Keycloak signs users in against a realm you or a customer runs. The directory stays on that server. Authdog fronts the application. Create a confidential client in the realm, then paste its credentials and the realm base URL into the environment.
Copy the redirect URI
In the Authdog console, select the project and environment, open Authentication > Providers, find Keycloak, and click Enable. Copy the redirect URI:
https://identity.authdog.com/api/v1/callback/<connectionId>Create the realm client
- Open the Keycloak admin console and select the realm.
- Under Clients, create a client with Client authentication on (a confidential client).
- Enable the Standard flow (authorization code).
- Under Valid redirect URIs, add the redirect URI from Authdog.
- Save, then copy the Client ID and the secret from the Credentials tab.
- Note the realm base URL. That is the Domain URI, for example
https://keycloak.example.com/realms/acme.
Use the realm base URL, not the admin console URL and not the authorize endpoint.
Configure Authdog
| Field | Value |
|---|---|
| Client ID | The client identifier |
| Client Secret | The secret from the Credentials tab |
| Domain URI | https://host/realms/<realm> |
Save, then toggle the connection active. Authdog requests openid email profile and reads the profile from the ID token. Protocol mappers on the realm control extra claims.
Test it
- Open hosted sign-in, or
https://identity.authdog.com/api/v1/signin/<connectionId>. - Select the Keycloak button and complete the flow.
- Confirm the user appears under Users with a Keycloak identity.
Troubleshooting
| Symptom | Cause |
|---|---|
invalid_client |
The client is public, so it has no secret |
Invalid parameter: redirect_uri |
The URI is missing from the client's valid redirect URIs |
| 404 on authorize | The Domain URI is not the realm base |
| Works in one environment only | Each environment has its own connectionId and redirect URI |
Related
| Read | To learn how to |
|---|---|
| Keycloak connector | The same setup in the connector catalog |
| Enterprise SSO | Connect Keycloak as a generic OIDC enterprise connection with domain routing |
| Marketplace | The listing for this integration |