Formerly known as Azure AI Services or Azure Cognitive Services is a unified collection of prebuilt AI capabilities within the Microsoft Foundry platform
The error occurs because the agent now uses a tool (Azure AI Search knowledge base) that is configured with On-Behalf-Of (OBO) authentication. Tools configured with OBO auth cannot be invoked when the caller authenticates with an API key. After adding the knowledge base, the agent’s tool stack changed, so the same API key–based call that worked before is now rejected.
To call this agent successfully, use an authentication method that issues a bearer token instead of an API key, and keep using the same Responses API endpoint pattern. For agent applications, this means:
- Authenticate with Microsoft Entra ID to obtain an access token for
https://ai.azure.com. - Call the same Responses API endpoint, but pass the token in the
Authorization: Bearer <token>header instead ofapi-key.
This aligns with the documented behavior for published Agent Applications:
- The Responses API protocol is the correct way to invoke a published agent application.
- When tools require downstream access (for example, to Azure AI Search) using OBO or RBAC-based auth, the caller must also use token-based auth so the service can perform delegated access checks.
If API key–only access is required, remove or reconfigure tools that use OBO auth (such as the knowledge base connection) so that no tool in the agent requires OBO. Otherwise, keep the knowledge base and switch to Entra ID–based bearer token authentication.
References: