You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Keycloak 15.0.2中启用Token Exchange功能?已尝试多法失败

Keycloak 15.0.2 启用Token Exchange功能解决方案

一、修正配置文件(standalone.xml/domain.xml)

找到Keycloak配置文件中的<subsystem xmlns="urn:jboss:domain:keycloak-server:1.1">节点,补充以下配置:

  1. 启用Token Exchange提供者:
<spi name="token-exchange">
    <provider name="default" enabled="true"/>
</spi>
  1. 开启Token Exchange功能:
    如果配置中已有<profile>节点,直接在内部添加;如果没有,创建该节点:
<profile>
    <feature name="token_exchange" enabled="true"/>
</profile>

二、正确启动Keycloak服务器

之前启动参数格式错误导致报错,需使用以下命令启动:

  • Windows环境:
standalone.bat --preview -Dkeycloak.profile.feature.token_exchange=enabled
  • Linux环境:
standalone.sh --preview -Dkeycloak.profile.feature.token_exchange=enabled

说明:--preview参数无需赋值,直接使用即可;必须同时指定预览模式和Token Exchange的feature启用参数,两者缺一不可。

三、客户端配置验证

  1. 进入Keycloak控制台,找到目标客户端,在Settings标签页:
    • 将Access Type设置为confidential(Token Exchange要求客户端为保密类型)。
    • 确保Service Accounts Enabled已开启(若需通过服务账号进行令牌交换)。
  2. 在Client Scopes标签页:
    • 确认token-exchange已添加到客户端的默认作用域中,若未添加,手动将其从Available Client Scopes移至Assigned Default Client Scopes。

四、验证Token Exchange请求

发送POST请求到/realms/{你的领域名}/protocol/openid-connect/token,参数示例:

grant_type=urn:ietf:params:oauth:grant-type:token-exchange
subject_token=<源访问令牌>
subject_token_type=urn:ietf:params:oauth:token-type:access_token
client_id=<客户端ID>
client_secret=<客户端密钥>

问题原因分析

  1. 单独使用--preview=enabled启动:参数格式错误,Keycloak 15中--preview无需赋值,直接使用即可。
  2. 单独添加-Dkeycloak.profile.feature.token_exchange=enabled:未启用预览模式,Token Exchange作为预览功能无法加载。
  3. 仅修改配置文件:缺少启动时的参数启用,且可能客户端配置不符合要求,导致返回501未实现响应。

内容的提问来源于stack exchange,提问作者Shahab.es

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 17:55:12