如何从Keycloak AuthzClient获取其他声明?配置Mapper后仍为空
getOtherClaims() with Keycloak AuthzClient Let’s work through why you’re seeing empty results from getOtherClaims() even after setting up a custom attribute mapper in Keycloak. Here are the most likely issues and fixes to try:
1. You’re using the wrong method to access token claims
First, a critical clarification: AccessTokenResponse.getOtherClaims() returns extra parameters from the OAuth2 token response (like expires_in or custom response fields configured in Keycloak), not the custom claims embedded inside the JWT access token itself.
To access the custom attributes stored in the token payload, you need to decode the access token first:
// Decode the raw access token to get the AccessToken object AccessToken accessToken = authzClient.getTokenManager().decodeToken(accessTokenResponse.getToken()); // Fetch a specific custom claim by name String customPortalAttribute = (String) accessToken.getClaim("your_custom_claim_name"); System.out.println("Custom portal attribute: " + customPortalAttribute); // Or print all claims in the token payload System.out.println("All token claims: " + accessToken.getClaims());
2. Your custom claims aren’t actually present in the access token
Before debugging code, verify if your custom attributes are even included in the token:
- Print the raw access token string with
System.out.println(accessTokenResponse.getToken()); - Paste this string into a JWT parser tool (like jwt.io) and check the payload section. If your custom claims aren’t here, the issue lies with your Keycloak mapper configuration, not the code.
3. Fix your Keycloak Mapper configuration
If the claims aren’t in the token, double-check these mapper settings in Keycloak:
- Token Claim Name: Ensure this is the exact, case-sensitive name you’re trying to fetch in code.
- Add to access token: Make sure this checkbox is enabled (you’re using the access token, not the ID token).
- User Attribute: Confirm this matches the exact name of your portal’s custom user attribute (case-sensitive).
- Claim JSON Type: Match this to your attribute’s data type (e.g.,
Stringfor text values,Booleanfor flags).
4. Verify client scope and permissions
- Ensure your Keycloak client has the client scope containing your custom mapper attached. Go to your client’s "Client Scopes" tab and confirm the scope is added (either as default or optional).
- If you’re using Keycloak’s Authorization Services, check that your permission policies don’t restrict the inclusion of these custom claims in the access token.
Quick Diagnostic Test
Run this modified code to pinpoint where the issue is:
AccessTokenResponse accessTokenResponse = authzClient.obtainAccessToken(loginRequest.getUsername(), loginRequest.getPassword()); // This is what you were checking before (response-level extra fields) System.out.println("Response other claims: " + accessTokenResponse.getOtherClaims()); // This is where your custom attributes should appear (token payload) AccessToken accessToken = authzClient.getTokenManager().decodeToken(accessTokenResponse.getToken()); System.out.println("Token payload claims: " + accessToken.getClaims());
内容的提问来源于stack exchange,提问作者Nayan

