[keycloak-user] Directs Grants API & OTP

Stefan Schlesinger sts at ono.at
Thu Feb 23 05:54:39 EST 2017


Hello,

I’m using the Direct Grants API as authentication backend for our Radius server.

Currently I’m unable to determine whether an user already has an OTP token configured or not,
and thus our Radius server always prompts the user with an Access-Challenge dialog.

Users who haven’t configured an OTP token yet won’t be able to login, or in case I can work
around this issue, will at least be presented with a question for an OTP token, which they
are not aware of.

Is there a way how I could improve this? Eg. an API call, which authenticated OpenIDC
clients can trigger?

Best,

Stefan.


More information about the keycloak-user mailing list