[keycloak-user] OpenID Connect Clients and Roles

Stian Thorgersen sthorger at redhat.com
Wed Sep 14 07:56:53 EDT 2016


Roles are a Keycloak specific extension and are not shown in the OpenID
Connect configuration. They are available in the access token.

On 14 September 2016 at 08:52, Andy Stebbing <andy.stebbing at adelaide.edu.au>
wrote:

> Hi,
>   I'm fairly new to OpenID Connect and Keycloak (using version 2.2.0-CR1
> and RedHat SSO v7), I've managed to get a client working with a realm
> within Keycloak. I've configured the client in the realm using a shared key
> and have configured my remote client accordingly. It works fine for
> authentication and I'm getting the standard claims back. But I don't know
> how to get the roles associated with the user to come through. I can see in
> the endpoint OpenID connect configuration on the server that the following
> claims are supported:
>
> "claim_types_supported": [
>         "normal"
>     ],
>     "claims_parameter_supported": false,
>     "claims_supported": [
>         "sub",
>         "iss",
>         "auth_time",
>         "name",
>         "given_name",
>         "family_name",
>         "preferred_username",
>         "email"
>     ]
>
> Does this mean that it's not possible to get the roles from the userinfo
> call? Or if it is possible, how do I configure it to be supported?
>
> Any help is very much appreciated !
>
> Thanks
> andy
>
> _______________________________________________
> keycloak-user mailing list
> keycloak-user at lists.jboss.org
> https://lists.jboss.org/mailman/listinfo/keycloak-user
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/keycloak-user/attachments/20160914/f8c03245/attachment.html 


More information about the keycloak-user mailing list