Office 365认证求助:使用授权码请求访问令牌失败
Hey there, let's walk through why you're getting a bool(false) instead of an access token when exchanging your authorization code with Azure AD. This usually points to a misconfigured request or a failed HTTP call—here are the most common fixes to check:
Common Issues & Fixes
Wrong Token Endpoint URL
Azure AD uses different endpoints depending on your tenant type, and mixing up the authorization endpoint with the token endpoint is a super common slip-up. Make sure you're sending your POST to:- For multi-tenant apps:
https://login.microsoftonline.com/common/oauth2/v2.0/token - For single-tenant apps:
https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/token
Double-check that you're not using the authorization endpoint (which ends with/authorize) by mistake.
- For multi-tenant apps:
Missing/Invalid Request Parameters
Azure AD requires specific form-data parameters (not JSON, unless you set the right headers) for the token exchange. Verify you're sending all required fields:grant_type: Must be exactlyauthorization_code(case-sensitive)client_id: Your app's registered client ID from the Azure Portalcode: The fresh authorization code you received (codes are single-use and expire after 10 minutes—if you reused an old one, grab a new one)redirect_uri: Must exactly match the URI you registered in Azure AD (no extra slashes, case matters!)client_secret: Required if your app is a confidential client (like a web app; skip this for public clients like mobile apps)
Also, ensure your request uses theapplication/x-www-form-urlencodedcontent type—JSON requests need an explicitContent-Type: application/jsonheader, but form-data is the standard here.
Authorization Code Reuse/Expiry
Azure AD authorization codes are one-time use and expire after 10 minutes. If you've tried using the same code more than once, or waited too long, the request will fail. Generate a new authorization code by re-running the initial login flow and try again.Confidential Client Authentication Errors
If your app is a web app (confidential client), you need to authenticate with either aclient_secretor client certificate. If you forgot to include the secret, or entered it incorrectly, the request will fail silently. Double-check your secret matches what's in the Azure Portal (note: secrets are only visible once when created—if you lost it, generate a new one).HTTP Client Execution Failures
Abool(false)response often means your HTTP client couldn't even complete the request (e.g., SSL issues, proxy blocks, or missing error handling in your code). Try testing the request directly from your server with a curl command to isolate the issue:curl -X POST https://login.microsoftonline.com/common/oauth2/v2.0/token \ -d "grant_type=authorization_code&client_id=YOUR_CLIENT_ID&code=YOUR_AUTH_CODE&redirect_uri=YOUR_REDIRECT_URI&client_secret=YOUR_CLIENT_SECRET"If you're using a language like PHP, enable cURL error reporting to see the actual failure reason—
bool(false)usually indicates the request never got a valid response.Misconfigured Azure AD App Registration
Head back to the Azure Portal and verify your app settings:- Confirm the redirect URI is added under Authentication > Redirect URIs
- Check that your app supports the OAuth 2.0 flow you're using (under Authentication > Advanced settings)
- Ensure you've granted the necessary API permissions (though this usually returns a specific error, not a failed request)
Start with the simplest checks first—verify the endpoint and parameters, then test with curl. Once you get a proper error message from Azure AD (like invalid client, invalid code, etc.), you'll have a clear path to fix it!
内容的提问来源于stack exchange,提问作者RGriffiths

