Keycloak IAM Deep Dive | Realms, OAuth2 Clients, Roles, PKCE & JWT
Secure AI Learning Lab
0:00 / 0:00
Keycloak IAM Deep Dive | Realms, OAuth2 Clients, Roles, PKCE & JWT
24 просмотра · 9 дней назад
Secure AI Learning Lab
41 подписчик
24 просмотра · 9 дней назад
How do you configure Keycloak Identity and Access Management for both human users and machine-to-machine applications?
In this video, I walk through a complete Keycloak v26 realm configuration, including realm JSON export/import, OAuth2 clients, PKCE, Client Credentials, realm roles, JWT claims, client scopes, service accounts, and token testing.
The example demonstrates two very different authentication patterns inside the same enterprise architecture:
Human User → Angular SPA → Keycloak → Authorization Code + PKCE
and
Python AI Agent → Keycloak → Client Credentials → Spring Boot APIs
This is a practical Keycloak IAM walkthrough based on an enterprise Agentic AI retail replenishment Proof of Concept.
1. Keycloak Realm Configuration
2. Public Angular Client — Authorization Code + PKCE
3. Confidential Python Agent — Client Credentials Grant
4. Realm Roles and RBAC
5. JWT Access Tokens
We inspect the JWT access token issued by Keycloak and examine important claims such as:
iss
sub
aud
exp
iat
azp
scope
realm_access
resource_access
6. Client Scopes
Client scopes are an important but sometimes confusing part of Keycloak.
We look at how scopes influence:
Token contents
Protocol mappers
Role claims
OpenID Connect behavior
Client configuration
7. Realm Export and Import Gotchas
8. Manual OAuth2 Token Testing
9. Security Responsibility Boundaries