You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OAuth2客户端凭证流获取Microsoft Graph令牌遇AADSTS900144错误求助

问题

我按照OAuth 2.0客户端凭证授予流程的步骤说明,尝试获取访问令牌,用于通过旧版Azure AD Graph查询已注册应用的相关信息。我的curl命令如下:

curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d '{"grant_type":"client_credentials","client_id":"my_client_id", "client_secret":"my_client_secret", "scope":"https://graph.windows.com/.default"}' https://login.microsoftonline.com/my_tenant_id/oauth2/v2.0/token

但返回如下错误信息,明明请求体中已经包含grant_type参数:

{"error":"invalid_request","error_description":"AADSTS900144: The request body must contain the following parameter: 'grant_type'.\r\nTrace ID: a95260ff-63b6-405f-880b-738bfda33b00\r\nCorrelation ID: d606ab93-59c7-4d7d-ac45-643074e23a75\r\nTimestamp: 2023-02-24 02:29:25Z","error_codes":[900144],"timestamp":"2023-02-24 02:29:25Z","trace_id":"a95260ff-63b6-405f-880b-738bfda33b00","correlation_id":"d606ab93-59c7-4d7d-ac45-643074e23a75","error_uri":"https://login.microsoftonline.com/error?code=900144"}

请问如何正确获取访问令牌?

解决方法

错误根源是请求格式不匹配:你设置了Content-Type: application/x-www-form-urlencoded,但请求体用了JSON格式,Azure AD令牌端点无法解析JSON格式的表单参数,因此判定grant_type参数缺失。

修正后的curl命令需将请求体改为URL编码的键值对格式:

curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d 'grant_type=client_credentials&client_id=my_client_id&client_secret=my_client_secret&scope=https://graph.windows.com/.default' https://login.microsoftonline.com/my_tenant_id/oauth2/v2.0/token

关键注意点

  • 替换命令中的my_tenant_id、my_client_id、my_client_secret为你的实际租户ID、客户端ID和客户端密钥
  • 针对旧版Azure AD Graph,scope必须设置为https://graph.windows.com/.default,表示使用应用已配置的所有权限
  • 你的应用必须已被授予旧版Azure AD Graph的对应权限(如Application.Read.All),且该权限已获得管理员同意

内容的提问来源于stack exchange,提问作者Dean Schulze

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 23:42:29