Report post

What is allowed token audiences?

The "Allowed token audiences" option is meant to provide additional audiences, such as if you were using a custom domain, etc. This is certainly confusing. There are probably UX improvements that could communicate this better (info balloon, list entries that can't be removed, etc.).

How do I change a token audience in a web app?

OR you can navigate to portal and click on Advanced section of authentication and update the Allowed Token Audiences with the value of web app. With the current app service changes, it can be done automatically but good to check this configuration.

Does allow token audience validate a client ID?

I had thought Allow Token Audience would validate the audience ( aud) claim of my JWT token - which for my JWT token matches my Client Id. This does not appear to be the case. All the values I supplied for Allow Token Audience are incorrect, but users are still successfully authenticated. How is Allow Token Audience supposed to be used?

The World's Leading Crypto Trading Platform

Get my welcome gifts