You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Keycloak 26.2令牌交换配置异常问题求助

Keycloak跨Realm令牌交换失败:Key not found错误

我们正在开发一款API网关,收到外部IdP的Bearer令牌时会执行OAuth2令牌交换操作。为在CI流水线中测试该功能,我们部署了Keycloak,通过internal和external两个realm分别模拟公司内部IdP与外部IdP。但配置令牌交换时遇到以下错误:

2025-06-27 07:04:41,089 DEBUG [org.keycloak.authentication.AuthenticationProcessor] (executor-thread-13) AUTHENTICATE CLIENT
2025-06-27T07:04:41.090378045Z 2025-06-27 07:04:41,090 DEBUG [org.keycloak.authentication.ClientAuthenticationFlow] (executor-thread-13) client authenticator: client-secret
2025-06-27T07:04:41.090448345Z 2025-06-27 07:04:41,090 DEBUG [org.keycloak.authentication.ClientAuthenticationFlow] (executor-thread-13) client authenticator SUCCESS: client-secret
2025-06-27T07:04:41.090459945Z 2025-06-27 07:04:41,090 DEBUG [org.keycloak.authentication.ClientAuthenticationFlow] (executor-thread-13) Client internal-cli authenticated by client-secret
2025-06-27T07:04:41.092154945Z 2025-06-27 07:04:41,091 DEBUG [org.keycloak.services.managers.AuthenticationManager] (executor-thread-13) Failed to verify identity token: Key not found
...
2025-06-27T07:04:41.092923845Z 2025-06-27 07:04:41,092 WARN  [org.keycloak.events] (executor-thread-13) type="TOKEN_EXCHANGE_ERROR", realmId="d0418d1d-0102-4f6f-9add-f3469e079937", realmName="internal", clientId="internal-cli", userId="null", ipAddress="192.168.143.2", error="invalid_token", reason="subject_token validation failure", auth_method="token_exchange", grant_type="urn:ietf:params:oauth:grant-type:token-exchange", client_auth_method="client-secret"

复现步骤

  • 启动提供的docker-compose文件,等待Keycloak启动完成(访问地址:http://localhost:8080)
  • 执行requests.http文件中的两个请求:
    • 获取external realm的令牌
    • 执行令牌交换:将外部令牌转换为内部令牌

我们仅将Keycloak用于测试,不涉及IdP开发,因此需要纯配置方式解决此问题,恳请提供帮助。

内容的提问来源于stack exchange,提问作者Sandra Markerud

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 19:45:12