Bearer error="invalid_token": IDX10223: Lifetime validation failed. The token is expired / IDX10501: Signature validation failed
ASP.NET Core’s JwtBearer middleware rejected the token — expired (IDX10223), signature key not found (IDX10501/IDX10503), or wrong issuer/audience (IDX10214/IDX10205).
Seen on:
.NET
Meaning
The WWW-Authenticate header and logs carry the IDX code. Clock skew, keys rotated at the identity provider, Authority/Audience misconfiguration, or tokens for another API are common.
Common causes
- Token expired (IDX10223)
- Signing key not found / wrong authority (IDX10501, IDX10503)
- Audience mismatch (IDX10214)
- Issuer mismatch (IDX10205)
⚡ Quick fix
- Enable logging (IdentityModelEventSource.ShowPII in dev) to see details
- Set Authority and Audience to match the token
- Refresh tokens before expiry; allow small ClockSkew
Detailed fix by platform
C#
- csharp
builder.Services.AddAuthentication().AddJwtBearer(o => { o.Authority = "https://login.example.com/"; o.Audience = "api://orders"; });
How to diagnose
- Code — IDX number
- Token — iss/aud/exp claims
- Config — Authority/Audience
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026