# Conceptual question - why does logout require a refresh token?

**URL:** <https://forum.keycloak.org/t/conceptual-question-why-does-logout-require-a-refresh-token/6292>\
**Category:** Miscellanaeous\
**Created:** [December 4, 2020, 8:44pm UTC](https://forum.keycloak.org/t/conceptual-question-why-does-logout-require-a-refresh-token/6292 "2020-12-04T20:44:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hamiltont](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/hamiltont/32/1833_2.png) [@hamiltont](https://forum.keycloak.org/u/hamiltont)\
**Post date:** [December 4, 2020, 8:44pm UTC](https://forum.keycloak.org/t/conceptual-question-why-does-logout-require-a-refresh-token/6292/1 "2020-12-04T20:44:54Z")

</div>

Conceptual question on OAuth logout, specifically the KeyCloak implementation.

I’m not understanding why Keycloak’s logout endpoint requires the caller to pass in both an access token and a refresh token. From [the source code](https://github.com/keycloak/keycloak/blob/master/services/src/main/java/org/keycloak/protocol/oidc/endpoints/LogoutEndpoint.java#L188) of `LogoutEndpoint#logoutToken`, we see this Javadoc comment:

> You must pass in the refresh token and authenticate the client if it is not public.

“authenticate the client” is clear - Keycloak wants to check your identity and ensure you can only logout yourself. Why it needs a refresh token is unclear.

The first thing this method does is access the refresh token from the request body and verify it. The git commit which added this verification references [KEYCLOAK-6771](https://issues.redhat.com/browse/KEYCLOAK-6771) which is about supporting HoK tokens (a reference to the OpenID Financial API). However, the code path verifies the request token for all logout requests, not just for HoK tokens.

By contrast, _RFC 7009 OAuth 2.0 Token Revocation_, which is supported by KeyCloak since 10.0.0 via GitHub PR#6704, does not require passing a refresh\_token to revoke an access token. However, I seem to again be misunderstanding something fundamental about the protocol, because while KeyCloak supports RFC 7009, they choose to only allow revoking refresh\_tokens and will not allow revoking access\_tokens.

Is this because they cannot guarantee an access\_token will no longer be accepted by downstream clients?

So I have two big conceptual questions:

1. Why does KC’s logout endpoint require passing a valid refresh token?
2. Why does KC’s token revocation endpoint only support revoking refresh tokens?

---

<div class="post-metadata">

**Author:** ![hamiltont](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/hamiltont/32/1833_2.png) [@hamiltont](https://forum.keycloak.org/u/hamiltont)\
**Post date:** [December 4, 2020, 8:57pm UTC](https://forum.keycloak.org/t/conceptual-question-why-does-logout-require-a-refresh-token/6292/2 "2020-12-04T20:57:01Z")

</div>

Discourse would not let me put \>2 links in the original post, so here are the reference links:

[Link](https://tools.ietf.org/html/rfc7009#section-2.1) to RFC 7009  
[Link](https://github.com/keycloak/keycloak/pull/6704) to GitHub PR#6704

---

<div class="post-metadata">

**Author:** ![nithin.bandaru1](https://avatars.discourse-cdn.com/v4/letter/n/ccd318/32.png) [@nithin.bandaru1](https://forum.keycloak.org/u/nithin.bandaru1)\
**Post date:** [March 24, 2023, 5:00am UTC](https://forum.keycloak.org/t/conceptual-question-why-does-logout-require-a-refresh-token/6292/3 "2023-03-24T05:00:25Z")

</div>

Seriously after 1.k views, no one replied. Crazy.
