You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Data Factory中用证书实现OAuth2客户端凭证认证调用REST API

用证书完成OAuth认证并调用REST API(第一方应用场景)

核心逻辑

第一方应用采用证书认证时,无需ClientSecret,而是通过证书私钥签名的JWT断言向令牌服务证明身份,验证通过后获取访问令牌,再用令牌调用目标API。

前置准备

  • 持有有效PKCS#12格式证书(.pfx/.p12):必须包含私钥,且证书的公钥已上传至你的身份提供商(比如Azure AD的应用注册「证书和密码」模块)
  • 确认证书与应用注册的绑定关系:部分身份系统要求证书主题/SAN与应用配置匹配,需提前核对

具体操作步骤

1. 生成签名JWT断言

用证书私钥生成符合要求的JWT,必填声明包括:

  • aud:令牌端点完整URL(拼接规则:https://${TokenEndpointHostname}/${TenantId}/${TokenEndpointResourcePath})
  • iss:你的ClientId
  • sub:与iss一致(即ClientId)
  • exp:过期时间(建议设为当前时间+3600秒,最长不超过1小时)
  • nbf:生效时间(当前时间或稍早)
  • jti:随机唯一字符串(防止请求重放)

2. 请求访问令牌

向令牌端点发送POST请求,参数如下:

  • grant_type: client_credentials
  • client_id: 你的ClientId
  • client_assertion_type: urn:ietf:params:oauth:client-assertion-type:jwt-bearer
  • client_assertion: 步骤1生成的签名JWT
  • scope: 你的Scope值

3. 调用目标REST API

拿到访问令牌后,在API请求的Authorization头中添加Bearer ${access_token},即可发起请求。

代码示例

C#(基于Microsoft.Identity.Client)

using Microsoft.Identity.Client;
using System.Security.Cryptography.X509Certificates;
using System.Net.Http.Headers;

// 加载本地证书
var cert = new X509Certificate2("your-cert.pfx", "cert-password");

// 初始化认证客户端
var app = ConfidentialClientApplicationBuilder
    .Create("your-client-id")
    .WithTenantId("your-tenant-id")
    .WithCertificate(cert)
    .Build();

// 获取访问令牌
var tokenResult = await app.AcquireTokenForClient(new[] { "your-scope" })
    .ExecuteAsync();

// 调用API
using var httpClient = new HttpClient();
httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", tokenResult.AccessToken);
var apiResponse = await httpClient.GetAsync("https://your-api-endpoint");
var responseContent = await apiResponse.Content.ReadAsStringAsync();

Python(基于msal)

import msal
import requests

# 加载证书
cert_credential = ("your-cert.pfx", "cert-password")

# 初始化认证客户端
app = msal.ConfidentialClientApplication(
    client_id="your-client-id",
    authority=f"https://{TokenEndpointHostname}/{TenantId}",
    client_credential=cert_credential
)

# 获取访问令牌
token_result = app.acquire_token_for_client(scopes=["your-scope"])

# 调用API
if "access_token" in token_result:
    headers = {"Authorization": f"Bearer {token_result['access_token']}"}
    api_response = requests.get("https://your-api-endpoint", headers=headers)
    print(api_response.json())
else:
    print(f"认证失败: {token_result.get('error')} - {token_result.get('error_description')}")

注意事项

  • 证书有效期:提前监控证书过期时间,到期前需更新证书并重新上传公钥至身份提供商
  • 权限配置:确保应用已被授予目标API的对应应用权限(第一方应用通常使用应用权限而非委派权限)
  • 令牌端点校验:确认拼接后的令牌端点URL正确,比如Azure AD的默认端点为https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/token

内容的提问来源于stack exchange,提问作者Swasti

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 12:32:52