IdP Integration
Integration with Identity Providers¶
The Authorization Code Grant Flow is commonly used in server-side applications to securely obtain access tokens from identity providers (IdPs) like Keycloak. When integrating with Keycloak and HashiCorp Vault, the flow involves:
1. Redirecting users to Keycloak for authentication and authorization.
2. Exchanging the authorization code for tokens (access, refresh, ID) using the client secret (stored securely in Vault).
3. Using Vault to manage secrets (e.g., client secrets) and optionally store tokens for secure access.
This section demonstrates how to implement this flow with Keycloak as the IdP and Vault for secret management.
Keycloak Configuration for Authorization Code Flow¶
1. Register a Client in Keycloak¶
Create a client application in Keycloak and configure it for the Authorization Code flow.
Steps:
- Log in to Keycloak Admin Console.
- Navigate to Clients > Create Client.
- Set Client ID (e.g., my-app) and enable Standard Flow.
- Under Redirect URIs, add https://your-app.com/callback (exact URI depends on your app).
- Enable Service Accounts and Client Authentication (if using client secrets).
Example: Create a client via Keycloak Admin API
curl -X POST \
http://localhost:8080/auth/realms/master/clients \
-H "Authorization: Bearer <admin-token>" \
-H "Content-Type: application/json" \
-d '{
"clientId": "my-app",
"redirectUris": ["https://your-app.com/callback"],
"enabled": true
}'
2. Configure PKCE (Optional for Public Clients)¶
If your client is a public client (no client secret), enable Proof Key for Code Exchange (PKCE):
- In Keycloak, enable PKCE under the client's Advanced Settings.
- During the flow, generate a code_verifier and code_challenge to secure the authorization code.
HashiCorp Vault Integration for Secret Management¶
1. Store Client Secret in Vault¶
Vault securely stores secrets like client secrets, which are used to exchange the authorization code for tokens.
Example: Store Keycloak client secret in Vault
2. Retrieve Secret During Token Exchange¶
In your application, retrieve the client secret from Vault before exchanging the authorization code.
Example: Retrieve secret using Vault API
VAULT_TOKEN=<your-vault-token> \
curl -X GET \
http://localhost:8200/v1/secret/keycloak-client \
-H "X-Vault-Token: $VAULT_TOKEN"
Combined Workflow: Authorization Code Flow with Keycloak + Vault¶
-
Redirect to Keycloak
-
User Authentication
Keycloak prompts the user to log in. Upon successful authentication, Keycloak redirects the user back to your app with anauthorization_code. -
Exchange Code for Tokens
Use the client secret (retrieved from Vault) to exchange the code for tokens:
curl -X POST \ https://keycloak.example.com/auth/realms/your-realm/protocol/openid-connect/token \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=authorization_code" \ -d "client_id=my-app" \ -d "client_secret=<vault-retrieved-secret>" \ -d "code=<authorization-code>" \ -d "redirect_uri=https://your-app.com/callback" -
Store Tokens Securely (Optional)
Use Vault to store tokens or sensitive data retrieved from Keycloak.
Security Considerations¶
- Always use HTTPS to protect communication between your app, Keycloak, and Vault.
- Rotate client secrets periodically and store them in Vault.
- Enable PKCE for public clients to prevent authorization code interception.
Key takeaways¶
- Keycloak provides the identity provider for user authentication, while Vault securely stores client secrets and tokens.
- The Authorization Code flow requires exchanging the authorization code for tokens using the client secret, which must be retrieved from Vault.
- PKCE is critical for public clients to mitigate replay attacks.
- Always use HTTPS and rotate secrets to maintain security.