← cd ~/errors
// entra id sign-in error · app registration and tokens
AADSTS50146
MissingCustomSigningKey
What it means
The app needs an app-specific signing key, which is missing, expired or not yet valid.
How to fix it
Check the SAML signing certificate on the Enterprise App and its expiry.
How to investigate
- Compare what the app sends (client ID, redirect URI, scopes, tenant) with the app registration.
- Decode the token or request: the JWT and SAML decoders on this site show exactly what was sent.
- Check the app's credentials (secrets and certificates) and whether the service principal exists and is enabled in this tenant.
- Search the sign-in logs for the request ID or correlation ID from the troubleshooting details on the error page.
Guides on this site
Tools that help
Error names and meanings follow Microsoft's error code reference. The fixes are this site's guidance.