web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Power Automate / Can't trigger the Powe...
Power Automate
Unanswered

Can't trigger the Power Automate workflow with error "Token must be a valid JWT signed with HS256"

(1) ShareShare
ReportReport
Posted on by 2
I find that part of my Power Automate cloud workflows can't trigger to run successfully with below error messages:
 
Error from token exchange: Bad Key authorization token. Token must be a valid JWT signed with HS256
Failed to validate token: IDX10223: Lifetime validation failed. The token is expired. ValidTo (UTC): ''11/13/2024 9:35:31 AM', Current time (UTC): '5/16/2025 6:52:55 AM'.
 
But if I edit the Power Automate and save it directly without any changes, this Power Automate can trigger by user event and run with positive result. Why?
 
Here is some information for my Power Automate workflow setup:
1.) The trigger point of the Power Automate is "List Item created or updated" in a M365 SharePoint list.
2.) The Power Automate is created by a Azure account that should be changed password frequently in local AD Windows server.
3.) The local AD account will then synchronize to Azure AD.
4.) The error Power Automate may not be triggered by end user over few months and if the Power Automate turns off by the system automatically, we will turn it on again manually or by scheduled task without any saving.
 
Categories:
I have the same question (0)
  • yashag2255 Profile Picture
    24,769 Super User 2024 Season 1 on at
     
    I have seen such issues happen when there are policies implemented on the tenant level that require users to change passwords frequently or else the authentication tokens are expired. 
     
    Below are a few work arounds you can implement: 
    1. If possible, get the account that is being used for the flows removed from the policy (just have MFA but without a requirement to change password frequently)
    2. If the actions you are using in the flows can be achieved by using HTTP actions by calling direct api requests, you can configure service principals and use azure key vault to get the credential, authenticate and then use the token to call the action. (this would require you to re build the entire flow and certain actions/connectors may not have direct api requests exposed)
     
    Hope this helps!
     
    If this reply has answered your question or solved your issue, please mark this question as answered. Answered questions helps users in the future who may have the same issue or question quickly find a resolution via search. If you liked my response, please consider giving it a thumbs up. THANKS!

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Power Automate

#1
Michael E. Gernaey Profile Picture

Michael E. Gernaey 501 Super User 2025 Season 2

#2
Tomac Profile Picture

Tomac 323 Moderator

#3
abm abm Profile Picture

abm abm 237 Most Valuable Professional

Last 30 days Overall leaderboard