OneNote页面内容preAuthenticated参数失效,请求返回401错误
I’ve run into this exact issue a few times when working with OneNote’s Graph API, so let’s break down why those pre-authenticated image URLs are throwing 401s and how to fix it:
Pre-authenticated URLs have a short expiration window
ThepreAuthenticated=trueparameter generates time-limited URLs (usually ~1 hour) that don’t require additional auth. If you’re caching these URLs and trying to access them later, they’ll be invalid. Fix this by fetching fresh page content (and fresh image URLs) every time you need to display the page—don’t store these links long-term.Your access token lacks the right permissions
To generate valid pre-authenticated URLs, your token needs the correct scopes. For site-specific OneNote pages, this usually meansNotes.Read(delegated permission) orSites.Read.All(application permission). Use a token decoder to check thescp(delegated) orroles(application) field in your token. If permissions are missing, update your app’s Azure AD settings and grab a new token.Double-check the
preAuthenticatedparameter
It’s easy to misspell the parameter (e.g.,preauthinstead ofpreAuthenticated) or place it incorrectly in the request. Ensure it’s a query string parameter in your GET request:.../content?preAuthenticated=true. If the returned image URLs don’t include a pre-auth token parameter (likeaccess_token), the API didn’t process the flag correctly.Verify your token’s audience
Your access token must be targeted athttps://graph.microsoft.com(check theaudfield when decoding). If it’s for a different resource (likehttps://onenote.com), the pre-authenticated URLs will fail. Make sure when you request your token, you specify the Graph API as the resource or use Graph-specific scopes.Application permissions may need site-level access
If you’re using application permissions (not user-delegated), your app might not have access to the specific site’s OneNote resources. Check the site’s SharePoint permissions to confirm your app is granted access, or test with a delegated token (user login) to rule out permission issues.
A valid pre-authenticated image URL should look something like this:
https://graph.microsoft.com/v1.0/sites/{site-id}/onenote/resources/{resource-id}/content?access_token={short-lived-token}&...
If you cross-check these points, you’ll almost certainly track down why those URLs are returning 401s.
内容的提问来源于stack exchange,提问作者user3665749

