{"id":8,"date":"2024-01-31T20:44:10","date_gmt":"2024-01-31T19:44:10","guid":{"rendered":"https:\/\/elinternetdemiscosas.com\/?p=8"},"modified":"2024-01-31T20:58:53","modified_gmt":"2024-01-31T19:58:53","slug":"request-tokens-from-keycloak-using-oidc-endpoints","status":"publish","type":"post","link":"https:\/\/elinternetdemiscosas.com\/index.php\/2024\/01\/31\/request-tokens-from-keycloak-using-oidc-endpoints\/","title":{"rendered":"Request tokens from Keycloak using OIDC endpoints"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the realm of secure authentication and authorization, OAuth 2.0 and OpenID Connect (OIDC) protocols play key roles. This post explores the essentials of obtaining tokens from a Keycloak 23.0.4 server using the OIDC endpoints. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will use the various grant types (from Authorization Code to Client Credentials) to obtain the tokens, enhancing your understanding of securing applications with Keycloak. Embark on this concise journey into the heart of request tokens to amplify your grasp on authentication and authorization in the Keycloak environment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prepare your server<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Install Keycloak<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">First of all, you will need to get a Keycloak server (either in a <a href=\"https:\/\/www.keycloak.org\/getting-started\/getting-started-docker\" data-type=\"link\" data-id=\"https:\/\/www.keycloak.org\/getting-started\/getting-started-docker\">Docker container<\/a> or on <a href=\"https:\/\/www.keycloak.org\/getting-started\/getting-started-zip\" data-type=\"link\" data-id=\"https:\/\/www.keycloak.org\/getting-started\/getting-started-zip\">your PC<\/a>). If you have the Keycloak server in your PC you will need to execute the following in the Keycloak folder to start the server:<\/p>\n\n\n<div class=\"wp-block-syntaxhighlighter-code \"><pre class=\"brush: bash; gutter: false; title: ; notranslate\" title=\"\">\nbin\/kc.&#x5B;sh|bat] start-dev\n<\/pre><\/div>\n\n\n<h3 class=\"wp-block-heading\">Create a realm<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once the server is running we are ready to create a realm; we will call it \u00abmyrealm\u00bb. In Keycloak, a realm is a distinct security area with its own user and application management settings.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"959\" height=\"707\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura1.png\" alt=\"\" class=\"wp-image-21\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura1.png 959w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura1-300x221.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura1-768x566.png 768w\" sizes=\"auto, (max-width: 959px) 100vw, 959px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"560\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1-1024x560.png\" alt=\"\" class=\"wp-image-24\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1-1024x560.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1-300x164.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1-768x420.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1-1200x656.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-1.png 1320w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Create a client<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The following step will be creating a client from which we will perform the tokens requests. We will call it \u00abmyclient\u00bb.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"614\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-2-1024x614.png\" alt=\"\" class=\"wp-image-25\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-2-1024x614.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-2-300x180.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-2-768x461.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura3-2.png 1182w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"805\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-5-1024x805.png\" alt=\"\" class=\"wp-image-38\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-5-1024x805.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-5-300x236.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-5-768x604.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-5.png 1122w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Note that in the Capability config area we must activate <strong>Client authentication<\/strong>. This defines the type of the OIDC client. When it&#8217;s ON, the OIDC type is set to confidential access type. When it&#8217;s OFF, it is set to public access type. We also need to activate <strong>Service accounts roles<\/strong>. As we will see soon, this allows you to authenticate this client to Keycloak and retrieve access token dedicated to this client. In terms of OAuth2 specification, this enables support of Client Credentials Grant for this client.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"758\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4-1024x758.png\" alt=\"\" class=\"wp-image-27\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4-1024x758.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4-300x222.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4-768x569.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4-1200x888.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura4.png 1248w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"654\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-1-1024x654.png\" alt=\"\" class=\"wp-image-28\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-1-1024x654.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-1-300x192.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-1-768x491.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-1.png 1139w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">Get client credentials<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In the next section, we will request tokens using the client&#8217;s credentials. Because of this, we will need to know the client id (<em>myclient<\/em>) and the client password. To obtain this password go to:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1-1024x576.png\" alt=\"\" class=\"wp-image-43\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1-1024x576.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1-300x169.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1-768x432.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1-1200x675.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Capture1.png 1445w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"558\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1-1024x558.png\" alt=\"\" class=\"wp-image-44\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1-1024x558.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1-300x163.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1-768x419.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1-1200x654.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura2-1.png 1536w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">And you can click on the eye or copy button to get the credentials.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Create a user<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The last configuration step will be creating a user. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"583\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5-1024x583.png\" alt=\"\" class=\"wp-image-29\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5-1024x583.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5-300x171.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5-768x437.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5-1200x683.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura5.png 1289w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In our case the user will have the username \u00abalice\u00bb, email \u00abalice@alice.es\u00bb.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"744\" height=\"756\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-2.png\" alt=\"\" class=\"wp-image-30\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-2.png 744w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/imagen-2-295x300.png 295w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Once the user is created we will need to set a credentials for it, this is, a password.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"712\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6-1024x712.png\" alt=\"\" class=\"wp-image-32\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6-1024x712.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6-300x209.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6-768x534.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6-1200x834.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura6.png 1240w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"538\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7-1024x538.png\" alt=\"\" class=\"wp-image-33\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7-1024x538.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7-300x158.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7-768x404.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7-1200x631.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura7.png 1373w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It is important to set the <em>Temporary <\/em>obtion to unchecked, because if enabled, the user would need to change the password on the first login.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"605\" height=\"356\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura8.png\" alt=\"\" class=\"wp-image-35\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura8.png 605w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Captura8-300x177.png 300w\" sizes=\"auto, (max-width: 605px) 100vw, 605px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Requesting the tokens<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As you may know, Keycloak provides different kinds of <strong>tokens<\/strong>: Access, Refresh, and ID tokens (<a href=\"https:\/\/auth0.com\/blog\/id-token-access-token-what-is-the-difference\/\" data-type=\"link\" data-id=\"https:\/\/auth0.com\/blog\/id-token-access-token-what-is-the-difference\/\">this post<\/a> helped me to figure out the differences among them). Basicly, <strong>Access Tokens<\/strong> grant permission to access protected resources, <strong>Refresh Tokens<\/strong> enable token renewal without reauthentication, and <strong>ID token<\/strong> provide user identity information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In Keycloak, these tokens can be requested in several ways; these \u00abways\u00bb are called grants. Each grant type offers a distinct approach to authentication and authorization, allowing developers to tailor de token acquisition process according to specific use cases and security needs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will walk through how to obtain these tokens using these different grants.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Postman collection<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">I have created a Postman collection containing all the request I have used during this post, you can download it here.<\/p>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-08691b9a-97dc-4cbc-b57f-824db11588ab\" href=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Keycloak-EIDMC.postman_collection.json\">Keycloak-EIDMC.postman_collection<\/a><a href=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Keycloak-EIDMC.postman_collection.json\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-08691b9a-97dc-4cbc-b57f-824db11588ab\">Download the postman collection<\/a><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Note that, in order to execute the requests properly, you need to have the following Postman environment configured.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"364\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6-1024x364.png\" alt=\"\" class=\"wp-image-58\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6-1024x364.png 1024w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6-300x107.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6-768x273.png 768w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6-1200x427.png 1200w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-6.png 1360w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Note also that the variables kc_refresh_token, kc_access_token and kc_id_token are automatically assigned to the values received in the requests. This behavior is set in the <em>Test<\/em> section of every Postman request.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"278\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-7.png\" alt=\"\" class=\"wp-image-59\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-7.png 766w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-7-300x109.png 300w\" sizes=\"auto, (max-width: 766px) 100vw, 766px\" \/><\/figure>\n\n\n\n<p class=\"has-normal-font-size wp-block-paragraph\">You can download the environment variables export file here or configure them manually.<\/p>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-f735737b-bd49-4943-9b04-71ce86bf046c\" href=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Keycloak-EIDMC.postman_environment.json\">Keycloak-EIDMC.postman_environment<\/a><a href=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/Keycloak-EIDMC.postman_environment.json\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-f735737b-bd49-4943-9b04-71ce86bf046c\">Download the postman environment<\/a><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Resource Owner Password Credential Grant<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Resource Owner Password Credential (ROPC) Grant simplifies authentication, involving the direct exchange of user-provided credentials for access tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Endpoint<\/strong>: <code>{{kc_server}}\/realms\/{{kc_realm}}\/protocol\/openid-connect\/token<\/code><br><strong>Method<\/strong>: POST<br><strong>Body:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Key<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><tr><td><code>client_id<\/code><\/td><td>Id of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>client_secret<\/code><\/td><td>Secret of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>grant_type<\/code><\/td><td><code>password<\/code><\/td><\/tr><tr><td><code>scope<\/code><\/td><td><code>openid<\/code><\/td><\/tr><tr><td><code>username<\/code><\/td><td>User&#8217;s username<\/td><\/tr><tr><td><code>password<\/code><\/td><td>User&#8217;s password<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Body of the Resource Owner Password Grant token request<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If I send the request using Postman I get the following response.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"775\" height=\"876\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-3.png\" alt=\"\" class=\"wp-image-48\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-3.png 775w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-3-265x300.png 265w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-3-768x868.png 768w\" sizes=\"auto, (max-width: 775px) 100vw, 775px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As you can see, the response contains several keys in JSON format.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Key<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><tr><td><code>access_token<\/code><\/td><td>Response&#8217;s Access Token <\/td><\/tr><tr><td><code>expires_in<\/code><\/td><td>Access Token&#8217;s expiration time (in seconds)<\/td><\/tr><tr><td><code>refresh_expires_in<\/code><\/td><td>Refresh Token&#8217;s expiration time (in seconds) <\/td><\/tr><tr><td><code>refresh_token<\/code><\/td><td>Response&#8217;s Refresh Token<\/td><\/tr><tr><td><code>token_type<\/code><\/td><td>Type of token, usually <code>Bearer<\/code><\/td><\/tr><tr><td><code>id_token<\/code><\/td><td>Response&#8217;s ID Token<\/td><\/tr><tr><td><code>not-before-policy<\/code><\/td><td>Timestamp that indicates the time before which the JWT must not be accepted for processing. More info <a href=\"https:\/\/mojoauth.com\/glossary\/jwt-not-before\/\">here<\/a>.<\/td><\/tr><tr><td><code>session_state<\/code><\/td><td>Keycloak&#8217; session state<\/td><\/tr><tr><td><code>scope<\/code><\/td><td>openid email profile<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Token&#8217;s response JSON explained<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Client Credentials Grant<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Client Credentials Grant enables secure access by allowing applications to directly request access tokens using their client credentials, streamlining authentication for machine-to-machine communication.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"798\" height=\"895\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-2.png\" alt=\"\" class=\"wp-image-47\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-2.png 798w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-2-267x300.png 267w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-2-768x861.png 768w\" sizes=\"auto, (max-width: 798px) 100vw, 798px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Endpoint<\/strong>: <code>{{kc_server}}\/realms\/{{kc_realm}}\/protocol\/openid-connect\/token<\/code><br><strong>Method<\/strong>: POST<br><strong>Body:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Key<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><tr><td><code>client_id<\/code><\/td><td>Id of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>client_secret<\/code><\/td><td>Secret of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>grant_type<\/code><\/td><td><code>client_credentials<\/code><\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Body of the Client Credentials Grant token request<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Refresh Token Grant<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Refresh Token Grant facilitates seamless token renewal, allowing applications to obtain fresh access tokens without requiring user reauthentication, enhancing the efficiency and security of long-running sessions.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"798\" height=\"884\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-4.png\" alt=\"\" class=\"wp-image-49\" style=\"width:610px;height:auto\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-4.png 798w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-4-271x300.png 271w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-4-768x851.png 768w\" sizes=\"auto, (max-width: 798px) 100vw, 798px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Endpoint<\/strong>: <code>{{kc_server}}\/realms\/{{kc_realm}}\/protocol\/openid-connect\/token<\/code><br><strong>Method<\/strong>: POST<br><strong>Body:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Key<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><tr><td><code>client_id<\/code><\/td><td>Id of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>client_secret<\/code><\/td><td>Secret of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>grant_type<\/code><\/td><td><code>refresh_token<\/code><\/td><\/tr><tr><td><code>scope<\/code><\/td><td>openid<\/td><\/tr><tr><td><code>refresh_token<\/code><\/td><td>Refresh Token to obtain in a previous request<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Body of the Client Credentials Grant token request<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Authorization Code Grant<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Authorization Code Grant is a secure authentication process where clients obtain access tokens by exchanging an authorization code, optimizing user authentication for web applications while maintaining robust security measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, the authorization code would come from the authorization server, this is, Keycloak. I will create a post showing a case study of this situation soon.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"929\" height=\"786\" src=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-5.png\" alt=\"\" class=\"wp-image-50\" srcset=\"https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-5.png 929w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-5-300x254.png 300w, https:\/\/elinternetdemiscosas.com\/wp-content\/uploads\/2024\/01\/image-5-768x650.png 768w\" sizes=\"auto, (max-width: 929px) 100vw, 929px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Endpoint<\/strong>: <code>{{kc_server}}\/realms\/{{kc_realm}}\/protocol\/openid-connect\/token<\/code><br><strong>Method<\/strong>: POST<br><strong>Body:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Key<\/strong><\/td><td><strong>Description<\/strong><\/td><\/tr><tr><td><code>client_id<\/code><\/td><td>Id of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>client_secret<\/code><\/td><td>Secret of the Keycloak&#8217;s client<\/td><\/tr><tr><td><code>grant_type<\/code><\/td><td><code>authorization_code<\/code><\/td><\/tr><tr><td><code>scope<\/code><\/td><td><code>openid<\/code><\/td><\/tr><tr><td><code>code<\/code><\/td><td>Authorization Code obtained from Keycloak<\/td><\/tr><tr><td><code>redirect_uri<\/code><\/td><td>URI to redirect<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Body of the Authorization Code Grant token request<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In conclusion, we&#8217;ve navigated the crucial steps of securing applications with Keycloak, honing in on token acquisition using OAuth 2.0 and OpenID Connect. From setting up the Keycloak server and creating realms, clients, and users to exploring grant types like Resource Owner Password Credential, Client Credentials, Refresh Token, and a glimpse into Authorization Code Grant \u2013 we&#8217;ve covered it all. This guide is your go-to for understanding authentication and authorization in the Keycloak environment. Plus, I&#8217;ve got a Postman collection with all the requests for practical implementation \u2013 go ahead, download it and dive into a more secure application experience!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Embark on a journey into the heart of Keycloak authentication, mastering token acquisition via OAuth 2.0 and OpenID Connect. From setting up the server to exploring grant types, this guide demystifies authentication, leaving you equipped to secure applications effortlessly.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3],"tags":[4],"class_list":["post-8","post","type-post","status-publish","format-standard","hentry","category-keycloak","tag-keycloak"],"_links":{"self":[{"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/posts\/8","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/comments?post=8"}],"version-history":[{"count":18,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/posts\/8\/revisions"}],"predecessor-version":[{"id":65,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/posts\/8\/revisions\/65"}],"wp:attachment":[{"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/media?parent=8"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/categories?post=8"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/elinternetdemiscosas.com\/index.php\/wp-json\/wp\/v2\/tags?post=8"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}