Keycloak领域用户验证及Token获取技术咨询(新手求助)
Hey there, no worries at all—starting out with Keycloak can feel a bit confusing when you're first digging into the APIs! Let’s break down the simplest way to validate a user and get an access token, building on the work you’ve already done in the UI.
Since you mentioned you’ve already done some configuration in the Keycloak UI, let’s make sure we have the basics covered (these are prerequisites for the API call):
- You have a Realm (either the default
masterrealm, or a custom one you created—pro tip: use a custom realm for your apps instead of master) - You’ve created a Client for your application. Depending on your use case:
- If this is for a backend service, set the client’s Access Type to
confidential(you’ll need its Client Secret later) - If it’s for a frontend app, set it to
public
- If this is for a backend service, set the client’s Access Type to
- You’ve created a test User and set a valid password (you’ll need this user’s credentials to test the API)
- Double-check that Direct Access Grants Enabled is turned on for your client (under the client’s Settings tab—this allows the password grant flow we’ll use here)
Keycloak’s OpenID Connect token endpoint is where you’ll send the user’s credentials to get an access token. The base URL for your setup is:http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token
For Confidential Clients (Backend Services)
Use a POST request with form data (here’s a curl example you can run directly):
curl -X POST "http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=password" \ -d "client_id={YOUR_CLIENT_ID}" \ -d "client_secret={YOUR_CLIENT_SECRET}" \ -d "username={TEST_USER_USERNAME}" \ -d "password={TEST_USER_PASSWORD}"
For Public Clients (Frontend Apps)
The request is similar, but you omit the client_secret parameter:
curl -X POST "http://localhost:8008/auth/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=password" \ -d "client_id={YOUR_CLIENT_ID}" \ -d "username={TEST_USER_USERNAME}" \ -d "password={TEST_USER_PASSWORD}"
If the credentials are valid, you’ll get a JSON response with everything you need:
{ "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJ...", "expires_in": 300, "refresh_expires_in": 1800, "refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJ...", "token_type": "Bearer", "not-before-policy": 0, "session_state": "abc123xyz...", "scope": "openid email profile" }
- Use the
access_tokenas a Bearer token in your subsequent API calls (addAuthorization: Bearer {access_token}to your request headers) - Use the
refresh_tokento get a newaccess_tokenwhen the old one expires (without making the user log in again)
- If you’re using Keycloak 17 or newer, the API path no longer includes
/auth—so your endpoint would behttp://localhost:8008/realms/{YOUR_REALM_NAME}/protocol/openid-connect/token - The password grant flow we used here is great for testing or trusted internal services. For public-facing frontend apps, use the Authorization Code Flow with PKCE—it’s more secure
- Make sure your user’s password isn’t set to temporary (if you created it via the UI, you might have to toggle "Temporary" off when setting the password)
内容的提问来源于stack exchange,提问作者Rohitesh

