You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Authentik为OAuth2身份提供商对接Keycloak客户端遇错求助

问题:Keycloak集成Authentik作为身份提供商时认证失败

需求流程

  • 已在Authentik中存在的用户访问应用网站,点击Login按钮;
  • 被重定向至Keycloak登录页面,点击Login with Authentik按钮;
  • 被重定向至Authentik登录页面完成登录;
  • 被重定向回应用网站,Keycloak中添加该用户的基础信息;
  • 下次登录流程相同,但Keycloak不会新增用户条目。

环境配置

.env 文件内容

PG_PASS=FOocZZ7TtB+QDx4goBa9P7c7XjjbayXPCZKn/l8SKz7k6WsP
AUTHENTIK_SECRET_KEY=iL/rjxhET7UUkV6AVAF42KuG1GjENBKVgwxbAuD3dwKGDsA4F4WqQP9HiiORtOp26UKQuNzcSLQG55yf
AUTHENTIK_ERROR_REPORTING__ENABLED=true
AUTHENTIK_EMAIL__HOST=localhost
AUTHENTIK_EMAIL__PORT=25
AUTHENTIK_EMAIL__USERNAME=test@authentik.com
AUTHENTIK_EMAIL__PASSWORD=supersecretpassword
AUTHENTIK_EMAIL__USE_TLS=false
AUTHENTIK_EMAIL__USE_SSL=false
AUTHENTIK_EMAIL__TIMEOUT=10
AUTHENTIK_EMAIL__FROM=authentik@localhost

docker-compose.yaml 文件内容

---
services:
  postgresql:
    image: docker.io/library/postgres:16-alpine
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
      start_period: 20s
      interval: 30s
      retries: 5
      timeout: 5s
    volumes:
      - database:/var/lib/postgresql/data
    environment:
      POSTGRES_PASSWORD: ${PG_PASS:?database password required}
      POSTGRES_USER: ${PG_USER:-authentik}
      POSTGRES_DB: ${PG_DB:-authentik}
    env_file:
      - .env
  redis:
    image: docker.io/library/redis:alpine
    command: --save 60 1 --loglevel warning
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "redis-cli ping | grep PONG"]
      start_period: 20s
      interval: 30s
      retries: 5
      timeout: 3s
    volumes:
      - redis:/data
  server:
    image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.4.1}
    restart: unless-stopped
    command: server
    environment:
      AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_POSTGRESQL__HOST: postgresql
      AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
      AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
      AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
    volumes:
      - ./media:/media
      - ./custom-templates:/templates
    env_file:
      - .env
    ports:
      - "${COMPOSE_PORT_HTTP:-9000}:9000"
      - "${COMPOSE_PORT_HTTPS:-9443}:9443"
    depends_on:
      postgresql:
        condition: service_healthy
      redis:
        condition: service_healthy
  worker:
    image: ${AUTHENTIK_IMAGE:-ghcr.io/goauthentik/server}:${AUTHENTIK_TAG:-2025.4.1}
    restart: unless-stopped
    command: worker
    environment:
      AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:?secret key required}
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_POSTGRESQL__HOST: postgresql
      AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
      AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
      AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS}
    user: root
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
      - ./media:/media
      - ./certs:/certs
      - ./custom-templates:/templates
    env_file:
      - .env
    depends_on:
      postgresql:
        condition: service_healthy
      redis:
        condition: service_healthy

  keycloak:
    image: quay.io/keycloak/keycloak:26.2.5
    command: start-dev
    environment:
      KC_BOOTSTRAP_ADMIN_USERNAME: admin
      KC_BOOTSTRAP_ADMIN_PASSWORD: admin
    ports:
      - 8080:8080
      - 8443:8443
      - 9001:9000

volumes:
  database:
    driver: local
  redis:
    driver: local

已执行操作步骤

  • docker compose up -d;
  • 访问http://localhost:9000/if/flow/initial-setup/,设置邮箱admin@authentik.com、密码password;
  • 登录Authentik后台,创建用户user123并设置密码userpassword;
  • 创建OAuth2/OpenID ProviderMyProvider及对应应用MyApplication;
  • 登录Keycloak后台,创建OpenID Connect身份提供商authentik,配置相关URL、Client ID和Client Secret;
  • 在Authentik的MyProvider中添加重定向URI:http://localhost:8080/realms/master/broker/authentik/endpoint;
  • 打开无痕窗口访问http://localhost:8080/,点击Login with Authentik,使用user123/userpassword登录并点击Continue。

错误现象

被重定向到Keycloak URL:

http://localhost:8080/realms/master/broker/authentik/endpoint?code=12bc93c423db420690223c83ea14499f&state=mvQiFh0NjhLPXzAGv1SptJehMEwK2iVuqzWeyEdDC_M.cDP5u-nH0rU.2H2vdrPZQveN5tAD4RfpGg.eyJydSI6Imh0dHA6Ly9sb2NhbGhvc3Q6ODA4MC9hZG1pbi9tYXN0ZXIvY29uc29sZS8iLCJydCI6ImNvZGUiLCJybSI6InF1ZXJ5Iiwic3QiOiJlNjNhMjg2YS1iNzljLTQxNGItYjIyZi0xMGQ1M2Q5YzFlNjUifQ

并显示错误:We are sorry... Unexpected error when authenticating with identity provider

排查方向

  • 检查Keycloak身份提供商的OIDC端点配置:
    确认Keycloak中配置的Authentik端点是否正确,Authentik的OIDC端点路径为/application/o/开头,需对应创建的MyProvider实际端点:

    • 授权端点:http://localhost:9000/application/o/authorize/
    • 令牌端点:http://localhost:9000/application/o/token/
    • 用户信息端点:http://localhost:9000/application/o/userinfo/
    • JWKS端点:http://localhost:9000/application/o/.well-known/jwks.json
  • 验证Client ID/Secret一致性:
    确保Keycloak中填写的Client ID和Secret,与Authentik的MyProvider生成的完全一致,注意大小写、特殊字符无遗漏。

  • 检查Docker容器网络连通性:
    Keycloak容器内部无法通过localhost:9000访问Authentik,需改用Docker服务名server配置端点,即:
    http://server:9000/application/o/authorize/等,重定向URI仍保留http://localhost:8080/...(外部访问地址)。

  • 查看日志定位具体错误:

    • 查看Keycloak日志:docker compose logs keycloak,搜索error或broker关键词;
    • 查看Authentik日志:docker compose logs server worker,检查授权流程中的错误返回。
  • 确认Authentik Provider的Scopes配置:
    在Authentik的MyProvider中,必须勾选openid、profile、email等必要Scopes,Keycloak需要这些信息同步用户数据。

内容的提问来源于stack exchange,提问作者ychiucco

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 23:30:00