AADSTS70021: No matching federated identity record found for presented assertion (GitHub Actions / workload identity)
The OIDC token from GitHub Actions/Kubernetes/another IdP doesn’t match any federated credential on the app — issuer, subject or audience differ.
Seen on:
Azure
Meaning
Federated credentials match exactly on issuer and subject (e.g. repo:org/repo:ref:refs/heads/main or repo:org/repo:environment:prod). Running from another branch, a pull request, or an environment changes the subject.
Common causes
- Subject doesn’t match (branch vs environment vs pull_request)
- Wrong issuer URL
- Audience not api://AzureADTokenExchange
- Federated credential added to a different app
⚡ Quick fix
- Read the assertion’s subject from the error and add a matching federated credential
- Use environment-based subjects for deployment jobs
- Check the client ID used by azure/login
Detailed fix by platform
Azure CLI
az ad app federated-credential create --id <app-id> --parameters '{"name":"main","issuer":"https://token.actions.githubusercontent.com","subject":"repo:myorg/myrepo:ref:refs/heads/main","audiences":["api://AzureADTokenExchange"]}'
How to diagnose
- Subject — Value in the error message
- Credentials — az ad app federated-credential list
- Client ID — Same app?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026