使用client_assertion调用Entra ID /token接口失败求助
背景
我正尝试按照《Microsoft identity platform应用程序身份验证证书凭据》文档,用身份验证证书获取JWT,通过OAuth JWT访问SharePoint Online API。
生成client_assertion的代码
const privateKeyPEM = createPrivateKey(pem); const jwt = await new SignJWT({}) .setProtectedHeader({ alg: 'PS256', // or RS384 or PS256 typ: 'JWT', x5t: 'REI1RREI1RDM2MTM1MDJFQjBEQTE3NkU2RDc3MkYxMUQ5OTdFQTc5MTlDQgo' // base 64 encoded 'X.509 SHA-1 Thumbprint (in hex)' field from Azure Key Vault }) .setAudience('https://login.microsoftonline.com/<my tenant>/oauth2/v2.0/token') .setExpirationTime('1h') .setIssuer('aab7f7ac-XXXXX') .setJti(v4()) .setNotBefore('1s') .setSubject('aab7f7ac-XXXXX') .setIssuedAt() .sign(privateKeyPEM);
生成的JWT内容
HEADER
{ "alg": "PS256", "typ": "JWT", "x5t": "REI1RREI1RDM2MTM1MDJFQjBEQTE3NkU2RDc3MkYxMUQ5OTdFQTc5MTlDQgo" }
PAYLOAD
{ "aud": "https://login.microsoftonline.com/<my tenant>/oauth2/v2.0/token", "exp": 1749013438, "iss": "aab7f7ac-XXXXX", "jti": "e6cbe5c7-5dfe-4d57-bbde-f85aabcd121b", "nbf": 1749009839, "sub": "aab7f7ac-XXXXX", "iat": 1749009838 }
错误信息
调用接口时返回如下错误:
{ "error": "invalid_client", "error_description": "AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application. [Reason - The key was not found., Thumbprint of key used by client: '444235451108D510CCD8C4CCD4C0C91508C11104C4DCD914D910DCDCC918C4C510E4E4DD1504DCE4C4E50D0828', Please visit the Azure Portal, Graph Explorer or directly use MS Graph to see configured keys for app Id 'aab7f7ac-eea6-4f0a-9c8d-a15e6798c1ee'. Review the documentation at https://docs.microsoft.com/en-us/graph/deployments to determine the corresponding service endpoint and https://docs.microsoft.com/en-us/graph/api/application-get?view=graph-rest-1.0&tabs=http to build a query request URL, such as 'https://graph.microsoft.com/beta/applications/aab7f7ac-XXXXX']. Alternatively, SNI may be configured on the app. Please ensure that client assertion is being sent with the x5c claim in the JWT header using MSAL's WithSendX5C() method so that Azure Active Directory can validate the certificate being used. Trace ID: 1f02592a-a6e1-4c9e-a992-35677cf54e00 Correlation ID: ecc793cd-98dc-4a1d-964a-ce6b88ccf3ef Timestamp: 2025-06-04 04:05:08Z", "error_codes": [ 700027 ], "timestamp": "2025-06-04 04:05:08Z", "trace_id": "1f02592a-a6e1-4c9e-a992-35677cf54e00", "correlation_id": "ecc793cd-98dc-4a1d-964a-ce6b88ccf3ef", "error_uri": "https://login.microsoftonline.com/error?code=700027" }
已确认的信息
- 密钥保管库中的证书已关联至该应用
- 该证书可在Azure DevOps流水线中成功部署制品至SharePoint Online,但在Postman中无法正常工作
求解决思路。
内容的提问来源于stack exchange,提问作者Andrew Tyson
相关产品推荐
相关产品推荐

