You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用curl调用MS Graph接口时遇InvalidAuthenticationToken错误求助

问题原因

你的curl获取令牌的命令缺少resource参数,导致生成的access token的受众(aud)不是Microsoft Graph API,调用Graph接口时就会触发"Invalid audience"错误。

解决方案

修改获取令牌的curl命令,添加resource=https://graph.microsoft.com参数:

curl -X POST -d 'grant_type=client_credentials&client_id=[APP_ID]&client_secret=[APP_SECRET]&resource=https://graph.microsoft.com' https://login.microsoftonline.com/[TENANT_ID]/oauth2/token

用这个命令获取的access token,受众会被指定为Microsoft Graph API,再调用https://graph.microsoft.com/v1.0/groups即可正常通过验证。

补充说明
  • 你在NodeJS+Axios中能正常使用,是因为请求里已经指定了对应的resource/scope参数,确保令牌受众正确。
  • 也可以切换到Microsoft身份平台v2.0端点,用scope=https://graph.microsoft.com/.default代替resource参数,命令如下:
curl -X POST -d 'grant_type=client_credentials&client_id=[APP_ID]&client_secret=[APP_SECRET]&scope=https://graph.microsoft.com/.default' https://login.microsoftonline.com/[TENANT_ID]/oauth2/v2.0/token

这个新版本端点适配更多场景,是官方更推荐的用法。

内容的提问来源于stack exchange,提问作者Peter

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 21:15:53