Limited user's token scope on user password grant flow

Viewed 102

I have a Keycloak instance with :

  • user1 / password1
  • user2 / password2
  • client / secret with Direct Access Grants Enable and scopes : resourceA, resourceB

When I do a password grant flow like :

curl --location --request POST 'https://keycloak.instance/auth/realms/my-realm/protocol/openid-connect/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=password' \
--data-urlencode 'client_id=client' \
--data-urlencode 'client_secret=secret' \
--data-urlencode 'username=user1' \
--data-urlencode 'password=password1'

I want to retrieve a token with the scope : resourceA and NOT resourceB. And when the same call is made using user2, I want ONLY resourceB scope.

Is there a way to configure this rule in Keycloak to only have a token with an intersection of scope/role of the client and the grant user ?

0 Answers
Related