You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot OAuth2客户端注册:tokenUri与issuerUri的区别及适配问题

Understanding OAuth2 Configs with Spring Boot & Keycloak (And Fixing Your 405 Error)

Hey there, let's break this down step by step—OAuth2 configuration can feel super confusing when you're starting out, so I get your frustration! Let's start with clarifying each of those config options, then tackle your tokenUri/issuerUri mixup, and wrap up with practical fixes and learning resources.

First: What Do Each of These Configs Do?

Let's go through each of your listed properties one by one:

1. spring.security.oauth2.resourceserver.jwt.issuer-uri

This is for your resource server (the app that protects APIs with JWT tokens). It tells Spring Security where to fetch public keys to verify JWT signatures, and to validate that the token's iss (issuer) claim matches this URI. Set this to your Keycloak realm URL (e.g., http://your-keycloak/auth/realms/your-realm), since Keycloak exposes its public keys and issuer info here.

2. spring.security.oauth2.client.provider.keycloak.issuer-uri

This is for your OAuth2 client (the app logging users in via Keycloak). Setting this triggers Spring's auto-discovery of Keycloak's OAuth2 endpoints: it hits the .well-known/openid-configuration endpoint under this URI to automatically populate values like token-uri, authorization-uri, jwk-set-uri, etc. Again, this is your Keycloak realm URL.

3. spring.security.oauth2.client.registration.keycloak.*

These are your client's core registration details:

  • client-id/client-secret: Credentials for your app registered in Keycloak (created via the Keycloak admin console).
  • provider: Tells Spring which provider config (from the spring.security.oauth2.client.provider.keycloak section) to use for this client.
  • grant-type: The OAuth2 flow your app uses (e.g., authorization_code for user-facing login, client_credentials for service-to-service calls).

Why You Got the 405 Error: tokenUri vs issuerUri

Let's clear up the critical difference here:

  • issuerUri: Points to the provider's base realm URL (Keycloak), which serves an OpenID Connect metadata endpoint (.well-known/openid-configuration). Spring sends a GET request here to automatically fetch all necessary endpoint URLs.
  • tokenUri: Is the specific endpoint where your client sends POST requests to get access tokens (e.g., http://your-keycloak/auth/realms/your-realm/protocol/openid-connect/token). This endpoint only accepts POST requests.

Your error happened because you set issuerUri to the tokenUri value. Spring tried to send a GET request to the token endpoint (to fetch metadata), but that endpoint doesn't support GET—hence the 405 Method Not Allowed error.

Fixing the Issue for Spring Security 5.3.x

Since 5.3.x doesn't support the ClientRegistration.issuerUri() method (auto-discovery), you'll need to manually configure all provider endpoints instead. Here's what your properties should look like:

# Keycloak Provider Config (manual endpoints)
spring.security.oauth2.client.provider.keycloak.authorization-uri=http://your-keycloak/auth/realms/your-realm/protocol/openid-connect/auth
spring.security.oauth2.client.provider.keycloak.token-uri=http://your-keycloak/auth/realms/your-realm/protocol/openid-connect/token
spring.security.oauth2.client.provider.keycloak.jwk-set-uri=http://your-keycloak/auth/realms/your-realm/protocol/openid-connect/certs
spring.security.oauth2.client.provider.keycloak.user-info-uri=http://your-keycloak/auth/realms/your-realm/protocol/openid-connect/userinfo
spring.security.oauth2.client.provider.keycloak.user-name-attribute=preferred_username

# Client Registration
spring.security.oauth2.client.registration.keycloak.client-id=your-client-id
spring.security.oauth2.client.registration.keycloak.client-secret=your-client-secret
spring.security.oauth2.client.registration.keycloak.provider=keycloak
spring.security.oauth2.client.registration.keycloak.authorization-grant-type=authorization_code
spring.security.oauth2.client.registration.keycloak.redirect-uri={baseUrl}/login/oauth2/code/keycloak

If you can upgrade to 5.4+, you can simplify this by just setting the issuer-uri in the provider config—Spring will auto-fill all endpoints for you.

Better Learning Paths (Beyond Google & Javadoc)

Here's what I recommend to build a solid grasp:

  • Spring Security Official Docs: Start with the OAuth2 Client and OAuth2 Resource Server sections. They have clear explanations and Spring Boot-specific code examples.
  • Keycloak Spring Boot Guide: Keycloak's own docs have a dedicated Spring Boot Integration section that walks through configs for both clients and resource servers.
  • Hands-On Demos: Build tiny sample apps—first a client using authorization code flow for login, then a resource server validating Keycloak JWTs. Hands-on configuration makes these concepts click far better than reading alone.
  • Source/Javadoc Deep Dive: When stuck on a config, look at the classes behind the properties (e.g., OAuth2ClientProperties, ClientRegistration). Their Javadoc often has precise explanations of what each property does.

内容的提问来源于stack exchange,提问作者BAMF4bacon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 18:34:05