ID token validation failing after successful sign-in

Luca 20 Reputation points
2026-06-19T04:51:39.5833333+00:00

We're integrating our application with Microsoft Entra External ID using OpenID Connect. Users are able to sign in successfully, and we receive the ID token, but our application fails when validating the token signature.

We're currently not sure if we're using the correct signing certificates or metadata endpoint for validation.

Has anyone run into this issue before? Which endpoint should we be using to retrieve the signing keys, and is there anything specific we need to consider when validating tokens issued by Entra External ID?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
0 comments No comments

Answer accepted by question author
VEMULA SRISAI 13,990 Reputation points Microsoft External Staff Moderator
2026-06-19T05:12:12.8333333+00:00

Hello Luca,

From your description, the sign-in flow is working as expected, but the failure during token validation indicates that your application is not using the correct signing keys.

In Entra External ID, tokens are issued from the CIAM endpoint, and the signing keys are different from the standard Entra ID endpoints. If your application is currently fetching keys from login.microsoftonline.com, the kid in the token will not match, resulting in signature validation failure.

Update your application to use the tenant-specific OpenID Connect metadata endpoint for External ID:

https://<tenant-name>.ciamlogin.com/<tenant-id>/v2.0/.well-known/openid-configuration

From this endpoint:

  • Retrieve the jwks_uri
  • Use that JWKS endpoint to validate the token signature What to validate
  • Check the iss claim in the ID token — it must match your CIAM authority
  • Ensure the kid in the token header exists in the JWKS response
  • Do not use hardcoded or cached keys — always retrieve from metadataUpdate your application to use the tenant-specific OpenID Connect metadata endpoint for External ID:
      https://<tenant-name>.ciamlogin.com/<tenant-id>/v2.0/.well-known/openid-configuration
    
    From this endpoint:
    • Retrieve the jwks_uri
  • Use that JWKS endpoint to validate the token signature Why this happens

This issue occurs when there is a mismatch between:

  • Token issuer (ciamlogin.com)
  • Key discovery endpoint (login.microsoftonline.com)

Because of this mismatch, the validator cannot find the correct signing key and fails validation.

Once the authority and metadata endpoint are aligned with your External ID tenant, the token validation should succeed.

Was this answer helpful?

1 person found this answer helpful.

0 additional answers

Sort by: Newest

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.