How to Fix Power Automate Get Item HTTP 403 Token Exchange Error
Question details
The user needs to resolve an HTTP 403 token exchange permission error occurring in Power Automate during a SharePoint Get item action.

- Product
- Power Automate & SharePoint
- Device & OS
- not provided
- Scenario
- Running a Power Automate flow that utilizes the SharePoint Get item action to retrieve data from a list.
- Observed behavior
- The flow fails and returns an HTTP 403 error related to token exchange permissions, despite the connection appearing active and the user having Full Control access.
Ensure you have your Microsoft 365 account credentials ready, as you will need to reauthenticate your SharePoint connections.
Reauthorize or Create a New SharePoint Connection
The most common cause for a token exchange error is an expired or corrupted authentication token in the connection reference.
Even if a connection appears 'active' in the interface, the underlying OAuth token used to communicate with SharePoint may have expired or been invalidated by recent security changes in your Microsoft tenant. Rebuilding this token solves the majority of 403 errors.
Log into Power Automate, expand the 'Data' section in the left navigation pane, and click on 'Connections'.
Find your SharePoint connection in the list. If it has a 'Fix connection' warning, click it. Otherwise, click the three dots (...) next to it and select 'Switch account' or 'Update'.
Sign in using your Microsoft 365 credentials to generate a fresh authentication token.
Open the failing flow in Edit mode. Expand the 'Get item' action, ensure the newly refreshed connection is selected at the bottom, and save the flow before testing again.

Verify Permissions and Conditional Access Policies
Tenant-level security policies or altered list permissions might be blocking the flow from validating your token.
Try WPS Office for Seamless Document Management
While troubleshooting complex Power Automate and SharePoint permission errors can be frustrating, managing your daily documents shouldn't be. WPS Office is a highly compatible, free, and lightweight suite that handles Word, Excel, and PowerPoint files natively without complicated connection tokens.
- 1. Download WPS Office: Visit the official WPS website to download and install the software for free on your device.
- 2. Open Your Documents: Launch WPS Office and directly open your existing Word, Excel, and PowerPoint files with perfect formatting compatibility.
- 3. Edit and Collaborate: Use the familiar interface to edit your documents seamlessly and save them locally or to your preferred cloud drive.

Frequently Asked Questions
What does HTTP 403 token exchange error mean in Power Automate?
It indicates that the Power Automate flow was unable to successfully authenticate with SharePoint. Although credentials might be present, the security token required to authorize the specific 'Get item' action could not be generated or exchanged, often due to an expired OAuth token.
Why does my connection show as 'active' but still throws a 403 error?
The user interface often caches the connection status. Even if it says active, the underlying authentication token may have expired or been revoked by a backend security policy change, requiring manual reauthorization.
Can Azure AD Conditional Access policies cause Power Automate failures?
Yes. If your organization enforces strict Conditional Access policies (such as requiring Multi-Factor Authentication for certain apps or blocking access from unauthorized IP ranges), these rules can block Power Automate from successfully refreshing its connection tokens.




