咨询Microsoft OneDrive OAuth2中Windows及Android应用的重定向URI
Hey there! I’ve helped a bunch of devs sort out OneDrive OAuth2 redirect URIs for Windows and Android, so let’s break this down clearly for your app.
Windows Platform
The right URI depends on what type of Windows app you’re building:
Traditional Desktop Apps (Win32, WPF, WinForms)
For these native desktop apps (which count as "public clients" without a backend server), use this pre-defined redirect URI:
https://login.microsoftonline.com/common/oauth2/nativeclient
To make this work, head to your Azure AD app registration, go to the Authentication tab, select Add a platform, choose Mobile and desktop applications, then check the box for Public client (mobile & desktop). This will auto-add the above URI for you.
UWP (Universal Windows Platform) Apps
UWP apps use a URI tied to your app’s package SID. The format is:
ms-appx-web://Microsoft.AAD.BrokerPlugin/<your_package_SID>
To get your package SID:
- Run this PowerShell command (replace
<YourAppDisplayName>with your app’s name):Get-AppxPackage -Name <YourAppDisplayName> | Select-Object PackageSID
Paste that SID into the URI format above, then add it manually in your Azure AD app registration’s Authentication tab.
Android Platform
Android apps use a URI tied to your app’s package name and signature hash. The format is:
msauth://<your_package_name>/<your_url_encoded_signature_hash>
Step 1: Get your signature hash
Use this command (replace placeholders with your keystore details):
keytool -exportcert -alias <your_key_alias> -keystore <path_to_keystore> | openssl sha1 -binary | openssl base64
- For debug builds, the default alias is
androiddebugkey, keystore path is usually~/.android/debug.keystore(Linux/macOS) orC:\Users\<YourName>\.android\debug.keystore(Windows), with passwordandroid. - Take the output hash, URL-encode it (replace
+with%2B,/with%2F,=with%3D).
Step 2: Set up the URI in Azure
Go to your Azure AD app registration, select Add a platform, choose Android, then input your app’s package name and the raw (non-encoded) signature hash. Azure will auto-generate the correct redirect URI for you.
Step 3: Add intent filter to your app
In your AndroidManifest.xml, add this intent filter to the activity that should handle the redirect:
<intent-filter> <action android:name="android.intent.action.VIEW" /> <category android:name="android.intent.category.DEFAULT" /> <category android:name="android.intent.category.BROWSABLE" /> <data android:scheme="msauth" android:host="<your_package_name>" android:path="/<your_encoded_signature_hash>" /> </intent-filter>
Note: You’ll need separate redirect URIs for debug and release builds (since their signature hashes are different).
Quick Tips
- Always double-check that all your redirect URIs are listed in your Azure AD app registration—missing ones will cause authorization errors.
- Use Microsoft’s MSAL (Microsoft Authentication Library) for both platforms—it handles most of the redirect logic automatically, so you don’t have to parse the response manually.
内容的提问来源于stack exchange,提问作者Alireza

