How to Fix OneDrive Preauthenticated Download URL HTTP 401 Error
Question details
Users encounter an HTTP 401 Unauthorized error when attempting to download content via a Microsoft Graph OneDrive preauthenticated URL.

- Product
- Microsoft Graph OneDrive API
- Device & OS
- not provided
- Scenario
- A developer or application is requesting file content from OneDrive using a preauthenticated download URL provided by Microsoft Graph.
- Observed behavior
- Adding the original bearer token to the preauthenticated download URL request results in a 401 Unauthorized response for certain customer accounts.
Verify your API client's configuration to see if it automatically appends authorization headers to all outgoing HTTP requests.
Remove the Bearer Token from the Request Header
Preauthenticated URLs contain built-in authorization in their query parameters. Sending an extra bearer token in the header causes authentication conflicts.
When Microsoft Graph returns a preauthenticated download URL, the URL itself is designed to grant access without requiring additional authentication tokens. If your HTTP client automatically attaches your original bearer token to this URL, the OneDrive API might reject the request with a 401 error.
Review your code (such as Axios interceptors, Fetch wrappers, or HttpClient configuration) to identify if an Authorization header is globally applied to all requests.
Modify your application logic to exclude the 'Authorization: Bearer <token>' header specifically when making GET requests to the preauthenticated download URL.
Send a standard GET request to the preauthenticated URL without the bearer token to verify that the file downloads successfully.
Contact Microsoft 365 Support for Account Investigation
If removing the bearer token does not resolve the issue, the problem may be linked to specific tenant policies or account configurations.
Need a Simpler Way to Manage Documents? Try WPS Office
While resolving Microsoft API and OneDrive authentication errors can be complex, editing your daily documents doesn't have to be. WPS Office offers a free, lightweight, and highly compatible alternative to Microsoft Office.
- 1. Download the Installer: Visit the official WPS Office website and click the free download button for your operating system.
- 2. Install WPS Office: Run the downloaded installer file and follow the quick on-screen instructions.
- 3. Open Your Documents: Launch WPS Office and instantly open, edit, or save any of your existing Microsoft Office files.

Frequently Asked Questions
What is a preauthenticated download URL in Microsoft Graph?
A preauthenticated download URL is a special link generated by the OneDrive API that contains embedded authentication tokens. It allows direct, short-term access to download a specific file without needing standard HTTP authorization headers.
Why does adding a bearer token cause a 401 error?
When you append a bearer token to a request that already uses a preauthenticated URL, the OneDrive API receives conflicting authentication methods. This mismatch often triggers a 401 Unauthorized response depending on the specific tenant's security configuration.
Do I need to generate a new token for preauthenticated URLs?
No. Preauthenticated URLs are designed to be used exactly as they are returned by Microsoft Graph. You do not need to generate or attach a new bearer token to access them.
How long is a preauthenticated download URL valid?
The validity duration is typically very short, often only a few minutes, as it is designed for immediate download operations. If the URL expires, you must make a new Microsoft Graph request to obtain a fresh download URL.




