Azure-Samples / Azure-Samples/remote-mcp-apim-functions-python

JWT has an invalid signature

Open
#18 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
Bicep
Stars
129
Forks
79
PR merge metrics
No merged PRs in 30d

Description

The access token stored in the APIM cache which is mapped to session key has an invalid signature. Though the JWT itself is valid, however, does not have any valid signature and it is causing the issue at various downstream levels where JWT validation failing.

![Image](https://github.com/user-attachments/assets/4ca099ed-f28e-4e8e-8666-39753b4e0a99)

![Image](https://github.com/user-attachments/assets/65c265b3-41b4-46ae-9213-c8a20bb5ec0e)

Further using the token in exchange flows through MSAL or Azure.Identity also deems the signature invalid -

![Image](https://github.com/user-attachments/assets/b31c67e6-c7be-47eb-9d01-4a75c37c424b)

Is it because we are assigned APIMGatewayURL as an issuer while the issuer in the token is different (https://sts.windows.net/tenantId) ?
@prjhawar @jukasper - Kindly help with this issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.