Skip to content

IdP Integration

Integration with Identity Providers

The Authorization Code Grant Flow is commonly used in server-side applications to securely obtain access tokens from identity providers (IdPs) like Keycloak. When integrating with Keycloak and HashiCorp Vault, the flow involves:
1. Redirecting users to Keycloak for authentication and authorization.
2. Exchanging the authorization code for tokens (access, refresh, ID) using the client secret (stored securely in Vault).
3. Using Vault to manage secrets (e.g., client secrets) and optionally store tokens for secure access.

This section demonstrates how to implement this flow with Keycloak as the IdP and Vault for secret management.


Keycloak Configuration for Authorization Code Flow

1. Register a Client in Keycloak

Create a client application in Keycloak and configure it for the Authorization Code flow.

Steps:
- Log in to Keycloak Admin Console.
- Navigate to Clients > Create Client.
- Set Client ID (e.g., my-app) and enable Standard Flow.
- Under Redirect URIs, add https://your-app.com/callback (exact URI depends on your app).
- Enable Service Accounts and Client Authentication (if using client secrets).

Example: Create a client via Keycloak Admin API

curl -X POST \
  http://localhost:8080/auth/realms/master/clients \
  -H "Authorization: Bearer <admin-token>" \
  -H "Content-Type: application/json" \
  -d '{
    "clientId": "my-app",
    "redirectUris": ["https://your-app.com/callback"],
    "enabled": true
  }'

2. Configure PKCE (Optional for Public Clients)

If your client is a public client (no client secret), enable Proof Key for Code Exchange (PKCE):
- In Keycloak, enable PKCE under the client's Advanced Settings.
- During the flow, generate a code_verifier and code_challenge to secure the authorization code.


HashiCorp Vault Integration for Secret Management

1. Store Client Secret in Vault

Vault securely stores secrets like client secrets, which are used to exchange the authorization code for tokens.

Example: Store Keycloak client secret in Vault

vault kv put secret/keycloak-client \
  client_id="my-app" \
  client_secret="your-client-secret"

2. Retrieve Secret During Token Exchange

In your application, retrieve the client secret from Vault before exchanging the authorization code.

Example: Retrieve secret using Vault API

VAULT_TOKEN=<your-vault-token> \
curl -X GET \
  http://localhost:8200/v1/secret/keycloak-client \
  -H "X-Vault-Token: $VAULT_TOKEN"


Combined Workflow: Authorization Code Flow with Keycloak + Vault

  1. Redirect to Keycloak

    GET https://keycloak.example.com/auth/realms/your-realm/protocol/openid-connect/auth
      ?client_id=my-app
      &redirect_uri=https://your-app.com/callback
      &response_type=code
      &scope=openid
      &state=xyz
    

  2. User Authentication
    Keycloak prompts the user to log in. Upon successful authentication, Keycloak redirects the user back to your app with an authorization_code.

  3. Exchange Code for Tokens
    Use the client secret (retrieved from Vault) to exchange the code for tokens:

    curl -X POST \
      https://keycloak.example.com/auth/realms/your-realm/protocol/openid-connect/token \
      -H "Content-Type: application/x-www-form-urlencoded" \
      -d "grant_type=authorization_code" \
      -d "client_id=my-app" \
      -d "client_secret=<vault-retrieved-secret>" \
      -d "code=<authorization-code>" \
      -d "redirect_uri=https://your-app.com/callback"
    

  4. Store Tokens Securely (Optional)
    Use Vault to store tokens or sensitive data retrieved from Keycloak.


Security Considerations

  • Always use HTTPS to protect communication between your app, Keycloak, and Vault.
  • Rotate client secrets periodically and store them in Vault.
  • Enable PKCE for public clients to prevent authorization code interception.

Key takeaways

  • Keycloak provides the identity provider for user authentication, while Vault securely stores client secrets and tokens.
  • The Authorization Code flow requires exchanging the authorization code for tokens using the client secret, which must be retrieved from Vault.
  • PKCE is critical for public clients to mitigate replay attacks.
  • Always use HTTPS and rotate secrets to maintain security.