# Best practices exposing id providers endpoints

**URL:** <https://forum.keycloak.org/t/best-practices-exposing-id-providers-endpoints/321>\
**Category:** Miscellanaeous\
**Created:** [November 5, 2019, 1:15pm UTC](https://forum.keycloak.org/t/best-practices-exposing-id-providers-endpoints/321 "2019-11-05T13:15:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulogervas](https://avatars.discourse-cdn.com/v4/letter/p/eb8c5e/32.png) [@paulogervas](https://forum.keycloak.org/u/paulogervas)\
**Post date:** [November 5, 2019, 1:15pm UTC](https://forum.keycloak.org/t/best-practices-exposing-id-providers-endpoints/321/1 "2019-11-05T13:15:39Z")

</div>

Hi!

I am implementing the complete authorization and authentication flow using keycloak as identity provider and oauth2.

I have some questions that I would like to share with you in order to get more opinions and find the best solution.

My infrastructure basically has:

LB \>\> WAF \>\> API GATEWAY \>\> IDENTITY PROVIDER \>\> SERVICES

My questions relate mainly to exposing Keycloak endpoints publicly for authentication.

For example: It’s a good practice to expose the Identity provider after WAF? (Following the infra described above the requests will hit ID provider directly bypassing api gateway).

Which approach have you been using?

Thanks  
Paulo.
