Keycloak -- OAuth2 -- Consent Page

Viewed 1017

Evaluating potentially leveraging KeyCloak to protect APIs --- still wrapping mind around KeyCloak.

Workflow: 1) User access Application A 2) User authenticates to Application A via Keycloak OpenID Connect 3) Application A calls APIs on Platform X -- APIs on Platform X are protected by KeyCloak OAuth2 -- in order to retrieve PII on user (say mail, address, favorite beer)

Question: Can KeyCloak present consent form to user for step 3 above -- i.e. that user agrees that Application A can call Platform X's API to retrieve data on user w.r.t mail, address, favorite beer?

1 Answers

This depends.. If both Applications are completely separate, but they are both within the same Realm in the same keycloak server, then you can have SSO implemented between apps where you don't need to retrieve info as the tokens received from keycloak will be available for App X with the same content provided to App A. The API will see you as who you are wrt App A. This means that you'll be "automatically logged in".

But, if they are secured with two different Keycloak server instances, then the second application should show the consent message. For example, my Dating website which is secured with Keycloak, asks you to connect to Facebook so it would populate a list of the pages you like to match you with someone... Facebook sign in dialog will pop up for you to sign in, then asks you if you allow App A to see your liked pages and interests.

Related