Azure Storage SAS Debugger
Find expiry, permission, and resource mismatches behind a failed SAS request
Checks run in your browser. The link is not opened. A SAS URL grants access; use a test link when possible.
SAS dates and permissions
A token that allows a single upload may still fail when an SDK uploads blocks. Choose the operation that failed to check its permissions and resource scope.
For a 403 response, select the error code returned by Azure to see the relevant checks.
Debug Azure SAS 403 errors
AuthenticationFailed can point to timing, encoding, or a changed signature. AuthorizationPermissionMismatch points to the request's permission requirements. The exact Blob operation matters: listing a container and downloading a blob require different permissions and resource scopes.
Start with the original SAS value and the operation that failed. Follow the Azure SAS 403 troubleshooting guide for CLI and request examples.
SAS types and access policies
Account, service, and user delegation SAS use different signed fields. The operation checks here cover Blob Storage REST requests. If the dates and permissions look correct, check the stored access policy, credential revocation, firewall rules, RBAC, and container encryption-scope policy that apply to the request.
Use an Azure SDK or Storage Explorer to create a replacement SAS. Changing a signed permission or expiry invalidates its signature. For deployment identity failures, use the Entra Federated Credential Debugger.
Microsoft's Azure Storage 403 referenceInputs are not saved. The site may load analytics and advertising. Privacy details.