<div dir="ltr">Hi, <div><br></div><div><p>I configured a OIDC identity provider by<font color="#333333"> s</font>electing the <code class="" style="font-size:0.9em;font-family:courrier,monospace;white-space:nowrap">OpenID Connect v1.0</code> identity provider from the drop-down box on the top right corner of the identity providers table in Keycloak&#39;s Admin Console. During the configuration process, I also configure &quot;Logout Url&quot; for the IDP logout url. </p><p>







</p><p class=""><span class="">When I try to logout to the external IDP, the browser is redirected to the external IDP to perform the logout. I can see some URL as follows:</span></p><p class=""><span class="">https://<b><a href="http://keycloakdev.xxxxxxx.com">keycloakdev.xxxxxxx.com</a></b>/auth/realms/<b>Internal</b>/protocol/openid-connect/logout?<b>state=</b>a4efbda0-8b98-4169-a369-59e92bc3fac5&amp;<b>id_token_hint=</b>eyJhbGciOiJSUzI1NiJ9.eyJqdGkiOiJjMDY0NWJmZC0yZDhlLTQ1MjQtOWQ5Mi05OGViMDk5MDgxMzUiLCJleHAiOjE0NTgxNDg1ODksIm5iZiI6MCwiaWF0IjoxNDU4MTQ4NTg4LCJpc3MiOiJodHRwczovL2tleWNsb2FrZGV2Lm1hc2VyZ3kuY29tL2F1dGgvcmVhbG1zL0ludGVybmFsIiwiYXVkIjoiZXh0ZXJuYWxfcmVhbG1fYWNjZXNzXzIiLCJzdWIiOiI2ZmNmMDMwMi1jNzE0LTRiZDUtYjdlZS02MjMyODU2YTBlZWUiLCJ0eXAiOiJJRCIsImF6cCI6ImV4dGVybmFsX3JlYWxtX2FjY2Vzc18yIiwic2Vzc2lvbl9zdGF0ZSI6ImY1MWM3MzFkLTJkZWItNGRhZi04YWM3LTQyZDdkYjc1Zjc5YyIsIm5hbWUiOiJYaWFvIE1hIiwicHJlZmVycmVkX3VzZXJuYW1lIjoieG1hIiwiZ2l2ZW5fbmFtZSI6IlhpYW8iLCJHUk9VUFNfRlJPTV9JTlRFUk5BTF9SRUFMTSI6WyIvTk9DIiwiL2xhbmRzY2FwZV9nZW5lcmFsX3VzZXIiXSwiZmFtaWx5X25hbWUiOiJNYSIsImVtYWlsIjoieGlhby5tYUBtYXNlcmd5LmNvbSJ9.BIneKvUpSPq4c32dV5JclWPjtbA0U55u8Pf_C7KDokNMMBKCERHnzIS8-9csBxh8NLJbB_PmApMY0raAz-YPOcwyvmsOJ23bSrDR3Oa2HZ5JEGzs9IVFyhzQXJuDBCBWcPZl-eNxnxdGkNJBd7Cx03iWsUVUE9NeJYPjeZ5s8rmDtaX38V6JywugWRby5rfSZDLpu7xoGj6a_ZSZEXUfktwCMHS0Jnz_1M778Bmka0TcD1bvIpuqVl4-YQf2P3UZWgxqFQoNDVegZUNuekqUQyJiuRjlQuhITg5tDYfy2DbhkqVsN2gR7mUp21WNx2S5pG5Hb9cXajIVGR6SmW4qKA</span>:</p><p class="">&quot;<a href="http://keycloakdev.xxxxxxx.com">keycloakdev.xxxxxxx.com</a>&quot; is where the externalIDP is located. &quot;Internal&quot; is the name of the realm. The parameters &quot;state&quot; and &quot;id_token_hint&quot; are appended to the endpoint logout URL automatically during the logout process.   <br></p><p class="">However, this process failed because I got &quot;Session Not Active&quot; error in the UI. After some investigations, I found this &quot;Session Not Active&quot; error seems to be related to the value of <font color="#333333" face="Arial, sans-serif"><span style="font-size:14px;line-height:20px">Realm Setting —&gt; Tokens —&gt; Access Token Lifespan I configured. The default value is 5 minutes, if I trigger the logout within 5 minutes, I can logout to the external IDP successfully. If I do the logout after 5 minutes, I will get this &quot;</span></font>&quot;Session Not Active&quot; error. Is this the expected behavior? <span style="font-size:14px;line-height:20px;color:rgb(51,51,51);font-family:Arial,sans-serif"> Do I have to bump up the value of &quot;</span><span style="color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Access Token Lifespan&quot; to get a longer session for the logout purpose? </span></p><p class=""><span style="color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Thanks a lot for the help!</span></p><p class=""><span style="color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px">Xiao</span></p><p class=""><span style="color:rgb(51,51,51);font-family:Arial,sans-serif;font-size:14px;line-height:20px"> </span></p><a id="d4e2151" style="color:rgb(51,51,51);font-family:&#39;Lucida Grande&#39;,Geneva,Verdana,Arial,sans-serif;font-size:12px;line-height:18px;text-align:justify"><div class=""><br></div></a><p class=""><span class=""><br></span></p><p class=""><span class=""><br></span></p><p><br></p><p><br></p><p><br></p><p></p><p style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255)"><a id="d4e2151" style="color:rgb(51,51,51);font-family:&#39;Lucida Grande&#39;,Geneva,Verdana,Arial,sans-serif;font-size:12px;line-height:18px;text-align:justify"></a></p><div class="" style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255)"></div><p></p><table summary="Configuration Options" border="1" style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;border:1px solid rgb(170,170,170);width:659.333px;border-collapse:collapse;background-color:rgb(255,255,255)"><tbody valign="top"><tr><td align="left" valign="top" style="margin:0px;font-family:arial,sans-serif;border-style:none;padding:0.15em 0.5em"></td></tr></tbody></table><p><br></p><p><br></p><table summary="Configuration Options" border="1" style="border:1px solid rgb(170,170,170);width:659.333px;border-collapse:collapse"><tbody valign="top"><tr><td align="left" valign="top" style="border-style:none;padding:0.15em 0.5em"></td></tr></tbody></table><div><br></div></div></div>