<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OIDC Setup – &amp;quot;Failed to decrypt ID token&amp;quot; Error with Azure AD in Integration, Extension &amp; APIs</title>
    <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541130#M22717</link>
    <description>&lt;P&gt;Hi, afak Qlik Cloud does not support implicit grant flow, instead try and use an authorization code flow in Azure AD (Entra) See if that helps.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bjorn_Wedbratt_0-1768836256980.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/186296iE18E941766AAC22A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bjorn_Wedbratt_0-1768836256980.png" alt="Bjorn_Wedbratt_0-1768836256980.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Bjorn&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jan 2026 15:24:38 GMT</pubDate>
    <dc:creator>Bjorn_Wedbratt</dc:creator>
    <dc:date>2026-01-19T15:24:38Z</dc:date>
    <item>
      <title>OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541073#M22715</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm trying to set up an OIDC connection between Qlik Cloud and Azure AD, but I'm encountering the following error during the validation step:&lt;/P&gt;&lt;P&gt;{ "status": "error", "protocol": "OIDC", "error": "Failed to decrypt ID token", "traceId": "&amp;lt;hidden&amp;gt;" }&lt;BR /&gt;Setup details:&lt;/P&gt;&lt;P&gt;Protocol: OIDC&lt;BR /&gt;Identity Provider: Azure AD&lt;BR /&gt;Redirect URI: https://&amp;lt;tenant&amp;gt;.&amp;lt;region&amp;gt;.qlikcloud.com/login/callback&lt;BR /&gt;(this URI is configured both in Azure and in Qlik)&lt;/P&gt;&lt;P&gt;What I've tried so far:&lt;/P&gt;&lt;P&gt;ID token issuance is enabled (enableIdTokenIssuance: true)&lt;/P&gt;&lt;P&gt;Implicit grant flow is enabled&lt;/P&gt;&lt;P&gt;Optional claims are configured: upn, email, groups&lt;/P&gt;&lt;P&gt;A client secret is registered&lt;/P&gt;&lt;P&gt;The app is registered as AzureADMyOrg&lt;/P&gt;&lt;P&gt;I'm not intending to encrypt the ID token, and have not configured any tokenEncryptionKeyId.&lt;/P&gt;&lt;P&gt;Still receiving the "Failed to decrypt ID token" error.&lt;/P&gt;&lt;P&gt;Try to understand :&lt;/P&gt;&lt;P&gt;Why would Qlik try to decrypt the token if no encryption was configured&lt;/P&gt;&lt;P&gt;Could this be caused by missing or misconfigured claims&lt;/P&gt;&lt;P&gt;Has anyone else encountered this ?&lt;/P&gt;&lt;P&gt;Thanks in advance for any suggestions or insights&lt;/P&gt;&lt;P&gt;Eyal&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/60539"&gt;@Benoit_C&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jan 2026 12:50:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541073#M22715</guid>
      <dc:creator>eyalnir_qlik</dc:creator>
      <dc:date>2026-01-18T12:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541130#M22717</link>
      <description>&lt;P&gt;Hi, afak Qlik Cloud does not support implicit grant flow, instead try and use an authorization code flow in Azure AD (Entra) See if that helps.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bjorn_Wedbratt_0-1768836256980.png" style="width: 400px;"&gt;&lt;img src="https://community.qlik.com/t5/image/serverpage/image-id/186296iE18E941766AAC22A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bjorn_Wedbratt_0-1768836256980.png" alt="Bjorn_Wedbratt_0-1768836256980.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Bjorn&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 15:24:38 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541130#M22717</guid>
      <dc:creator>Bjorn_Wedbratt</dc:creator>
      <dc:date>2026-01-19T15:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541236#M22725</link>
      <description>&lt;P&gt;Thanks for the reply, &lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/6112"&gt;@Bjorn_Wedbratt&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Just to clarify, we actually started without the implicit grant flow, following both Qlik and Azure documentation, and got the same error: "Failed to decrypt ID token".&lt;BR /&gt;Only after that did we try enabling implicit as a workaround, but it made no difference.&lt;BR /&gt;Also, we noticed that the enableIdTokenIssuance: true flag does not actually appear in the app manifest.&lt;BR /&gt;In any case, we're still getting the same error.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 10:02:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541236#M22725</guid>
      <dc:creator>eyalnir_qlik</dc:creator>
      <dc:date>2026-01-21T10:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541404#M22729</link>
      <description>&lt;P&gt;Hi Eyal&lt;BR /&gt;&lt;BR /&gt;Does the manifest include the following?:&lt;BR /&gt;"accessTokenAcceptedVersion": 2&lt;/P&gt;
&lt;P&gt;In the issuer URL, did you add v2.0?&lt;BR /&gt;&amp;lt;TENANT_ID&amp;gt;/v2.0&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;In the Azure logs, can you see that&amp;nbsp;sign-in = Success, while Qlik fails with &lt;EM data-start="2174" data-end="2192"&gt;decrypt ID token?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 14:18:41 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541404#M22729</guid>
      <dc:creator>JanJorissen</dc:creator>
      <dc:date>2026-01-23T14:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541484#M22730</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/61724"&gt;@JanJorissen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, it doesn't, see their manifest attached&amp;nbsp; (&lt;SPAN&gt;blurr&lt;/SPAN&gt;ed sensitive details)&lt;/P&gt;&lt;P&gt;also will check the logs for == success&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 10:40:28 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2541484#M22730</guid>
      <dc:creator>eyalnir_qlik</dc:creator>
      <dc:date>2026-01-25T10:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: OIDC Setup – "Failed to decrypt ID token" Error with Azure AD</title>
      <link>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2543038#M22768</link>
      <description>&lt;P&gt;After a lot of digging, we found the root cause in a customer's environment:&lt;/P&gt;&lt;P&gt;There was a duplicate Identity Provider (IdP) configured in the Qlik Cloud tenant.&lt;BR /&gt;Although only one was actively in use (Azure AD), the existence of another IdP caused Qlik to fail during token processing likely due to domain overlap or internal ambiguity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Qlik only supports a single IdP per tenant ,silently fail with misleading errors in this case:&lt;BR /&gt;"Failed to decrypt ID token"&lt;/P&gt;&lt;P&gt;Once the unused IdP was removed and only the correct one remained, the issue was resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;Suggestion to Qlik: This kind of case would benefit from a clearer error message.&lt;BR /&gt;For example:&lt;BR /&gt;"Multiple IdPs detected for this Qlik Cloud tenant. Please ensure only one is active."&lt;BR /&gt;…would make the issue easier to identify and resolve.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2026 08:19:08 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Integration-Extension-APIs/OIDC-Setup-quot-Failed-to-decrypt-ID-token-quot-Error-with-Azure/m-p/2543038#M22768</guid>
      <dc:creator>eyalnir_qlik</dc:creator>
      <dc:date>2026-02-15T08:19:08Z</dc:date>
    </item>
  </channel>
</rss>

