Authorization Services
Keycloak provides fine-grained authorization services based on the User-Managed Access (UMA) specification and a rich policy evaluation engine. These services go beyond role-based access control (RBAC) to support attribute-based, time-based, and context-aware authorization decisions.
TOC
OverviewKey ConceptsPolicy TypesDecision StrategiesAuthorization FlowEnabling Authorization ServicesUser-Managed Access (UMA)Overview
Traditional RBAC assigns roles to users and checks roles in application code. Keycloak Authorization Services externalizes authorization logic from the application into a centralized policy engine:
- Applications register their protected resources and scopes.
- Administrators define policies that govern access to those resources.
- Keycloak evaluates policies at runtime and returns authorization decisions.
- Applications enforce the decisions using the authorization response.
This separation allows authorization logic to be managed centrally without changing application code.
Key Concepts
Policy Types
Keycloak supports multiple policy types that can be combined:
Decision Strategies
When a permission references multiple policies, the decision strategy determines how the individual policy decisions are combined:
Authorization Flow
- The client application requests an access token from Keycloak.
- The client sends the access token to the resource server (API).
- The resource server requests an RPT from the Keycloak token endpoint, specifying the resource and scope being accessed.
- Keycloak evaluates all applicable policies and returns an RPT containing the granted permissions (or denies the request).
- The resource server inspects the RPT permissions and allows or denies the operation.
Alternatively, the resource server can call the token introspection endpoint to evaluate permissions without obtaining an RPT.
Enabling Authorization Services
Authorization services are enabled per client:
- In the Admin Console, go to Clients and select the target client.
- Enable Client authentication (the client must be confidential).
- Enable Authorization.
- Click Save.
- A new Authorization tab appears with sub-sections for resources, scopes, policies, and permissions.
For step-by-step configuration, see Configure Authorization.
User-Managed Access (UMA)
UMA extends the authorization model to allow resource owners (end users) to manage access to their own resources. With UMA:
- Users can share resources with other users or groups.
- Users can approve or deny access requests.
- Authorization decisions respect the resource owner's policies.
UMA is an advanced feature used primarily in scenarios where end users need fine-grained control over resource sharing (for example, document sharing, API access delegation).