Un servizio di Azure che fornisce archiviazione universale ospitata per le configurazioni app di Azure.
Hello Andrea Zacconi,
Thank you for the detailed information and logs.
Based on your description, the issue is occurring within the federation flow between Microsoft Entra External ID and the EU Login IdP, and not in your application. The AADSTS40016 error indicates that Entra External ID received an error response from the external identity provider, which aligns with the feedback from EU Login stating that the authorization code is being rejected due to reuse (single-use violation).
In a standard OIDC federation flow, Microsoft Entra External ID acts as an intermediary and is expected to redeem the authorization code once at the IdP token endpoint before issuing its own response back to the application. Since your application is not receiving an authorization code at /signin-oidc and only receives the final error, this confirms that the failure happens before the response is returned to your app, i.e., during the Entra ↔ EU Login exchange.
At present, there is no known documented behavior where Entra External ID performs duplicate authorization code redemption in a valid flow. When an IdP reports duplicate redemption, it is typically associated with one of the following conditions at the federation boundary:
- Retry or parallel token requests (for example, due to transient failures or timeouts)
- Misconfiguration of redirect URI or token endpoint leading to repeated exchanges
IdP-side validation or handling causing the same code to be treated as reused
Recommended next steps
To isolate the root cause, please validate the following:
- From EU Login side:
- Confirm if multiple token requests are received for the same authorization code
- Check timestamps to determine if they are near-simultaneous (parallel) or retries
- Ensure the redirect URI exactly matches the federation endpoints configured in both systems
- Verify token endpoint and client authentication settings are aligned
- From testing perspective:
- Execute the flow using Entra “Run user flow” to confirm whether the issue reproduces without the application
- If possible, capture a network trace (HAR/Fiddler) to validate if multiple backend calls are triggered.