Building and customizing solutions using Microsoft 365 Copilot APIs and tools
A 401 in a Copilot Studio REST/API connector means the downstream API rejected the request as unauthorized. Copilot Studio itself doesn’t surface the full raw HTTP request, so debugging focuses on:
- Verify and tighten connector inputs
- Open the agent in Copilot Studio.
- If the connector is configured as an agent-wide action:
- Go to Agents → select the agent.
- Select Actions → choose the connector action (for example, your REST action).
- Select Inputs and review values such as URL, headers (Authorization, API keys, etc.), and body.
- If the connector is used in a topic-specific action:
- Go to Agents → select the agent.
- Select Topics → open the topic that calls the connector.
- On the topic canvas, select the connector node.
- Under Inputs, check the parameters that are mapped from user input.
- Select Advanced inputs to review additional headers, query parameters, or body fields.
- Ensure the Authorization header or other auth parameters are correctly set and not empty or malformed.
- Reproduce the call outside Copilot Studio
To see the exact HTTP behavior, reproduce the same request with a tool such as
curlor Postman:- Take the URL, HTTP method, headers, and body from the connector configuration.
- Run a
curlcommand similar to:curl -i -X <HTTP_METHOD> \ -H "Accept: application/json" \ -H "User-Agent: azure-data-factory/2.0" \ -H "Authorization: <your token or key>" \ -H "<any-other-header>: <value>" \ -d '<HTTP body>' \ <URL> - If
curlalso returns 401, the issue is with the API’s auth configuration (token, key, client ID/secret, or scope), not Copilot Studio. Fix it untilcurlreturns 200, then mirror the working values back into the connector configuration.
- Check the API’s own logs
- Use the logging/monitoring of the target API (for example, Application Insights for Azure Functions or your web API) to see incoming requests and why they were rejected.
- Specifically look for 401/403 entries and error messages such as “invalid token,” “signature validation failed,” or “missing API key.”
- Common 401 causes to verify
- Expired or invalid access token or API key.
- Wrong audience/scope in the token.
- Missing required header (for example,
Authorization,Ocp-Apim-Subscription-Key, or a custom header). - Endpoint URL mismatch (calling a different environment or path than the one the token/key is valid for).
Because Copilot Studio doesn’t expose a raw trace of the outbound HTTP call, the practical way to “see” the exact call is to:
- Mirror the connector configuration into an external HTTP client (curl/Postman).
- Use the target API’s logging to inspect the received request and error details.
References: