# Dynamic Client registration with Token Exchange

**URL:** <https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297>\
**Category:** Miscellanaeous\
**Created:** [October 3, 2021, 9:18am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297 "2021-10-03T09:18:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:18am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/1 "2021-10-03T09:18:55Z")

</div>

Hi Members,

Our requirement is to enable users to create their own OIDC/OAuth2 clients with a definite scope.

We have a web application that was integrated with Keycloak with a client say “AppClient” with which users authenticate and get their OIDC Token, Access token.

We also have another client say “AppAdmin” of the type service account grant enabled (client credentials) with service account roles “Create client, Manage Client”.

Now we are trying to exchange the user’s access token from AppClient and getting a new access token for the “AppAdmin” Client but With this exchanged token I am not able to create/register a new client.  
Getting error response as insufficient\_scope.

Very much appreciate it if you can please advise on how to achieve our use case.

Thanks in advance.

Regards,  
Narendra

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:26am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/2 "2021-10-03T09:26:12Z")

</div>

Step 1: User Authentication to get an OIDC token and Access Token (ClientId: AppClient)

Request :  
curl --location --request POST ‘[http://localhost:8080/auth/realms/MyFirstRealm/protocol/openid-connect/token](http://localhost:8080/auth/realms/MyFirstRealm/protocol/openid-connect/token)’   
–header ‘Content-Type: application/x-www-form-urlencoded’   
–header ‘Cookie: AUTH\_SESSION\_ID\_LEGACY=ecfa1c43-a80c-41c6-9cfa-fdc5d4ce4af7.vpn-100’   
–data-urlencode ‘client\_id=AppClient’   
–data-urlencode ‘client\_secret=f81a92f6-d5b0-4b06-ad28-6dd1d4698b10’   
–data-urlencode ‘grant\_type=password’   
–data-urlencode ‘scope=MyFirstClientScope openid’   
–data-urlencode ‘username=achalla’   
–data-urlencode ‘password=admin’

Step-2 Exchange Access Token for a Different Client’s Access Token (ClientId: AppAdmin)

Request:  
curl --location --request POST ‘[http://localhost:8080/auth/realms/MyFirstRealm/protocol/openid-connect/token](http://localhost:8080/auth/realms/MyFirstRealm/protocol/openid-connect/token)’   
–header ‘Content-Type: application/x-www-form-urlencoded’   
–header ‘Cookie: AUTH\_SESSION\_ID\_LEGACY=ecfa1c43-a80c-41c6-9cfa-fdc5d4ce4af7.vpn-100’   
–data-urlencode ‘subject\_token=eyJhbGciOiJSUzI1NiIsInR5cCIgO\*\*\*\*\*\*\*\*\*\*\*’   
–data-urlencode ‘grant\_type=urn:ietf:params:oauth:grant-type:token-exchange’   
–data-urlencode ‘client\_id=AppClient’   
–data-urlencode ‘client\_secret=f81a92f6-d5b0-4b06-ad28-6dd1d4698b10’   
–data-urlencode ‘audience=AppAdmin’   
–data-urlencode ‘request\_token\_type=urn:ietf:params:oauth:token-type:access\_token’

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:29am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/3 "2021-10-03T09:29:11Z")

</div>

Step-3 Use New Access Token for Client Registration

Request:

curl --location --request POST ‘[http://localhost:8080/auth/realms/MyFirstRealm/clients-registrations/openid-connect](http://localhost:8080/auth/realms/MyFirstRealm/clients-registrations/openid-connect)’   
–header ‘Authorization: Bearer eyJhbcGciOiJSUzI1N\*\*\*\*\*\*\*\*\*\*\*\*\*’   
–header ‘Content-Type: application/json’   
–header ‘Cookie: AUTH\_SESSION\_ID\_LEGACY=ecfa1c43-a80c-41c6-9cfa-fdc5d4ce4af7.vpn-100’   
–data-raw ‘{  
“client\_name”: “MyClient”  
}’

Response:

{  
“error”: “insufficient\_scope”,  
“error\_description”: “Forbidden”  
}

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:38am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/4 "2021-10-03T09:38:46Z")

</div>

Also, I tried the following two cases,

1. Using the grant type = password on “ClienAdmin”, get an access token and tried to register a new client, getting an insufficient\_scope error

2. Using the grant type =client\_credentials on “ClientAdmin”, Got an access token and registered a new client successfully.

I suspect, the client\_credentials grant type only can fetch the entitlements from the service account roles and push them into the access token.  
The access tokens generated with other grant types will not get those entitlements and so failing while creating/registering the new client.

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:40am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/5 "2021-10-03T09:40:35Z")

</div>

Please suggest if there is any workaround for the above use case. So that an audit log can show us which user registered the new clients.

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:41am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/6 "2021-10-03T09:41:22Z")

</div>

Also, Is there any way to restrict users to manage/delete the clients only they created?

---

<div class="post-metadata">

**Author:** ![viruls](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/viruls/32/4033_2.png) [@viruls](https://forum.keycloak.org/u/viruls)\
**Post date:** [October 3, 2021, 9:45am UTC](https://forum.keycloak.org/t/dynamic-client-registration-with-token-exchange/11297/7 "2021-10-03T09:45:48Z")

</div>

References:  
[Token Exchange](https://www.keycloak.org/docs/latest/securing_apps/#_token-exchange) (7.1 Only)  
[Client Registration](https://www.keycloak.org/docs/latest/securing_apps/#_client_registration)
