使用Graph API创建工作表时遇WAC访问令牌获取失败错误求助
Let's break down why you're hitting this AccessDenied error and walk through actionable fixes. The message "Could not obtain a WAC access token" points to issues with the Web Application Companion (Office Online) failing to authenticate or access your target Excel file—here's what to check:
1. Make Sure You're Using Delegated Permissions (Not Application Permissions)
Graph API's workbook operations depend on a user context, so application permissions won't work here—WAC can't generate an access token without an active user session tied to the request. You need to use delegated permissions:
- For personal OneDrive: Add the
Files.ReadWritedelegated permission to your Azure AD app, and confirm the user has granted consent to this permission. - For SharePoint/OneDrive for Business: Use the
Sites.ReadWrite.Alldelegated permission (again, with user consent completed).
2. Verify the Target Item Is a Valid Excel File
Double-check that the item ID 01FUAEYJMWQZF5VGFFL5G27P5AGS5M2FXD points to an actual Excel document (.xlsx, .xlsm, etc.). Run this GET request to confirm:
GET https://graph.microsoft.com/v1.0/me/drive/items/01FUAEYJMWQZF5VGFFL5G27P5AGS5M2FXD
Look at the file.mimeType field—it should be something like application/vnd.openxmlformats-officedocument.spreadsheetml.sheet. If it's a folder or non-Excel file, replace the ID with a valid Excel file's ID.
3. Check Your Access Token's Scope
Decode your access token (you can use jwt.ms to do this quickly) and confirm it includes the required scope—either Files.ReadWrite or Sites.ReadWrite.All. If the scope is missing, re-authenticate the user with the correct scope included in your authorization request.
4. Ensure the File Isn't in a Restricted State
WAC can't access files that are:
- Locked by another user or application
- Marked as read-only
- Stored in the recycle bin
Manually open the file in OneDrive/SharePoint to confirm it's accessible and in a normal state. If it's locked, resolve the lock before retrying your API call.
Quick Note on Your Request Format
Your request URL is correctly formatted—once you fix the above issues, a POST request with a simple body like this should succeed:
{ "name": "New Worksheet" }
内容的提问来源于stack exchange,提问作者praveen

