Azure Storage: Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature (AuthenticationFailed)
The storage request’s signature or SAS token is invalid — wrong/rotated account key, expired SAS, or clock skew.
Seen on:
Azure
Meaning
Shared Key and SAS signatures depend on the key, the exact request and the time. Rotated keys, SAS tokens outside their start/expiry window, mangled URL encoding, or a machine clock off by more than 15 minutes all fail.
Common causes
- Account key rotated/old connection string
- SAS expired or start time in the future
- SAS URL-encoding broken (+ or %2B)
- System clock skew
- Signed resource/permissions don’t match the operation
⚡ Quick fix
- Regenerate the connection string/SAS from current keys
- Set SAS start time a few minutes in the past
- Sync the system clock
Detailed fix by platform
Azure CLI
- bash
az storage account keys list -n stapp -g rg --query "[0].value" -o tsv az storage container generate-sas --account-name stapp -n data --permissions rl --expiry 2026-12-31T00:00Z --auth-mode login --as-user
How to diagnose
- Detail — AuthenticationErrorDetail text
- Times — SAS st/se vs current UTC
- Key — Which key was used?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Azure
- App Service Application Error Azure App Service: ":( Application Error" / container didn’t respond to HTTP pings
- AuthorizationFailed Azure: AuthorizationFailed — The client does not have authorization to perform action
- SkuNotAvailable Azure: SkuNotAvailable / QuotaExceeded when creating a VM or resource
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026