Encrypt Online
Theme

Azure Storage SAS Debugger

Find expiry, permission, and resource mismatches behind a failed SAS request

Checks run in your browser. The link is not opened. A SAS URL grants access; use a test link when possible.

SAS URL and requestNo Azure login or account key needed
Azure error code and reference time

Use the specific error code in the response body or x-ms-error-code header.

Leave empty to use the current time. Set the failure time when investigating an older request.

SAS dates and permissions

A token that allows a single upload may still fail when an SDK uploads blocks. Choose the operation that failed to check its permissions and resource scope.

For a 403 response, select the error code returned by Azure to see the relevant checks.

Debug Azure SAS 403 errors

AuthenticationFailed can point to timing, encoding, or a changed signature. AuthorizationPermissionMismatch points to the request's permission requirements. The exact Blob operation matters: listing a container and downloading a blob require different permissions and resource scopes.

Start with the original SAS value and the operation that failed. Follow the Azure SAS 403 troubleshooting guide for CLI and request examples.

SAS types and access policies

Account, service, and user delegation SAS use different signed fields. The operation checks here cover Blob Storage REST requests. If the dates and permissions look correct, check the stored access policy, credential revocation, firewall rules, RBAC, and container encryption-scope policy that apply to the request.

Use an Azure SDK or Storage Explorer to create a replacement SAS. Changing a signed permission or expiry invalidates its signature. For deployment identity failures, use the Entra Federated Credential Debugger.

Microsoft's Azure Storage 403 reference

Inputs are not saved. The site may load analytics and advertising. Privacy details.