Managing external identities to enable secure access for partners, customers, and other non-employees
Hello Luca,
From your description, the sign-in flow is working as expected, but the failure during token validation indicates that your application is not using the correct signing keys.
In Entra External ID, tokens are issued from the CIAM endpoint, and the signing keys are different from the standard Entra ID endpoints. If your application is currently fetching keys from login.microsoftonline.com, the kid in the token will not match, resulting in signature validation failure.
Update your application to use the tenant-specific OpenID Connect metadata endpoint for External ID:
https://<tenant-name>.ciamlogin.com/<tenant-id>/v2.0/.well-known/openid-configuration
From this endpoint:
- Retrieve the
jwks_uri - Use that JWKS endpoint to validate the token signature What to validate
- Check the
issclaim in the ID token — it must match your CIAM authority - Ensure the
kidin the token header exists in the JWKS response - Do not use hardcoded or cached keys — always retrieve from metadataUpdate your application to use the tenant-specific OpenID Connect metadata endpoint for External ID:
From this endpoint:https://<tenant-name>.ciamlogin.com/<tenant-id>/v2.0/.well-known/openid-configuration- Retrieve the
jwks_uri
- Retrieve the
- Use that JWKS endpoint to validate the token signature Why this happens
This issue occurs when there is a mismatch between:
- Token issuer (ciamlogin.com)
- Key discovery endpoint (login.microsoftonline.com)
Because of this mismatch, the validator cannot find the correct signing key and fails validation.
Once the authority and metadata endpoint are aligned with your External ID tenant, the token validation should succeed.