I have modified some SMS OTP Authentication SPI from github and successfully used it for Keycloak Authentication. Then I made a custom flow for browser so that:
- Username-only form gets the username (May be the mobile number)
- Sends code to the user mobile
- Gets the code and authenticates the user
The above works great! Now I need the same in REST API. When using documents, they say we have to set grant type. But the grant type is password in all examples.
curl -L -X POST 'http://localhost:8080/auth/realms/apiman/protocol/openid-connect/token' \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=account' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'client_secret=xxxxxxxxxxxxxxxxxxx' \
--data-urlencode 'scope=openid' \
--data-urlencode 'username=otp'
BTW: I have added direct grant bindings same as form bindings (which works great) with no luck. How can I use REST API for login flow same as form authentication?