AuthenticationFailed 🔷 Azure

Azure Storage: Server failed to authenticate the request. Make sure the value of Authorization header is formed correctly including the signature (AuthenticationFailed)

The storage request’s signature or SAS token is invalid — wrong/rotated account key, expired SAS, or clock skew.

Seen on: Azure

Meaning

Shared Key and SAS signatures depend on the key, the exact request and the time. Rotated keys, SAS tokens outside their start/expiry window, mangled URL encoding, or a machine clock off by more than 15 minutes all fail.

Common causes

  • Account key rotated/old connection string
  • SAS expired or start time in the future
  • SAS URL-encoding broken (+ or %2B)
  • System clock skew
  • Signed resource/permissions don’t match the operation

⚡ Quick fix

  1. Regenerate the connection string/SAS from current keys
  2. Set SAS start time a few minutes in the past
  3. Sync the system clock

Detailed fix by platform

Azure CLI

  1. bash
    az storage account keys list -n stapp -g rg --query "[0].value" -o tsv
    az storage container generate-sas --account-name stapp -n data --permissions rl --expiry 2026-12-31T00:00Z --auth-mode login --as-user

How to diagnose

  1. Detail — AuthenticationErrorDetail text
  2. Times — SAS st/se vs current UTC
  3. Key — Which key was used?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.