<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't validate federated 'server-token' against Portal for ArcGIS self end point in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1683375#M43783</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to validate a token on the Portal for ArcGIS (11.5) Inspection end point (self) but I am noticing that when the token has been generated using "generateToken" endpoint to get a 'server-token' in exchange of a 'portal-token', then it does not work:&lt;/P&gt;&lt;P&gt;{"error": {&lt;BR /&gt;"code": 498,&lt;BR /&gt;"message": "Invalid token.",&lt;BR /&gt;"details": ["Error validating token: Server request cannot be verified for account: 0123456789ABCDEF ,Request url: &lt;A href="https://myportal.company.com/geoportal/sharing/rest/portals/self" target="_blank" rel="noopener"&gt;https://myportal.company.com/geoportal/sharing/rest/portals/self&lt;/A&gt; Server Id : jT5yBX8d125abcKp , Serverkey recieved 'false'"]&lt;BR /&gt;}}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it expected ? Or does it look like a bug ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Self documentation:&amp;nbsp;&lt;A href="https://developers.arcgis.com/rest/users-groups-and-items/portal-self/" target="_blank" rel="noopener"&gt;https://developers.arcgis.com/rest/users-groups-and-items/portal-self/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;GenerateToken:&amp;nbsp;&lt;A href="https://developers.arcgis.com/rest/users-groups-and-items/generate-token/" target="_blank" rel="noopener"&gt;https://developers.arcgis.com/rest/users-groups-and-items/generate-token/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2026 15:15:10 GMT</pubDate>
    <dc:creator>NicolasGIS</dc:creator>
    <dc:date>2026-02-10T15:15:10Z</dc:date>
    <item>
      <title>Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1683375#M43783</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to validate a token on the Portal for ArcGIS (11.5) Inspection end point (self) but I am noticing that when the token has been generated using "generateToken" endpoint to get a 'server-token' in exchange of a 'portal-token', then it does not work:&lt;/P&gt;&lt;P&gt;{"error": {&lt;BR /&gt;"code": 498,&lt;BR /&gt;"message": "Invalid token.",&lt;BR /&gt;"details": ["Error validating token: Server request cannot be verified for account: 0123456789ABCDEF ,Request url: &lt;A href="https://myportal.company.com/geoportal/sharing/rest/portals/self" target="_blank" rel="noopener"&gt;https://myportal.company.com/geoportal/sharing/rest/portals/self&lt;/A&gt; Server Id : jT5yBX8d125abcKp , Serverkey recieved 'false'"]&lt;BR /&gt;}}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it expected ? Or does it look like a bug ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Self documentation:&amp;nbsp;&lt;A href="https://developers.arcgis.com/rest/users-groups-and-items/portal-self/" target="_blank" rel="noopener"&gt;https://developers.arcgis.com/rest/users-groups-and-items/portal-self/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;GenerateToken:&amp;nbsp;&lt;A href="https://developers.arcgis.com/rest/users-groups-and-items/generate-token/" target="_blank" rel="noopener"&gt;https://developers.arcgis.com/rest/users-groups-and-items/generate-token/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 15:15:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1683375#M43783</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2026-02-10T15:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695512#M44058</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/408959"&gt;@NicolasGIS&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What you are seeing is expected behaviour because a server token is only meant to be used with ArcGIS Server not Portal. If you try to use a server token into different Portal endpoints you will get the error message that you received.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Glen&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 13:24:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695512#M44058</guid>
      <dc:creator>GlenterpriseUK</dc:creator>
      <dc:date>2026-04-10T13:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695756#M44068</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/745832"&gt;@GlenterpriseUK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;OK, noted. As it was generated by Portal for ArcGIS &lt;STRONG&gt;&lt;EM&gt;for&lt;/EM&gt;&amp;nbsp;&lt;/STRONG&gt;ArcGIS for Server, I would have expected that it could at least be introspected by Portal for ArcGIS.&lt;/P&gt;&lt;P&gt;My main problem is then how can I introspect this token ? I didn't find any other REST end point for doing so in the documentation.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 10:04:57 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695756#M44068</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2026-04-13T10:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695761#M44069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/408959"&gt;@NicolasGIS&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Generate the token for your user in ArcGIS Portal Directory using the &lt;A href="https://yourserver.domain.com/portal/sharing/rest/generateToken" target="_blank"&gt;https://yourserver.domain.com/portal/sharing/rest/generateToken&lt;/A&gt;&lt;/P&gt;&lt;P&gt;When you generate the token, use the following for the WebAppURL&amp;nbsp;&lt;A href="https://yourserver.domain.com/server/rest/services/ServiceName" target="_blank"&gt;https://yourserver.domain.com/server/rest/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Once you have the token generated for your desired user, using a Service URL append the token:&lt;/P&gt;&lt;P&gt;&lt;A href="https://yourserver.domain.com/server/rest/services/example/MapServer/0/qyery?where=1%3D1&amp;amp;token=APPENDTOKENVALUE" target="_blank"&gt;https://yourserver.domain.com/server/rest/services/example/MapServer/0/qyery?where=1%3D1&amp;amp;token=APPENDTOKENVALUE&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Glen&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 10:50:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695761#M44069</guid>
      <dc:creator>GlenterpriseUK</dc:creator>
      <dc:date>2026-04-13T10:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695775#M44070</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/745832"&gt;@GlenterpriseUK&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;I know how to use a token. I am looking for a way to &lt;STRONG&gt;&lt;U&gt;inspect&lt;/U&gt;&lt;/STRONG&gt; it server side.&lt;/P&gt;&lt;P&gt;In the meantime, I found the undocumented end point "/rest/self":&lt;/P&gt;&lt;P&gt;&lt;A href="https://myagsserver.company.com/arcgis/rest/self?token=foo&amp;amp;f=json" target="_blank" rel="noopener"&gt;https://myagsserver.company.com/arcgis/rest/self?token=foo&amp;amp;f=json&lt;/A&gt;&lt;/P&gt;&lt;P&gt;that does what I want but I don't like using anything not official:&lt;/P&gt;&lt;P&gt;&lt;A href="https://developers.arcgis.com/rest/services-reference/enterprise/get-started-with-the-services-directory/" target="_blank" rel="noopener"&gt;https://developers.arcgis.com/rest/services-reference/enterprise/get-started-with-the-services-directory/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 12:54:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695775#M44070</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2026-04-13T12:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can't validate federated 'server-token' against Portal for ArcGIS self end point</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695783#M44071</link>
      <description>&lt;P&gt;If you haven't already, it might be worth reading through&amp;nbsp;&lt;A href="https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/how-to-generate-correct-token-for-a-federated/td-p/1270664#:~:text=If%20the%20ArcGIS%20Server%20is,actually%20I%20tried%20OAuth%20initially." target="_blank"&gt;Solved: how to generate correct token for a federated Ente... - Esri Community.&lt;/A&gt;&amp;nbsp; Esri's various APIs handle authentication workflows correctly, and handling them with hand-rolled code commonly trips people up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't say I fully understand your authentication workflow. It seems like you are using what is commonly called the two-step exchange, i.e., authentication first happens on Portal to generate a Portal token, and then that Portal token is used to create an ArcGIS Server token using the generateToken endpoint with the token and serverUrl parameters.&amp;nbsp; Portal validates your Portal token, then creates a new ArcGIS Server token encrypted with the federated server's shared key. The resulting token is meant to be used with that specific federated ArcGIS Server and can be validated locally by that server. Portal cannot validate it because it was encrypted with the server's shared key, not the Portal's. If you need to validate a token against the Portal's portals/self endpoint, use the Portal token directly — before the exchange step.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2026 13:21:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/can-t-validate-federated-server-token-against/m-p/1695783#M44071</guid>
      <dc:creator>JoshuaBixby</dc:creator>
      <dc:date>2026-04-13T13:21:58Z</dc:date>
    </item>
  </channel>
</rss>

