Keycloak Admin Rest API unknown_error for update user API

Viewed 8103

I am trying to add a custom attribute to a user using Admin Rest API. When i try with default master realm, its working fine. But when i try it with another realm that i created, it yields "unknown_error".

I have attached the screenshot of request below. enter image description here

4 Answers

You haven't granted related permissions to your realm.

Go to 'Clients' -> select your client -> 'Service Account Roles':

  • In the client roles dropdown box, click realm-management
  • In Available Roles box, select related roles. Try manage-users and view-users.

Then get a new access token and try your API call again.

enter image description here

Apparently the Admin API needs to be accessed via the admin-cli client.

I got a 403 {"error":"unknown_error"} when I wanted to use a copy of the default admin-cli client.

I found that I had to use the admin-cli client in the master realm to use the admin REST API. When you look at the master realm, there is an admin role that does not exist in sub-realms. That admin role seems to be necessary to access the admin REST API successfully.

My suggestion is that you can create a client in the master realm as a service account, then assign the admin role to that client. You can then use that unique admin service account for API access by other programs.

Try to pass the attribute body like this.

{

"attributes": {
               "id": ["688"]
            }
}
Related