# Azure OIDC Client Credentials Flow - 500 Error

**URL:** <https://forum.weaviate.io/t/azure-oidc-client-credentials-flow-500-error/113>\
**Category:** Support\
**Created:** [May 31, 2023, 3:06pm UTC](https://forum.weaviate.io/t/azure-oidc-client-credentials-flow-500-error/113 "2023-05-31T15:06:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![belovm](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/belovm/32/112_2.png) [@belovm](https://forum.weaviate.io/u/belovm)\
**Post date:** [May 31, 2023, 3:06pm UTC](https://forum.weaviate.io/t/azure-oidc-client-credentials-flow-500-error/113/1 "2023-05-31T15:06:15Z")

</div>

Hi! I am setting up OIDC authentication to Weaviate on AKS with client credentials flow in Azure, and keep running into this error when trying to connect:

`UnexpectedStatusCodeException: Meta endpoint! Unexpected status code: 500, with response body: {'code': 500, 'message': "oidc: token doesn't contain required claim 'email'"}.`

I am using this code for testing the connection:

```auto
client_credentials_config = weaviate.AuthClientCredentials(
  client_secret = client_secret
  )
client = weaviate.Client(ip_url,
                         auth_client_secret=client_credentials_config,
                        )
client.schema.get() # Get the schema to test connection

```

Here is my Weaviate authentication config:

```auto
oidc:
    enabled: true
    issuer: https://login.microsoftonline.com/{tenant_id}/v2.0
    username_claim: email
    groups_claim: groups
    client_id: {client_id}
    scope: email

```

I do have email claim added as part of the token configuration. Any help is appreciated, thanks!

---

<div class="post-metadata">

**Author:** ![jphwang](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/jphwang/32/38_2.png) [@jphwang](https://forum.weaviate.io/u/jphwang)\
**Post date:** [June 12, 2023, 6:29pm UTC](https://forum.weaviate.io/t/azure-oidc-client-credentials-flow-500-error/113/2 "2023-06-12T18:29:24Z")

</div>

Hi @belovm - did you end up resolving this? (Sorry it seems to have slipped through the cracks). Otherwise I can give this a bump and ask around internally.

Cheers,  
JP
