IDX10223 🟪 .NET

Bearer error="invalid_token": IDX10223: Lifetime validation failed. The token is expired / IDX10501: Signature validation failed

ASP.NET Core’s JwtBearer middleware rejected the token — expired (IDX10223), signature key not found (IDX10501/IDX10503), or wrong issuer/audience (IDX10214/IDX10205).

Seen on: .NET

Meaning

The WWW-Authenticate header and logs carry the IDX code. Clock skew, keys rotated at the identity provider, Authority/Audience misconfiguration, or tokens for another API are common.

Common causes

  • Token expired (IDX10223)
  • Signing key not found / wrong authority (IDX10501, IDX10503)
  • Audience mismatch (IDX10214)
  • Issuer mismatch (IDX10205)

⚡ Quick fix

  1. Enable logging (IdentityModelEventSource.ShowPII in dev) to see details
  2. Set Authority and Audience to match the token
  3. Refresh tokens before expiry; allow small ClockSkew

Detailed fix by platform

C#

  1. csharp
    builder.Services.AddAuthentication().AddJwtBearer(o => {
        o.Authority = "https://login.example.com/";
        o.Audience = "api://orders";
    });

How to diagnose

  1. Code — IDX number
  2. Token — iss/aud/exp claims
  3. Config — Authority/Audience

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.