Forum Discussion
Understanding a Limitation in Fabric Data Factory Web Activity
Hi ShashankChhoker,
Thanks for sharing this.
One thing worth adding is that this limitation comes from the design scope of Web Activity itself. Web Activity is intended for HTTP orchestration (URLs, headers, payloads, authentication configuration), but it does not expose cryptographic primitives such as RSA signing or private key operations.
Microsoft documentation for Web Activity in Fabric :
https://learn.microsoft.com/en-us/fabric/data-factory/web-activity
For scenarios that require RS256/RSA-SHA256 signatures, Microsoft typically recommends using a compute layer or a dedicated cryptographic service. For example, Azure Key Vault natively supports RSA signing operations (RS256, RS384, RS512, PS256, etc.):
https://learn.microsoft.com/en-us/azure/key-vault/keys/about-keys-details
In practice, I've seen teams successfully solve this by moving the signing logic into :
- A Fabric Notebook (Python)
- An Azure Function
- Azure Key Vault signing APIs
So I would consider this less a bug and more an architectural boundary of Web Activity.
Thanks again for documenting the finding. This is exactly the kind of detail that helps others avoid spending hours troubleshooting 401 signature mismatch errors.