenInvalidSignature","message":"The provided authentication token is not valid, token signature is not properly formatted."}}'
需要解决这个问题。
解决方案
1. 修正权限范围
当前请求的scope是https://graph.microsoft.com/.default,但Power Automate HTTP触发器需要的是Power Automate服务的权限范围,而非Graph API。将scope替换为:
scope = 'https://service.flow.microsoft.com/.default'
替换后需确保Azure AD应用已添加Power Automate相关权限(如Flow.Manage.All),并完成管理员同意。
2. 验证Token格式与有效性
- 拿到
access_token后,用JWT解析工具(本地操作)检查:aud(受众)字段是否为https://service.flow.microsoft.com,若为Graph的地址则说明scope错误;- 确认token无截断、无多余空格或换行,确保请求头中
Bearer {access_token}的token是完整字符串。
3. 检查Power Automate触发器配置
- 确认HTTP触发器的认证方式为Azure Active Directory,而非API密钥等其他方式;
- 在触发器设置中,确保Azure AD应用的服务主体被允许访问该流,或设置为允许所有已授权的Azure AD应用访问。
4. 核对环境变量准确性
- 检查
TENANT_ID、CLIENT_ID、CLIENT_SECRET是否存在拼写错误或多余空格,特殊字符需正确读取; - 确认
POWER_AUTOMATE_URL是完整的触发器地址,无遗漏或多余斜杠。
5. 手动测试Token请求
用Postman或curl手动请求token(使用修正后的scope),拿到token后直接调用Power Automate接口:
- 若手动请求成功,排查代码中token处理逻辑;
- 若手动请求失败,重点检查Azure AD权限配置或Power Automate流的访问权限。
内容的提问来源于stack exchange,提问作者Pmd
相关产品推荐
相关产品推荐

