应用登录(Client ID/Secret/Tenant ID)连接SharePoint读写文件认证失败求助
我尝试通过应用登录方式(使用Client ID、Client Secret和Tenant ID)连接SharePoint以进行文件读写操作,但始终无法完成认证。我已尝试以下代码:
from office365.sharepoint.client_context import ClientContext from office365.runtime.auth.client_credential import ClientCredential from office365.runtime.auth.authentication_context import AuthenticationContext context = ClientContext(SITE_URL).with_credentials( ClientCredential(CLIENT_ID, CLIENT_SECRET)) cert_credentials = { "tenant": TENANT_ID, "client_id": CLIENT_ID, "thumbprint": test_cert_thumbprint, "cert_path": "{0}/../selfsignkey.pem".format(os.path.dirname(__file__)), } ctx = ClientContext(test_site_url).with_client_certificate(**cert_credentials) current_web = ctx.web.get().execute_query() print("{0}".format(current_web.url)) from office365.runtime.auth.authentication_context import AuthenticationContext from office365.sharepoint.client_context import ClientContext class SharepointService: app_principal = {'client_id': CLIENT_ID, 'client_secret': CLIENT_SECRET} context_auth = AuthenticationContext(url=site_url) token = context_auth.acquire_token_for_app(client_id=app_principal['client_id'], client_secret=app_principal['client_secret']) print(token) ctx = ClientContext(site_url, context_auth) web = ctx.web ctx.load(web) ctx.execute_query() print("Web site title: {0}".format(web.properties['Title']))
运行代码时出现invalid_client错误,提示信息为:AADSTS7000215: Invalid client secret provided. Ensure the secret being sent in the request is the client secret value, not the client secret ID, for a secret added to app '{Client ID}'。
排查与解决建议
- 核对Client Secret:确保使用的是Azure AD应用注册时生成的客户端密码值(生成密码时显示的一次性字符串),而非密码列表中的ID。若密码过期,重新生成新的客户端密码。
- 确认应用权限配置:在Azure AD应用注册页面,为应用添加SharePoint相关的应用权限(如
Sites.ReadWrite.All、Files.ReadWrite.All),并由租户管理员完成权限同意。 - 验证基础参数:检查代码中的
TENANT_ID、SITE_URL是否准确,SITE_URL需为完整的SharePoint站点地址(格式示例:https://yourtenant.sharepoint.com/sites/yoursite)。 - 使用最简测试代码:先通过简化代码排除其他逻辑干扰,测试核心认证流程:
from office365.sharepoint.client_context import ClientContext from office365.runtime.auth.client_credential import ClientCredential # 替换为你的实际参数 SITE_URL = "https://yourtenant.sharepoint.com/sites/yoursite" CLIENT_ID = "your-client-id" CLIENT_SECRET = "your-client-secret-value" ctx = ClientContext(SITE_URL).with_credentials(ClientCredential(CLIENT_ID, CLIENT_SECRET)) web = ctx.web.get().execute_query() print(f"站点标题: {web.properties['Title']}")
- 证书认证检查(若使用):如果尝试证书方式,确认证书文件路径正确,证书指纹(thumbprint)与Azure AD应用中上传的证书指纹完全匹配,且证书未过期。
内容的提问来源于stack exchange,提问作者Nicholas Tan
相关产品推荐
相关产品推荐

