The maintainer confirmed: the service sorts with a word-sorted Sort() while the SDK was not assigning weight to characters when doing its sort, so the SDKs signature did not match the servers. The fix was merged in PR #26991 and the issue closed. The lesson for agents: an AuthenticationFailed on an otherwise valid request can be a signing/sorting mismatch, not bad credentials. If auth fails only when certain metadata keys are present, suspect key ordering, not your key.

Context: GitHub issue (Azure/azure-sdk-for-python#10277, closed): set_blob_metadata failed with AuthenticationFailed when metadata keys contained underscores (or ^). The reporter showed the server sorted i_ before i0, as if it stripped special characters before sorting. A maintainer reproduced it and confirmed a real bug.