# Client Registration with Signed JWT

**URL:** <https://forum.keycloak.org/t/client-registration-with-signed-jwt/9961>\
**Category:** Getting advice\
**Tags:** admin-console, oidc\
**Created:** [July 7, 2021, 2:24pm UTC](https://forum.keycloak.org/t/client-registration-with-signed-jwt/9961 "2021-07-07T14:24:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![denisky](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/denisky/32/3498_2.png) [@denisky](https://forum.keycloak.org/u/denisky)\
**Post date:** [July 7, 2021, 2:24pm UTC](https://forum.keycloak.org/t/client-registration-with-signed-jwt/9961/1 "2021-07-07T14:24:14Z")

</div>

Hi,  
we have a use case where we want to register new clients on KeyCloak using the Client Registration Service.  
We want our client to authenticate through **Signed JWT**.

The service support different providers, my question is if we go with **openid-connect** is there a way to set the **clientAuthenticatorType** or we have to use the default provider?

---

<div class="post-metadata">

**Author:** ![ozidrifter](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/ozidrifter/32/5317_2.png) [@ozidrifter](https://forum.keycloak.org/u/ozidrifter)\
**Post date:** [March 14, 2022, 5:27am UTC](https://forum.keycloak.org/t/client-registration-with-signed-jwt/9961/2 "2022-03-14T05:27:14Z")

</div>

Hi Guys,

We have a similar use case as @denisky outlined above, but can see no response to date.

We’re working in the Australian Open Banking domain and are looking at implementing a light-weight local mocked “data-holder” (Bank) and are hoping Keycloak will be able to provide the OAuth2 OIDC features we need. One of these features is “[Dynamic Client Register](https://consumerdatastandardsaustralia.github.io/standards/#register-data-recipient-oauth-client)” and I can see Keycloak offers the “Client Registration” feature.

I’ve seen examples of a JSON post requests being sent to the “registration\_endpoint”, however our requirements, as can been seen from the above link, needs to allow us to pass in a Signed JWT.

We would expect that the signed JWT would be validated against the provided JWKS\_URI claim and we’ll also need to be able to validate the “software\_statement” claim and possible store and use the values from this SSA as its from a trusted source (ie redirect\_uris, jwks\_uri etc)

Any advise / guidance on this would be appreciated.

Cheers  
Mark

---

<div class="post-metadata">

**Author:** ![thiago\_aor](https://avatars.discourse-cdn.com/v4/letter/t/f1d935/32.png) [@thiago\_aor](https://forum.keycloak.org/u/thiago_aor)\
**Post date:** [December 10, 2022, 9:55pm UTC](https://forum.keycloak.org/t/client-registration-with-signed-jwt/9961/3 "2022-12-10T21:55:20Z")

</div>

Hi!

I would like to know if there~s a solution to configure dynamicaly the requests in Keycloak’s GUI for this problem.  
Does anyone have an answer?

Regards,
