logo
search
OneDrive Error Codes

Fix Microsoft Graph OneDrive Download 401 Unauthorized Error

Kushani NimanthikaKushani Nimanthika Sep 30, 2026 869 views

Question details

Users or developers encounter an HTTP 401 Unauthorized error when attempting to download OneDrive files using the Microsoft Graph API.

How to Fix Microsoft Graph OneDrive Download Returns 401 Unauthorized
Product
Microsoft Graph API / OneDrive
Device & OS
not provided
Scenario
Downloading OneDrive files via a third-party application or WordPress plugin using the Microsoft Graph API.
Observed behavior
The application successfully locates or uploads files but fails with an HTTP 401 Unauthorized status when trying to retrieve and download the actual file content.
Before you start

Ensure you have administrative access to your application's source code or plugin settings, and verify that you can inspect the Microsoft Graph API access tokens being generated.

Solution 1Recommended

Verify Access Token and API Permissions

Ensure your application requests the correct scopes and uses a valid, unexpired token for the correct Microsoft account.

A 401 Unauthorized error usually indicates that the access token used in the API request is expired, invalid, or lacks the necessary permissions to read the file content.

1
Check token expiration

Microsoft Graph access tokens have a limited lifespan. Ensure your application requests a fresh access token using a refresh token before initiating the file download.

2
Verify API scopes

Confirm that your Azure Active Directory (Azure AD) app registration includes the 'Files.Read' or 'Files.ReadWrite' delegated or application permissions required for downloading files.

3
Validate the target resource

Ensure the access token is explicitly issued for the exact Microsoft 365 tenant and OneDrive account hosting the requested file. A token issued for a different resource will be rejected.

Verify Access Token and API Permissions
Security Best Practice: Always keep your access tokens and refresh tokens secure. Avoid logging them in plain text, and never expose authorization headers or upload-session URLs publicly.
Free Microsoft Office alternative

Need a Reliable Alternative for Managing Your Documents? Try WPS Office

While troubleshooting complex API and OneDrive integration errors for your applications, you still need a dependable tool for daily document management. WPS Office provides a lightweight, highly compatible, and free alternative to Microsoft Office, making it easier to create, edit, and manage your local and cloud documents seamlessly.

  1. 1. Download the installer: Visit the official WPS Office website and download the free installation package for your operating system.
  2. 2. Install the software: Run the installer and follow the simple on-screen instructions to set up WPS Office on your device.
  3. 3. Open and edit documents: Launch WPS Office to instantly open, edit, and save your Word, Excel, and PowerPoint files without any formatting loss.
Highly compatible with Microsoft Office file formats (.docx, .xlsx, .pptx)Lightweight and fast performance for daily productivity tasksBuilt-in cloud sync for easy file backup, sharing, and managementFree to use with a familiar, user-friendly interface
microsoft office alternative - wps office

Frequently Asked Questions

Why can my plugin upload to OneDrive but not download?

Uploading and downloading require different API permissions. If your access token only has write-specific scopes or lacks the 'Files.Read' permission, Microsoft Graph will accept the upload but return a 401 Unauthorized error during download attempts.

Should I disable SSL verification to bypass the 401 error?

No, you should never disable SSL certificate verification in your application. Doing so exposes your connection to severe security risks, such as man-in-the-middle attacks, and will not resolve the underlying Microsoft Graph authentication issues.

How do I fix an expired token error in Microsoft Graph?

You must implement an OAuth token refresh flow in your application. Use the refresh token provided during the initial authorization to request a new access token from the Microsoft identity platform without requiring further user interaction.