You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Graph API为服务主体添加密钥遇Edm.Binary类型转换错误

解决创建服务主体时添加密钥的Edm.Binary类型错误

问题原因

你遇到的Cannot convert the literal 'redacted' to the expected type 'Edm.Binary'错误,核心原因是keyCredentials中的key字段要求传入Base64编码的二进制数据,而非明文字符串。Graph API无法直接将明文转换为二进制类型,因此必须先对密钥内容做Base64编码处理。

解决方案1:创建服务主体时同时添加密钥

修改请求体,将对称密钥的明文转换为Base64编码,同时补充密钥的有效期字段(startDateTime和endDateTime为必填项):

{
  "appId": "65415bb1-9267-4313-bbf5-ae259732ee12",
  "keyCredentials": [
    {
      "key": "替换为你的对称密钥明文的Base64编码值",
      "type": "Symmetric",
      "usage": "Verify",
      "startDateTime": "2024-01-01T00:00:00Z",
      "endDateTime": "2025-01-01T00:00:00Z"
    }
  ]
}

注意:对称密钥长度需符合要求(至少128位),Base64编码后的值要保证无格式错误。

解决方案2:使用addKey端点添加密钥(推荐)

若已成功创建仅含appId的服务主体,可通过addKey端点单独添加密钥,请求结构如下:

  1. 请求地址:POST https://graph.microsoft.com/v1.0/servicePrincipals/{servicePrincipalId}/addKey
  2. 请求体:
{
  "keyCredential": {
    "type": "Symmetric",
    "usage": "Verify",
    "key": "你的对称密钥明文的Base64编码值",
    "startDateTime": "2024-01-01T00:00:00Z",
    "endDateTime": "2025-01-01T00:00:00Z"
  },
  "passwordCredential": null
}

passwordCredential设为null即可,因为我们添加的是密钥凭据而非密码凭据。

权限要求

无论采用哪种方式,都需要确保你的应用或账户拥有Application.ReadWrite.All或Directory.ReadWrite.All权限(支持Delegated或Application权限,根据认证方式选择)。

内容的提问来源于stack exchange,提问作者Quinn Favo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 23:50:28