Secure Applications with OpenID Connect
This guide describes how to integrate a client application with Keycloak using the OpenID Connect (OIDC) protocol. Keycloak acts as the Identity Provider (IdP) and issues tokens that your application validates.
TOC
Integration ApproachPrerequisitesStep 1: Note the OIDC Discovery URLStep 2: Configure Your ApplicationStep 3: Implement the Authorization Code FlowFlow OverviewAuthorization RequestToken ExchangeToken ResponseSecuring a REST API (Resource Server)LogoutRP-Initiated LogoutBack-Channel LogoutToken RefreshOther Grant TypesIntegration Approach
Keycloak 26.x recommends using standard OIDC/OAuth 2.0 client libraries rather than Keycloak-specific adapters. Most legacy Keycloak adapters (Java, JavaScript, Node.js) have been deprecated in favor of generic OIDC libraries that work with any compliant provider.
Choose a library based on your application platform:
Prerequisites
- A Keycloak instance with a configured Realm.
- An OIDC client registered in Keycloak (see Manage Clients).
Step 1: Note the OIDC Discovery URL
Every Realm exposes an OIDC discovery endpoint:
This endpoint returns all the URLs your application needs (authorization, token, userinfo, JWKS, logout).
Step 2: Configure Your Application
Provide the following to your OIDC library:
Step 3: Implement the Authorization Code Flow
The Authorization Code Flow (with PKCE for public clients) is the recommended flow for interactive applications.
Flow Overview
- Your application redirects the user to the Keycloak authorization endpoint.
- The user authenticates at Keycloak.
- Keycloak redirects back to your application with an authorization code.
- Your application exchanges the code for tokens at the token endpoint.
- Your application validates the ID token and uses the access token to call APIs.
Authorization Request
Token Exchange
Token Response
Securing a REST API (Resource Server)
For backend APIs that receive bearer tokens from other applications:
-
Register a confidential client in Keycloak with all standard authentication flows disabled (uncheck Standard flow, Direct access grants, etc.). This is the recommended approach for resource servers in Keycloak 17+, as the deprecated bearer-only client type is no longer exposed in the Admin Console UI.
-
Configure your API to validate access tokens using the Keycloak JWKS endpoint:
-
On each request, extract the
Authorization: Bearer <token>header. -
Validate the token signature using the JWKS keys.
-
Check the
iss(issuer),exp(expiration), andaud(audience) claims. -
Use token claims (roles, groups) for authorization decisions.
Logout
RP-Initiated Logout
Redirect the user to the Keycloak logout endpoint to terminate the SSO session:
Back-Channel Logout
For applications that need to be notified when a user logs out from another application:
- In the client settings, set Backchannel logout URL to your application's logout endpoint (for example,
https://my-app.example.com/backchannel-logout). - Enable Backchannel logout session required.
- Keycloak sends a logout token (JWT) to your endpoint when the user's session is terminated.
Token Refresh
Use the refresh token to obtain new access tokens without re-authentication:
Other Grant Types
The Resource Owner Password Credentials (ROPC) grant is supported but discouraged. It exposes user credentials to the client application and cannot support MFA. Use the Authorization Code flow instead.