You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak 22.0.3与C# OidcClient集成问题:IdentityToken为空

Keycloak 22.0.3 + OidcClient登录后IdentityToken为空问题

我在C#应用中使用Keycloak进行身份认证,通过OidcClient库处理认证流程。目前遇到一个问题:登录成功后AccessToken有效,但IdentityToken为空。

代码片段如下:

var result = await _oidcClient.LoginAsync(new LoginRequest());
if (result == null || result.IsError)
{
    _logger.LogError($"Error in connection: {result?.Error ?? "No error"}");
}
result.AccessToken; // 正常获取
result.IdentityToken; // 为空

调用时使用的scope为:openid offline_access,Keycloak客户端类型为OpenIdConnect。

连接本身可以正常工作,但我需要IdentityToken来实现登出功能。已搜索相关答案,但找到的内容均已过时,不适用于Keycloak最新版本22.0.3,希望能得到帮助。

补充:开发环境配置

{
 "clientId": "appclient",
 "name": "App ClientId",
 "description": "",
 "rootUrl": "",
 "adminUrl": "",
 "baseUrl": "",
 "surrogateAuthRequired": false,
 "enabled": true,
 "alwaysDisplayInConsole": false,
 "clientAuthenticatorType": "client-secret",
 "redirectUris": [
   "app://authcallback/*"
 ],
 "webOrigins": [],
 "notBefore": 0,
 "bearerOnly": false,
 "consentRequired": false,
 "standardFlowEnabled": true,
 "implicitFlowEnabled": false,
 "directAccessGrantsEnabled": true,
 "serviceAccountsEnabled": false,
 "publicClient": true,
 "frontchannelLogout": true,
 "protocol": "openid-connect",
 "attributes": {
   "client.secret.creation.time": "1697036807",
   "post.logout.redirect.uris": "app://authcallback/*",
   "oauth2.device.authorization.grant.enabled": "true",
   "backchannel.logout.revoke.offline.tokens": "true",
   "use.refresh.tokens": "true",
   "oidc.ciba.grant.enabled": "false",
   "backchannel.logout.session.required": "true",
   "client_credentials.use_refresh_token": "false",
   "acr.loa.map": "{}",
   "require.pushed.authorization.requests": "false",
   "tls.client.certificate.bound.access.tokens": "false",
   "display.on.consent.screen": "false",
   "token.response.type.bearer.lower-case": "false"
 },
 "authenticationFlowBindingOverrides": {},
 "fullScopeAllowed": true,
 "nodeReRegistrationTimeout": -1,
 "protocolMappers": [
   {
     "name": "Client IP Address",
     "protocol": "openid-connect",
     "protocolMapper": "oidc-usersessionmodel-note-mapper",
     "consentRequired": false,
     "config": {
       "user.session.note": "clientAddress",
       "id.token.claim": "true",
       "access.token.claim": "true",
       "claim.name": "clientAddress",
       "jsonType.label": "String"
     }
   },
   {
     "name": "Client ID",
     "protocol": "openid-connect",
     "protocolMapper": "oidc-usersessionmodel-note-mapper",
     "consentRequired": false,
     "config": {
       "user.session.note": "client_id",
       "id.token.claim": "true",
       "access.token.claim": "true",
       "claim.name": "client_id",
       "jsonType.label": "String"
     }
   },
   {
     "name": "Client Host",
     "protocol": "openid-connect",
     "protocolMapper": "oidc-usersessionmodel-note-mapper",
     "consentRequired": false,
     "config": {
       "user.session.note": "clientHost",
       "id.token.claim": "true",
       "access.token.claim": "true",
       "claim.name": "clientHost",
       "jsonType.label": "String"
     }
   }
 ],
 "defaultClientScopes": [
   "web-origins",
   "acr",
   "openid",
   "roles",
   "profile",
   "user"
 ],
 "optionalClientScopes": [
   "address",
   "phone",
   "offline_access",
   "microprofile-jwt",
   "email"
 ],
 "access": {
   "view": true,
   "configure": true,
   "manage": true
 }
}

内容的提问来源于stack exchange,提问作者Weestit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 04:43:26