How to Get a SharePoint Access Token in Java for File Uploads
Question details
The user needs to authenticate a Java application to obtain an access token for uploading files to SharePoint.

- Product
- SharePoint
- Device & OS
- not provided
- Scenario
- Developing a Java application or background service that programmatically uploads files to a SharePoint document library.
- Observed behavior
- SharePoint user permissions do not automatically pass tokens to the Java environment; explicit authentication via Microsoft Entra ID (OAuth) is required.
Ensure you have administrator access to the Microsoft Entra ID (formerly Azure AD) portal to register your application and configure API permissions.
Register the Application in Microsoft Entra ID
Before requesting a token, your application must be registered in Microsoft Entra ID to establish its identity and define its permissions.
Microsoft uses OAuth 2.0 for authentication. You must decide between delegated permissions (if a user is signing in) or application permissions (for automated, unattended background services). For automated Java uploads, application permissions are typically used.
Sign in to the Azure Portal, navigate to 'Microsoft Entra ID', select 'App registrations', and click 'New registration'. Give your application a name and register it.
Go to 'API permissions' > 'Add a permission'. Select 'Microsoft Graph' or 'SharePoint'. Choose 'Application permissions' (for background apps) and select the required file scopes, such as 'Sites.ReadWrite.All'.
Click 'Grant admin consent for [Your Organization]' to apply the permissions. Without this step, the application will be denied access.
Navigate to 'Certificates & secrets', click 'New client secret', and save the generated secret value immediately. You will need this, along with the Client ID and Tenant ID, in your Java code.

Request and Use the Token in Java
Use standard Java HTTP libraries to request the access token from Microsoft's identity platform and attach it to your upload request.
Manage Documents Effortlessly with WPS Office
While integrating custom Java apps with SharePoint requires setting up complex OAuth flows, handling everyday document editing shouldn't be difficult. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office for creating, viewing, and editing your essential files.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install and Launch: Run the installer, follow the on-screen prompts, and launch the application.
- 3. Edit Your Documents: Open your existing Microsoft Office files instantly with perfect formatting preservation.

Frequently Asked Questions
Can I reuse a signed-in user's existing SharePoint token in my Java app?
No. There is no supported method to directly retrieve or reuse a user's session token from a browser. Your application must explicitly authenticate and request its own access token via Microsoft Entra ID using standard OAuth 2.0 flows.
What is the difference between delegated and application permissions?
Delegated permissions are used when an application acts on behalf of a signed-in user, meaning the app can only access what the user can. Application permissions are used for automated, background tasks where the application authenticates itself using a client secret or certificate without a user present.
Which REST API endpoint should I use to upload files to SharePoint?
While the legacy SharePoint REST API is still functional, Microsoft strongly recommends using the Microsoft Graph API (`https://graph.microsoft.com/v1.0/sites/...`) for modern integrations and file uploads in Java.
Why am I getting an 'Unauthorized' error when sending my file upload request?
This usually happens if the access token has expired (they are typically valid for one hour), if the token was requested for the wrong scope, or if you forgot to prefix the token with 'Bearer ' in the Authorization header of your HTTP request.




