You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter集成Keycloak时遇Invalid parameter: redirect_uri错误求助

解决方案

核心问题分析

你当前使用的io.Authenticator是openid_client库针对桌面/服务器端的认证实现,它默认生成http://localhost:4000/redirect这类重定向URI,但你在Keycloak中配置的是自定义Scheme的DeepLink(com.example.frontend://frontend),两者不匹配,导致Keycloak返回Invalid parameter: redirect_uri错误。

具体修复步骤

1. 修正Keycloak重定向URI配置

确保Keycloak客户端的Valid redirect URIs严格匹配你要使用的DeepLink地址,示例:

com.example.frontend://frontend

注意:不要加多余斜杠或后缀,必须和应用实际发送的redirect_uri参数完全一致。

2. 修改Flutter认证代码

放弃io.Authenticator,改用适配移动端的认证方式,显式指定自定义重定向URI,同时移除port参数:

Future<Credential?> authenticate(
    Client client, {
    List<String> scopes = const [],
}) async {
    try {
        final redirectUri = Uri.parse('com.example.frontend://frontend');
        var authenticator = Authenticator(
            client,
            scopes: scopes,
            redirectUri: redirectUri,
            urlLauncher: _urlLauncher,
        );
        return await authenticator.authorize();
    } catch (e) {
        log("Authorize error: $e");
        return null;
    }
}

注意:如果之前导入的是io子包下的Authenticator,改为导入基础openid_client包中的Authenticator(去掉io前缀)。

3. 验证安卓端配置一致性

检查AndroidManifest.xml中的intent-filter是否和重定向URI完全匹配:

  • android:scheme="com.example.frontend" 对应URI的scheme部分
  • android:host="frontend" 对应URI的host部分
    确保无拼写错误(如大小写、特殊字符)。

4. 清除缓存并重新测试

  • 重启Keycloak服务
  • 卸载并重新安装Flutter应用(避免旧配置缓存干扰)
  • 重新触发登录流程,确认redirect_uri参数与Keycloak配置一致

内容的提问来源于stack exchange,提问作者Berkkan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 19:43:11