You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已获取Token但调用SharePoint API返回401(ID3035)问题求助

问题

已在Azure中注册应用并配置对应API权限,Python代码如下:

import requests
from msal import ConfidentialClientApplication

client_id = "xxxxxxxxxxxxxxxxxxxxx"
client_secret = "yyyyyyyyyyyyyyyyyyyyy"
tenant_id = "tttttttttttttttttttttttttttttttttttttttt"
site_url = "https://{mytenent}.sharepoint.com/sites/mysite"
resource = "https://{mytenent}"

# Authenticate using client ID and secret
authority = f"https://login.microsoftonline.com/{tenant_id}"
app = ConfidentialClientApplication(
    client_id=client_id,
    authority=authority,
    client_credential=client_secret,
)

scope=[resource + "/.default"]
token_response = app.acquire_token_for_client(scopes=scope)


access_token = token_response.get("access_token") #token_response["access_token"]
print(access_token)

endpoint_url = f"{site_url}/_api/web"
headers = {
    "Authorization": "Bearer " + access_token,
    "Accept": "application/json;odata=verbose",
    "Content-Type": "application/json;odata=verbose",
}
print(endpoint_url)
response = requests.get(endpoint_url, headers=headers)

# Check for errors in the SharePoint API response
if response.status_code == 200:
    data = response.json()
    print("SharePoint Site Title:", data["d"]["Title"])
else:
    print("SharePoint API Error:")
    print("Status Code:", response.status_code)
    print("Response:", response.text)

能正常获取到Token字符串,但调用SharePoint API时收到401响应:

Status Code: 401 Response: {"error_description":"ID3035: The request was not valid or is malformed."}

请问该问题的原因可能是什么?

可能的原因及解决建议

  • Scope配置错误:当前用的resource = "https://{mytenent}"生成的scope是https://{mytenent}/.default,但SharePoint Online的正确资源标识应该是https://{mytenent}.sharepoint.com,而非仅租户域名。修改resource为https://{mytenent}.sharepoint.com,对应的scope改为["https://{mytenent}.sharepoint.com/.default"],重新获取Token后重试。

  • 权限未完成管理员授权:确认Azure应用注册里配置的SharePoint API权限(比如Sites.Read.All)已经点击授予管理员同意,仅添加权限但未授权会导致Token没有有效访问权限。

  • Token受众不匹配:解码获取到的Token,检查aud(受众)字段是否为https://{mytenent}.sharepoint.com,如果不是,说明scope配置错误,生成的Token不是针对SharePoint的。

  • 请求头冗余问题:GET请求通常不需要Content-Type头,可以尝试去掉这个字段,或者将odata=verbose改为odata=nometadata简化格式,避免格式解析报错。

  • 站点URL拼写错误:确认site_url里的{mytenent}已经替换成实际租户名称,确保端点URL是正确的SharePoint站点地址,比如https://contoso.sharepoint.com/sites/mysite。

内容的提问来源于stack exchange,提问作者Mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 05:12:47