You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft Partner Center API获取令牌遇AADSTS50000错误求助

问题:调用Microsoft Partner Center API获取令牌时出现AADSTS50000错误

尝试用PowerShell脚本调用Microsoft Partner Center APIs时遇到错误,无法正常使用API,相关信息如下:

示例代码

$AzureADtenant = "ABC.onmicrosoft.com"
$AzureADtenantId = "xxxx"
$ClientId = "yyyy"
$ClientSecret = "zzzzz"
$resource = "https://partner.microsoft.com"
$requestAccessTokenUri = "https://login.microsoftonline.com/$AzureADtenantid/oauth2/token"
$body = "grant_type=client_credentials&client_id=$ClientId&client_secret=$ClientSecret&resource=$resource"
$accessToken = Invoke-RestMethod -Method Post -Uri $requestAccessTokenUri -Body $body -ContentType 'application/x-www-form-urlencoded'

错误信息

Invoke-RestMethod : {"error":"server_error","error_description":"AADSTS50000: There was an error issuing a token or an issue with our sign-in service.\r\nTrace ID: 60c1365f-be7f-472a-87c8-fd03aa9b4a02\r\nCorrelation ID: d5422741-088d-4cad-9da8-fd6c4486fc94\r\nTimestamp: 2023-10-19 14:26:22Z","error_codes":[50000],"timestamp":"2023-10-19 14:26:22Z","trace_id":"60c1365f-be7f-472a-87c8-fd03aa9b4a02","correlation_id":"d5422741-088d-4cad-9da8-fd6c4486fc94","error_uri":"https://login.microsoftonline.com/error?code=50000"}
At line:12 char:16
+ ... cessToken = Invoke-RestMethod -Method Post -Uri $requestAccessTokenUr ...
+                 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-RestMethod], WebException
    + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeRestMethodComm

解决步骤

1. 修正资源URI

Partner Center API的合法资源URI是 https://api.partnercenter.microsoftonline.com,你当前使用的https://partner.microsoft.com是错误的,替换后可解决令牌颁发的核心问题。

2. 修复变量大小写问题

PowerShell对变量名大小写敏感,你脚本中定义的是$AzureADtenantId,但拼接请求URI时用了$AzureADtenantid(末尾d小写),会导致租户ID参数错误,修正为一致的变量名:

$requestAccessTokenUri = "https://login.microsoftonline.com/$AzureADtenantId/oauth2/token"

3. 验证应用注册配置

  • 确认Azure AD应用注册已添加Partner Center相关权限(如PartnerCenter.Read.All、PartnerCenter.Write.All),且已获得租户管理员的权限同意。
  • 检查客户端密钥(ClientSecret)是否过期、输入值是否完全正确。

4. 排查临时服务故障

AADSTS50000偶尔是Azure AD服务端的临时问题,若上述配置都无问题,可等待10-15分钟后重试。

修正后的完整脚本

$AzureADtenant = "ABC.onmicrosoft.com"
$AzureADtenantId = "xxxx"
$ClientId = "yyyy"
$ClientSecret = "zzzzz"
$resource = "https://api.partnercenter.microsoftonline.com"
$requestAccessTokenUri = "https://login.microsoftonline.com/$AzureADtenantId/oauth2/token"
$body = "grant_type=client_credentials&client_id=$ClientId&client_secret=$ClientSecret&resource=$resource"
$accessToken = Invoke-RestMethod -Method Post -Uri $requestAccessTokenUri -Body $body -ContentType 'application/x-www-form-urlencoded'

内容的提问来源于stack exchange,提问作者user2042727

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 08:35:58