Перейти к содержимому

Keycloak IAM Deep Dive | Realms, OAuth2 Clients, Roles, PKCE & JWT

Secure AI Learning Lab

0:00 / 0:00

Keycloak IAM Deep Dive | Realms, OAuth2 Clients, Roles, PKCE & JWT

24 просмотра · 9 дней назад
Secure AI Learning Lab
41 подписчик
24 просмотра · 9 дней назад
How do you configure Keycloak Identity and Access Management for both human users and machine-to-machine applications? In this video, I walk through a complete Keycloak v26 realm configuration, including realm JSON export/import, OAuth2 clients, PKCE, Client Credentials, realm roles, JWT claims, client scopes, service accounts, and token testing. The example demonstrates two very different authentication patterns inside the same enterprise architecture: Human User → Angular SPA → Keycloak → Authorization Code + PKCE and Python AI Agent → Keycloak → Client Credentials → Spring Boot APIs This is a practical Keycloak IAM walkthrough based on an enterprise Agentic AI retail replenishment Proof of Concept. 1. Keycloak Realm Configuration 2. Public Angular Client — Authorization Code + PKCE 3. Confidential Python Agent — Client Credentials Grant 4. Realm Roles and RBAC 5. JWT Access Tokens We inspect the JWT access token issued by Keycloak and examine important claims such as: iss sub aud exp iat azp scope realm_access resource_access 6. Client Scopes Client scopes are an important but sometimes confusing part of Keycloak. We look at how scopes influence: Token contents Protocol mappers Role claims OpenID Connect behavior Client configuration 7. Realm Export and Import Gotchas 8. Manual OAuth2 Token Testing 9. Security Responsibility Boundaries