You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer3使用Reference Tokens时introspection endpoint返回NotFound错误求助

解决Reference Tokens验证时的"Error returned from introspection endpoint: Not Found"问题

我帮你梳理下这个问题的核心原因和解决步骤,你遇到的401权限拒绝、端点找不到错误,其实和你IdentityServer配置里的一个关键开关直接相关:

问题根源

Reference Tokens(引用令牌)和JWT(自包含令牌)的验证逻辑完全不同:

  • JWT本身携带所有验证信息,API可以本地完成校验
  • Reference Tokens只是一个指向IdentityServer的"引用ID",API必须调用IdentityServer的introspection端点(也就是AccessTokenValidationEndpoint),去后端校验令牌的有效性、权限范围等信息

但你在IdentityServerOptions的EndpointOptions里直接关闭了这个必需的端点:

Endpoints = new EndpointOptions() {
    EnableAccessTokenValidationEndpoint = false // 这里关闭了引用令牌依赖的校验端点
}, // Disable when live

这就导致API尝试验证Reference Token时,找不到对应的校验接口,直接返回Not Found,进而触发invalid bearer token received和401错误。

解决步骤

1. 开启AccessTokenValidationEndpoint

把EnableAccessTokenValidationEndpoint设置为true,这是Reference Tokens正常工作的必要条件:

var identityServerOptions = new IdentityServerOptions {
    // 其他配置保持不变
    Endpoints = new EndpointOptions() {
        EnableAccessTokenValidationEndpoint = true // 必须开启这个端点
    },
    // 其他配置保持不变
};

注释里的Disable when live应该是之前针对JWT令牌的配置,对Reference Tokens完全不适用。

2. 调整API的令牌验证配置

因为你用的是Reference Tokens,建议明确指定验证模式为ValidationEndpoint,确保API走端点校验逻辑:

app.UseIdentityServerBearerTokenAuthentication(new IdentityServerBearerTokenAuthenticationOptions {
    Authority = "https://api-test.azurewebsites.net/identity",
    DelayLoadMetadata = true,
    ValidationMode = ValidationMode.ValidationEndpoint, // 明确指定用端点验证Reference Token
    RequiredScopes = new[] {"api"},
    ClientId = "api",
    ClientSecret = "8at?7nAtaB!E"
});

你之前注释掉了ValidationMode,打开并设置为ValidationEndpoint可以避免逻辑歧义。

3. 额外检查点

  • 确认你的客户端配置中,AccessTokenType设置为AccessTokenType.Reference(只有客户端请求Reference Token时,才会触发端点校验逻辑)
  • 检查Azure部署环境中的证书加载是否正常:你的LoadCertificate方法会优先从CurrentUser存储取证书,Azure环境中需要确保证书已正确部署到对应的存储位置
  • 查看IdentityServer的详细日志(你已经开启了EnableHttpLogging等日志选项),确认introspection端点开启后是否能正常接收API的校验请求

为什么之前正常现在突然出错?

可能的原因包括:

  • 之前项目用的是JWT令牌(不需要端点校验),后来切换到Reference Tokens但没更新端点配置
  • 部署环境的配置发生了变化(比如Azure的应用设置重置),导致原本关闭端点的配置生效
  • 依赖的NuGet包更新后,对Reference Tokens的校验逻辑要求更严格

内容的提问来源于stack exchange,提问作者r3plica

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:38:57