# Authentication Failure with OIDC Client After Keycloak Upgrade and Missing "sub" Claim

**URL:** <https://forum.keycloak.org/t/authentication-failure-with-oidc-client-after-keycloak-upgrade-and-missing-sub-claim/27972>\
**Category:** Miscellanaeous\
**Created:** [September 20, 2024, 12:08pm UTC](https://forum.keycloak.org/t/authentication-failure-with-oidc-client-after-keycloak-upgrade-and-missing-sub-claim/27972 "2024-09-20T12:08:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![umut123456](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/umut123456/32/11286_2.png) [@umut123456](https://forum.keycloak.org/u/umut123456)\
**Post date:** [September 20, 2024, 12:08pm UTC](https://forum.keycloak.org/t/authentication-failure-with-oidc-client-after-keycloak-upgrade-and-missing-sub-claim/27972/1 "2024-09-20T12:08:46Z")

</div>

Hello,

I recently upgraded my Keycloak instance to a newer version, and after the upgrade, I’m experiencing an authentication failure with my OIDC client. Upon checking the JWT token, I noticed that the **subject (“sub”) claim is missing**.

My questions are:

1. **Is the missing “sub” claim the reason for the failed authentication?**
2. **Is there any way to handle authentication without the “sub” claim?**

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [September 20, 2024, 12:14pm UTC](https://forum.keycloak.org/t/authentication-failure-with-oidc-client-after-keycloak-upgrade-and-missing-sub-claim/27972/2 "2024-09-20T12:14:07Z")

</div>

> [@umut123456](#):
>
> Is the missing “sub” claim the reason for the failed authentication?

No, as you actually have a token, the user is already authenticated succesfully. If your application can‘t handle it, it‘s not related to the authentication itself.

Most likely during the upgrade, your client was not configured to use the new „basic“ client scope as default. The „sub“ claim was moved to this scope. Add it as a default scope to your client config and you are good to go.

---

<div class="post-metadata">

**Author:** ![cffranco94](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/cffranco94/32/11420_2.png) [@cffranco94](https://forum.keycloak.org/u/cffranco94)\
**Post date:** [October 11, 2024, 7:16pm UTC](https://forum.keycloak.org/t/authentication-failure-with-oidc-client-after-keycloak-upgrade-and-missing-sub-claim/27972/3 "2024-10-11T19:16:49Z")

</div>

Hello @dasniko,

I already have the basic claim in the client, but still having issues with the sub claim. The authorization is successful, but the token exchange fails. Any ideas?

Thanks in advance
