You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Grafana集成Keycloak配置openid等scope时获取邮箱地址错误如何解决?

问题原因

Grafana使用通用OAuth对接身份源时,默认会在配置的api_url路径后拼接/emails后缀请求邮箱地址,而Keycloak的OpenID UserInfo接口不存在该路径,邮箱字段直接包含在UserInfo接口的返回JSON中,因此触发资源不存在的报错。

解决方案

  • 修改grafana.ini配置文件中[auth.generic_oauth]配置段,新增邮箱属性映射规则,指定Grafana直接从UserInfo返回结果的根节点读取email字段,无需额外请求独立的邮箱接口:
[auth.generic_oauth]
enabled = true
allow_sign_up = true
team_ids =
allowed_organizations =
name = Keycloak
scopes = openid profile email
client_id = grafana
client_secret = ba342011-3705-483c-8e04-7f95be561cd5
auth_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/auth
token_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/token
api_url = http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/userinfo
# 新增以下2行配置
email_attribute_name = email
email_attribute_path = email
# 若存在用户名、登录名显示异常,可额外添加以下2行配置
name_attribute_path = name
login_attribute_path = preferred_username
  • 验证Keycloak侧配置是否正确:
    1. 登录Keycloak管理后台,进入对应grafana客户端的「作用域」配置页,确认email作用域已添加
    2. 进入客户端「映射器」配置页,确认email映射规则存在,且「添加到用户信息」开关已开启
    3. 可通过以下命令手动验证UserInfo接口返回值是否包含email字段:
    curl -H "Authorization: Bearer 你获取到的Access Token" http://192.168.101.221:8080/auth/realms/grafana/protocol/openid-connect/userinfo
    
    正常返回结果应包含"email": "你的邮箱地址"字段。
  • 修改配置后重启Grafana服务,重新发起登录流程即可正常认证。

内容的提问来源于stack exchange,提问作者Ciocoiu Petrisor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 18:36:03