使用Postman向Keycloak演示客户端发POST请求未返回refresh_token如何解决
Keycloak配置返回Refresh Token的解决方案
客户端侧配置调整
- 进入Keycloak管理后台对应Realm的客户端列表,打开你使用的演示客户端配置页,将*访问类型(Access Type)*设置为
confidential或public,不可使用bearer-only类型,该类客户端默认不会发放refresh token。 - 确认配置页中标准流启用(Standard Flow Enabled)、*直接访问授权启用(Direct Access Grants Enabled)*两个开关处于开启状态。
- 找到*刷新令牌生命周期(Refresh Token Lifespan)*配置项,确认数值未设置为0,设置为0会禁用refresh token发放,可根据业务需求调整有效期,系统默认值为30天。
请求参数调整
- 发送POST请求到Keycloak的token端点时,必须携带
scope=openid参数,缺少该参数默认不会返回refresh token。 - 密码授权模式请求示例如下:
POST /realms/{替换为你的Realm名称}/protocol/openid-connect/token Content-Type: application/x-www-form-urlencoded grant_type=password &client_id={替换为你的客户端ID} &client_secret={替换为你的客户端密钥,public类型客户端无需传递} &username={登录用户名} &password={登录密码} &scope=openid
额外注意事项
- 若使用授权码模式,在兑换token的步骤同样需要携带
scope=openid参数,即可同时获取access token、id token和refresh token。 - 若需要长期有效的refresh token,可开启客户端的*离线访问(Offline Access)*权限,请求时在scope参数中额外添加
offline_access即可。
内容的提问来源于stack exchange,提问作者RiptimRip
相关产品推荐
相关产品推荐

