AADSTS7000222: The provided client secret keys for app are expired
The app registration’s client secret has expired, so service-to-service authentication fails.
Seen on:
Azure
Meaning
Client secrets expire (max 24 months, often 6–12). Pipelines, apps and integrations break on the expiry date. Rotate the secret, or move to certificates/managed identity/workload identity federation.
Common causes
- Client secret past its expiry date
- App still configured with an old secret after rotation
⚡ Quick fix
- Create a new secret and update every consumer (Key Vault, pipelines)
- Delete the expired secret
- Prefer managed identity or federated credentials
Detailed fix by platform
Azure CLI
- bash
az ad app credential list --id <app-id> --query "[].{name:displayName,end:endDateTime}" az ad app credential reset --id <app-id> --append --years 1
How to diagnose
- Expiry — Credential end dates
- Consumers — Where the secret is stored
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026