PHP中Azure身份验证报错求助:invalid_client异常解析
invalid_client Error in Azure OAuth with League OAuth2 Client Hey there, let's tackle that frustrating invalid_client error you're hitting when using the League OAuth2 Client library with Azure. This error is Azure's way of saying "I don't recognize the app trying to authenticate"—so let's walk through the most common fixes to get you sorted:
Double-check your Client ID and Secret
Make 100% sure theclientIdandclientSecretyou're passing toGenericProvidermatch exactly what's in your Azure AD app registration. Azure's Client IDs are long, case-sensitive UUIDs, and secrets are just as picky—even a single extra space or typo will trigger this error. Pro tip: Copy-paste these values directly from Azure instead of typing them manually to avoid mistakes. Also, confirm you're using the Application (client) ID, not the Object ID or Directory ID from your app registration.Validate your Client Secret's status
Head over to your Azure AD app registration > Certificates & secrets. Check if the client secret you're using is still active—has it expired? Was it deleted or revoked? If it's past its expiration date, create a new secret, save it somewhere secure, and update your code with the new value immediately.Match your Redirect URI exactly
Azure is strict about redirect URIs: the one you define in yourGenericProvidersetup must be an exact match to one of the URIs listed in your app registration > Authentication. Even small differences likehttpvshttps, or a missing/extra trailing slash, will cause Azure to reject your client. For example, if your code useshttps://your-app.com/callback, make sure that exact string is in Azure's allowed redirect URIs list.Confirm you're using the correct Azure OAuth endpoints
When configuringGenericProvider, ensure you're pointing to Azure's official endpoints. For most modern apps using Azure AD v2.0, these should be:'authorizationUrl' => 'https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/authorize', 'tokenUrl' => 'https://login.microsoftonline.com/{your-tenant-id}/oauth2/v2.0/token',If you're using the v1 endpoint, adjust the URIs accordingly, but v2 is recommended for broader compatibility.
Check your app's account access settings
If your app registration is set to Single tenant, make sure you're testing with a user from that specific tenant. If you need to allow users from any organization or personal Microsoft accounts, switch your app's account type to "Multitenant" or "Accounts in any organizational directory and personal Microsoft accounts" in the Azure portal.
Bonus Debug Tip
If none of the above fixes work, enable debug logging for the Guzzle client used by the OAuth provider. This will let you inspect the exact request being sent to Azure, which might reveal hidden issues like incorrectly encoded parameters or missing headers. You can add a logger to your provider setup by passing a custom Guzzle client configuration.
内容的提问来源于stack exchange,提问作者arjunrajantechie

