Entra Federated Credential Debugger
Compare OIDC claims with the credential configured for your Azure workload
Comparison stays in your browser. Use claims JSON when possible; a complete OIDC token can grant access. No token is sent to Azure.
Issuer, subject, and audience
Entra compares these values exactly. Letter case, trailing slashes, and encoded characters can cause a mismatch.
For AADSTS70021 or AADSTS700213, use the assertion and credential from the failing job.
AADSTS70021 and AADSTS700213
These errors report that Entra could not find a matching federated identity credential. Check the issuer (iss), subject (sub), and audience (aud) against the credential on the application or managed identity used by the job.
A GitHub environment subject differs from a branch subject. An AKS issuer's final slash matters. Use the actual values from the failing run. The Entra federation troubleshooting guide includes read-only commands to retrieve your configuration.
Exact subjects and matching expressions
Standard federated credentials require an exact subject match. For a credential with claimsMatchingExpression, issuer and audience are compared here; review the expression against Microsoft's rules for your issuer.
For general claims, use JWT Decode. For storage links that return 403, use the Azure Storage SAS Debugger. A successful token exchange can still be followed by a separate RBAC or resource access error.
Microsoft's federation considerationsInputs are not saved. The site may load analytics and advertising. Privacy details.