[keycloak-user] Can I get a google offline refresh tokens or not? PLEASE

Nick Powers sshscp at gmail.com
Thu Jul 18 14:35:07 EDT 2019


Hello,

I am setup with Keycloak & Gatekeeper and my users are able to authenticate
with Google and I can retrieve the access token from Google but I cannot
receive a refresh token, apparently because Keycloak is not adding
?access_type=offline to the Google authentication URL.  Is it even possible
to get a refresh token from Google while using Keycloak?

It's is very difficult to search for Keycloak related items on Google
because the results are littered with 404 pages from previous versions of
Keycloak that I guess have since been deleted.  But, most of what I have
found related to getting refresh tokens from Google end up being frustrated
people not getting an answer or people discussing how "someday" it "might"
be implemented.  These go back years.

>From what little I have been able to find, It seems offline access to
Google Identify Provider has never worked for Keycloak.  I hope that is not
true, it seems like a simple thing to add the option of appending
?access_type=offline to the Google authentication URL.

I know it may sound like nothing to someone not needing this feature but
for me if I cannot get the Google refresh tokens from Google with Keycloak
then I cannot use Keycloak.  I am not alone in wanting this, the archives
of this mailing list and Google search results have LOTS of people looking
to do the same thing.

PLEASE PLEASE PLEASE can someone PLEASE tell me what I need to do to get a
refresh token from Google????  I don't want to have to hard code
?access_type=offline into the URL in the source code if I don't have to.

Do any RedHat people monitor this mailing list?  Can I purchase a support
ticket from RedHat to get support on KeyCloak?  I really need to get this
working.

Thanks,

Nick


More information about the keycloak-user mailing list