You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD认证ASP.NET Core 3.0 Web API报401:签名密钥未找到

Fixing the 401 "signature key was not found" Error in ASP.NET Core 3.0 Web API with Azure AD Auth

Hey there, let's break down why you're hitting this 401 error and fix it step by step. The "signature key was not found" message means your app can't retrieve or validate the public key Azure AD uses to sign JWT tokens. Here are the key fixes you need to apply:

1. Ensure JwtBearer Automatically Fetches Signing Keys

While AddJwtBearer should pull signing keys from the Authority's metadata endpoint by default, in some cases (especially with Azure AD v2 endpoints), you need to explicitly configure this. Update your authentication setup like this:

services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(o => 
    {
        o.Authority = $"https://login.microsoftonline.com/<mytenantid>/v2.0";
        o.Audience = "<myappid>";
        o.TokenValidationParameters = new TokenValidationParameters
        {
            ValidAudiences = new string[] { "<myappid>", $"api://<myappid>" },
            ValidateIssuerSigningKey = true, // Explicitly enable signature validation
            // Resolve signing keys from Azure AD's OIDC metadata
            IssuerSigningKeyResolver = (token, securityToken, kid, validationParameters) =>
            {
                var configManager = new ConfigurationManager<OpenIdConnectConfiguration>(
                    $"{validationParameters.Origin}/.well-known/openid-configuration",
                    new OpenIdConnectConfigurationRetriever());
                var openIdConfig = configManager.GetConfigurationAsync().GetAwaiter().GetResult();
                return openIdConfig.SigningKeys.Where(k => k.KeyId == kid);
            }
        };
        // Disable default claim mapping to avoid conflicts with Azure AD v2 claims
        o.MapInboundClaims = false;
    });

This custom IssuerSigningKeyResolver ensures your app correctly fetches the right signing keys from Azure AD's metadata, which resolves the core "signature key not found" issue.

2. Fix the Swagger OAuth Authorization URL

In your Swagger security definition, the AuthorizationUrl uses a placeholder TenantId instead of your actual <mytenantid>. Replace that to ensure Swagger gets tokens from the correct tenant:

AuthorizationUrl = new Uri($"https://login.microsoftonline.com/<mytenantid>/oauth2/v2.0/authorize", UriKind.RelativeOrAbsolute)

A wrong tenant here would result in tokens that don't match your API's validation rules.

3. Verify Azure AD App Configuration

Double-check your Azure AD portal settings for the Web API app:

  • Make sure you've exposed an API and added the api://<myappid>/user_impersonation scope.
  • Confirm the client app you're using to get tokens has been granted permission to this scope (either admin-consented or user-consented, depending on your setup).

4. Validate the Token Content

Decode the JWT token you're using to call the API (use a local JWT decoding tool) and verify:

  • The aud (audience) claim matches either <myappid> or api://<myappid>
  • The iss (issuer) claim is https://login.microsoftonline.com/<mytenantid>/v2.0
  • The kid (key ID) in the token's header exists in the signing keys list from Azure AD's metadata endpoint (check the jwks_uri content from https://login.microsoftonline.com/<mytenantid>/v2.0/.well-known/openid-configuration)

Once you adjust these settings, your API should properly validate the Azure AD tokens and stop returning the 401 error.

内容的提问来源于stack exchange,提问作者Pavan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:27:38