Encrypt Online
Theme

Entra Federated Credential Debugger

Compare OIDC claims with the credential configured for your Azure workload

Comparison stays in your browser. Use claims JSON when possible; a complete OIDC token can grant access. No token is sent to Azure.

Token and credentialFor GitHub Actions, AKS, and other OIDC workloads

Use the OIDC token sent to Entra for the exchange, not the Azure access token returned afterward.

Paste one credential or the list returned by Azure CLI. Credentials inside an ARM properties object also work.

Reference time for assertion expiry

Leave empty to use the current time. Time checks apply when exp, nbf, or iat is supplied.

Issuer, subject, and audience

Entra compares these values exactly. Letter case, trailing slashes, and encoded characters can cause a mismatch.

For AADSTS70021 or AADSTS700213, use the assertion and credential from the failing job.

AADSTS70021 and AADSTS700213

These errors report that Entra could not find a matching federated identity credential. Check the issuer (iss), subject (sub), and audience (aud) against the credential on the application or managed identity used by the job.

A GitHub environment subject differs from a branch subject. An AKS issuer's final slash matters. Use the actual values from the failing run. The Entra federation troubleshooting guide includes read-only commands to retrieve your configuration.

Exact subjects and matching expressions

Standard federated credentials require an exact subject match. For a credential with claimsMatchingExpression, issuer and audience are compared here; review the expression against Microsoft's rules for your issuer.

For general claims, use JWT Decode. For storage links that return 403, use the Azure Storage SAS Debugger. A successful token exchange can still be followed by a separate RBAC or resource access error.

Microsoft's federation considerations

Inputs are not saved. The site may load analytics and advertising. Privacy details.