You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak领域用户验证及Token获取技术咨询(新手求助)

Hey there, no worries at all—starting out with Keycloak can feel a bit confusing when you're first digging into the APIs! Let’s break down the simplest way to validate a user and get an access token, building on the work you’ve already done in the UI.

First: Confirm Your UI Setup

Since you mentioned you’ve already done some configuration in the Keycloak UI, let’s make sure we have the basics covered (these are prerequisites for the API call):

  • You have a Realm (either the default master realm, or a custom one you created—pro tip: use a custom realm for your apps instead of master)
  • You’ve created a Client for your application. Depending on your use case:
    • If this is for a backend service, set the client’s Access Type to confidential (you’ll need its Client Secret later)
    • If it’s for a frontend app, set it to public
  • You’ve created a test User and set a valid password (you’ll need this user’s credentials to test the API)
  • Double-check that Direct Access Grants Enabled is turned on for your client (under the client’s Settings tab—this allows the password grant flow we’ll use here)
Second: Call the Token API to Authenticate the User

Keycloak’s OpenID Connect token endpoint is where you’ll send the user’s credentials to get an access token. The base URL for your setup is:
http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token

For Confidential Clients (Backend Services)

Use a POST request with form data (here’s a curl example you can run directly):

curl -X POST "http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password" \
  -d "client_id={YOUR_CLIENT_ID}" \
  -d "client_secret={YOUR_CLIENT_SECRET}" \
  -d "username={TEST_USER_USERNAME}" \
  -d "password={TEST_USER_PASSWORD}"

For Public Clients (Frontend Apps)

The request is similar, but you omit the client_secret parameter:

curl -X POST "http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password" \
  -d "client_id={YOUR_CLIENT_ID}" \
  -d "username={TEST_USER_USERNAME}" \
  -d "password={TEST_USER_PASSWORD}"
Third: Use the Returned Token

If the credentials are valid, you’ll get a JSON response with everything you need:

{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJ...",
  "expires_in": 300,
  "refresh_expires_in": 1800,
  "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJ...",
  "token_type": "Bearer",
  "not-before-policy": 0,
  "session_state": "abc123xyz...",
  "scope": "openid email profile"
}
  • Use the access_token as a Bearer token in your subsequent API calls (add Authorization: Bearer {access_token} to your request headers)
  • Use the refresh_token to get a new access_token when the old one expires (without making the user log in again)
Quick Notes
  • If you’re using Keycloak 17 or newer, the API path no longer includes /auth—so your endpoint would be http://localhost:8008/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token
  • The password grant flow we used here is great for testing or trusted internal services. For public-facing frontend apps, use the Authorization Code Flow with PKCE—it’s more secure
  • Make sure your user’s password isn’t set to temporary (if you created it via the UI, you might have to toggle "Temporary" off when setting the password)

内容的提问来源于stack exchange,提问作者Rohitesh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:12:34