Excel在线内容加载项SSO实现遇getAccessTokenAsync错误13000
Hey there! Let's break down why your Excel add-in's SSO flow works flawlessly on desktop but throws that 13000 error in Excel Online. Since the desktop client runs smoothly, the issue is almost certainly tied to configuration gaps or web-specific restrictions. Here are the key areas to check:
1. Verify Your Manifest.xml Configuration
The manifest is the backbone of your add-in's integration with Office, so let's start here:
- Ensure you have a properly structured
<WebApplicationInfo>node in your manifest. It should include:- A valid
ClientId(matching your Azure AD app registration's client ID) - The correct
Resourcevalue (e.g.,https://graph.microsoft.comfor Microsoft Graph, orhttps://outlook.office365.comfor Office resources) RequestedAccessTokenVersion="2"(v2 tokens are required for modern SSO flows in Online)
- A valid
- Double-check the
<Permissions>node to confirm you've declared the necessary permissions (e.g.,ReadWriteMailboxor Microsoft Graph scopes likeUser.Read). Missing or incorrect permissions can block the identity API. - Make sure your
<Hosts>node includes<Host Name="Workbook" />without any restrictions that limit the add-in to desktop only.
2. Validate Your Azure AD App Registration
Your app registration settings directly impact SSO functionality in Excel Online:
- Confirm the Redirect URI is correctly configured. For Office add-ins, you'll typically need to add
https://login.microsoftonline.com/common/oauth2/nativeclient(for desktop) and your add-in's HTTPS callback URL (e.g.,https://your-add-in-domain.com/auth.html) for web. Ensure these are marked as the appropriate type (Web or SPA, depending on your flow). - Check the Supported account types matches your use case. If you're testing with a work/school account, ensure the app is set to "Accounts in this organizational directory" or "Accounts in any organizational directory" (if multi-tenant).
- Verify that the required API permissions (e.g., Microsoft Graph) have been granted by an admin (if using delegated permissions that require admin consent).
3. Address Side-Loading Restrictions in Excel Online
Side-loaded add-ins have more restrictions in the online environment compared to deployed ones:
- Unverified add-ins (those not published to App Source or deployed via tenant admin) may be blocked from using the identity API in Excel Online. Ask your tenant admin to add your Azure AD app registration to the tenant's allowed app list, or test with an admin account to rule out permission blocks.
- Ensure your browser allows third-party cookies. SSO flows rely on these cookies for authentication, and disabling them can break the flow indirectly (even if the error code points to API support). Check Chrome/Edge settings under "Privacy and security" to confirm third-party cookies are enabled.
4. Check Your getAccessTokenAsync Call
A small mistake in the method call could cause this error:
- Confirm you're passing the correct
resourceparameter. For example, if you're requesting a token for Microsoft Graph, the resource should be"https://graph.microsoft.com". Mismatched resources can trigger the "API Not Supported" error. - Avoid using deprecated parameters (like
authority) that might not be supported in the online client. Stick to the current Office.js API specifications forgetAccessTokenAsync.
5. Dig Deeper with Debugging
If the above steps don't resolve the issue:
- Enable Office Add-in debugging logs: Open Excel Online, go to File > Options > Trust Center > Trust Center Settings > Add-ins, and check "Enable logging for add-ins". The logs will provide more detailed error context.
- Use the browser's developer tools (F12) to inspect network requests and console logs. Look for failed authentication requests or additional error messages that might point to the root cause.
Hopefully one of these steps gets your SSO flow working in Excel Online!
内容的提问来源于stack exchange,提问作者DebJ

