You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从Keycloak AuthzClient获取其他声明?配置Mapper后仍为空

Troubleshooting Empty getOtherClaims() with Keycloak AuthzClient

Let’s work through why you’re seeing empty results from getOtherClaims() even after setting up a custom attribute mapper in Keycloak. Here are the most likely issues and fixes to try:

1. You’re using the wrong method to access token claims

First, a critical clarification: AccessTokenResponse.getOtherClaims() returns extra parameters from the OAuth2 token response (like expires_in or custom response fields configured in Keycloak), not the custom claims embedded inside the JWT access token itself.

To access the custom attributes stored in the token payload, you need to decode the access token first:

// Decode the raw access token to get the AccessToken object
AccessToken accessToken = authzClient.getTokenManager().decodeToken(accessTokenResponse.getToken());

// Fetch a specific custom claim by name
String customPortalAttribute = (String) accessToken.getClaim("your_custom_claim_name");
System.out.println("Custom portal attribute: " + customPortalAttribute);

// Or print all claims in the token payload
System.out.println("All token claims: " + accessToken.getClaims());

2. Your custom claims aren’t actually present in the access token

Before debugging code, verify if your custom attributes are even included in the token:

  • Print the raw access token string with System.out.println(accessTokenResponse.getToken());
  • Paste this string into a JWT parser tool (like jwt.io) and check the payload section. If your custom claims aren’t here, the issue lies with your Keycloak mapper configuration, not the code.

3. Fix your Keycloak Mapper configuration

If the claims aren’t in the token, double-check these mapper settings in Keycloak:

  • Token Claim Name: Ensure this is the exact, case-sensitive name you’re trying to fetch in code.
  • Add to access token: Make sure this checkbox is enabled (you’re using the access token, not the ID token).
  • User Attribute: Confirm this matches the exact name of your portal’s custom user attribute (case-sensitive).
  • Claim JSON Type: Match this to your attribute’s data type (e.g., String for text values, Boolean for flags).

4. Verify client scope and permissions

  • Ensure your Keycloak client has the client scope containing your custom mapper attached. Go to your client’s "Client Scopes" tab and confirm the scope is added (either as default or optional).
  • If you’re using Keycloak’s Authorization Services, check that your permission policies don’t restrict the inclusion of these custom claims in the access token.

Quick Diagnostic Test

Run this modified code to pinpoint where the issue is:

AccessTokenResponse accessTokenResponse = authzClient.obtainAccessToken(loginRequest.getUsername(), loginRequest.getPassword());

// This is what you were checking before (response-level extra fields)
System.out.println("Response other claims: " + accessTokenResponse.getOtherClaims());

// This is where your custom attributes should appear (token payload)
AccessToken accessToken = authzClient.getTokenManager().decodeToken(accessTokenResponse.getToken());
System.out.println("Token payload claims: " + accessToken.getClaims());

内容的提问来源于stack exchange,提问作者Nayan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 09:37:37