从Microsoft Graph获取令牌时遇AADSTS900144错误求助
解决Azure AD令牌请求中"AADSTS900144: 缺少grant_type参数"的问题
问题原因
你手动设置了Content-Type: multipart/form-data请求头,但没有包含表单边界(boundary)。当使用FormData作为请求体时,浏览器会自动生成包含boundary的Content-Type头,手动覆盖后,Azure AD的令牌端点无法正确解析表单数据,导致识别不到你已经添加的grant_type参数。
修复代码
直接移除手动设置的Content-Type头即可:
const graphTokenFormData = new FormData(); graphTokenFormData.append("scope", "https://graph.microsoft.com/.default"); graphTokenFormData.append("grant_type", "client_credentials"); graphTokenFormData.append("client_id", client_id); graphTokenFormData.append("client_secret", client_secret); const graphTokenResponse = await fetch(graphTokenUrl, { method: "post", // 移除手动设置的Content-Type,让fetch自动处理 body: graphTokenFormData }).catch((reason) => { console.log( `📝 Failed to fetch graph token from https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/token`, reason ); }); // 补充:完善响应处理逻辑 if (graphTokenResponse && graphTokenResponse.ok) { const tokenData = await graphTokenResponse.json(); console.log("令牌获取成功:", tokenData.access_token); } else { const errorData = await graphTokenResponse?.json(); console.error("令牌请求失败:", errorData); }
额外检查项
- 确认
client_id、client_secret、graphTokenUrl(已替换{tenantID})变量均正确赋值,无空值或拼写错误 - 确保你的Azure AD应用注册已配置有效客户端密钥,且目标权限(Scope)已获得管理员授权
内容的提问来源于stack exchange,提问作者user2140740
相关产品推荐
相关产品推荐

