how to fix signin issue. AADSTS501209: JWT signature is invalid [Reason - The key used is expired

Brenda Knight 0 Reputation points
2026-10-05T14:59:52.12+00:00

how to fix signin issue. AADSTS501209: JWT signature is invalid [Reason - The key used is expired.

I have an active Office 365 account which is current.

Microsoft 365 and Office | Subscription, account, billing | For business | Windows
0 comments No comments

1 answer

Sort by: Most helpful
  1. Roebe Ta 1,545 Reputation points Independent Advisor
    2026-10-05T15:12:16.43+00:00

    Hello @Brenda Knight,

    I hope you're doing well. 

    Based on my research, the error "AADSTS501209: JWT signature is invalid (key expired) " usually indicates that the JWT token is signed using an expired key (certificate or client secret) configured on the Microsoft Entra ID (Azure AD) app registration. 

    Once the signing key reaches its End date, Microsoft Entra ID will no longer accept tokens signed with it, resulting in the JWT signature validation failure. 

    To troubleshoot and resolve, you can try these steps: 

    1. Find your IT admin/Microsoft 365 admin to assist with this kind of issue.  

    If you haven’t yet reached out, here’s a helpful guide to locate your Microsoft 365 administrator: How do I find my Microsoft 365 admin? - Microsoft Support  

    2.Check credentials in the Azure Portal 

    • Sign in to Microsoft Entra ID at https://entra.microsoft.com using an administrator account. 
    • Navigate to Microsoft Entra ID > App registrations > All applications. 
    • Paste the Application (client) ID into the search box, or locate it directly in the Application (client) ID column. 

    User's image

    • Click on the app's Display name. 
    • Navigate to Certificates & secrets.  
    • Check and verify whether any credential has an End date in the past or matching the date shown in the error: 
      • Certificates under Certificates 
      • Client secrets under Client secrets

    User's image

     

    3. Rotate the expired credential (required) 

    If using a certificate 

    • Upload a new certificate 
    • Ensure the new certificate has a valid future expiration date 
    • Update the application/service to use the new certificate 

    User's image

     

    If using a client secret 

    • Create a new client secret 

    User's image

    • Copy the secret value immediately 
    • Update the application configuration with the new secret 

    The expired credential cannot be reused once its end date has passed. 

     

    4. (Optional) Verify via Microsoft Graph 

    You can also inspect configured credentials using Microsoft Graph using the instructions:  

    Review: 

    • keyCredentials > certificates 
    • passwordCredentials > client secrets 
    • Check the endDateTime values for expiration. 

    Note: Ensure you are using the correct Graph endpoint if the tenant is in a national cloud (GCC, Germany, China, etc.). 

    Once the credential is renewed and the application updated, authentication should succeed. 

    Please let me know if the issue persists. I'll be happy to assist further. 


    If the answer is helpful, please click "Yes, Accept Answer". If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in the forum documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.