AADSTS7000222 🔷 Azure

AADSTS7000222: The provided client secret keys for app are expired

The app registration’s client secret has expired, so service-to-service authentication fails.

Seen on: Azure

Meaning

Client secrets expire (max 24 months, often 6–12). Pipelines, apps and integrations break on the expiry date. Rotate the secret, or move to certificates/managed identity/workload identity federation.

Common causes

  • Client secret past its expiry date
  • App still configured with an old secret after rotation

⚡ Quick fix

  1. Create a new secret and update every consumer (Key Vault, pipelines)
  2. Delete the expired secret
  3. Prefer managed identity or federated credentials

Detailed fix by platform

Azure CLI

  1. bash
    az ad app credential list --id <app-id> --query "[].{name:displayName,end:endDateTime}"
    az ad app credential reset --id <app-id> --append --years 1

How to diagnose

  1. Expiry — Credential end dates
  2. Consumers — Where the secret is stored

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.