which API should use to get user permissions list by userId with Keycloak Admin REST API?

Viewed 66
1 Answers

User needs to assign the view-users role to user.

API

POST {Keycloak URL:PORT}/auth/admin/realms/{my-realm}/users/{user-ID}/role-mappings/clients/{realm-management-ID}

You can do it by Keycloak UI enter image description here

After assign this role into user, she can get the user list Demo by Postman enter image description here

If user has no this role, he can't get the user list. He get the HTTP 403 Forbidden response status enter image description here

In the Keycloak Admin API section, Add client-level roles to the user role mapping but it is not detail information. enter image description here

You can see detail steps, how to assign token variable in Postman. first step in here. that link use master-token but I use user-token. It is test{my-realm}'s specific user's(user name is user) token for demo.

If you use the master admin token, can get any realm's user list.

Related