You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot应用读取KeyCloak令牌时iat字段存在两小时时差问题

KeyCloak部署到局域网服务器后JWT认证时区相关错误问题

我有一个基于Spring Boot的应用,通过KeyCloak OAuth2/OIDC实现认证。本地运行KeyCloak实例时一切正常,但将KeyCloak按相同配置部署到局域网服务器后,出现以下错误:

[invalid_id_token] An error occurred while attempting to decode the Jwt: The ID Token contains invalid claims: {iat=2024-04-23T13:26:41Z}

调用时本地时间为15:26,与JWT中的时间存在2小时时差,我的时区为CET(GMT+2),推测是时区问题,但暂未定位到具体原因。

已完成以下检查:

  • 服务器的时间及时区正确(通过timedatectl命令验证)
  • SpringBoot应用的时间及时区正确(通过LocalDateTime.now()验证)
  • JWT中的时间戳看似正常(通过Postman调用KeyCloak的/protocol/openid-connect/token端点,解析access_token确认)

JWT内容如下:

{
  "exp": 1713879118,
  "iat": 1713878818,
  "jti": "d89131ca-e904-40cc-806f-50496d2abdf0",
  "iss": "http://192.168.252.141:8080/realms/myRealm",
  "aud": "account",
  "sub": "6ba5043e-9faf-4cbc-914f-bb5623e04bfe",
  "typ": "Bearer",
  "azp": "myrealm-login",
  "session_state": "a8406003-b6d7-4bd2-8dec-e728c48600b1",
  "acr": "1",
  "allowed-origins": [
    "*",
    "http://localhost:8080/"
  ],
  ...
}

版本信息:

  • KeyCloak 24.0.3
  • SpringBoot 3.2.4

内容的提问来源于stack exchange,提问作者Loibologic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 14:03:36