# Evaluation of Posibilities

**URL:** <https://forum.keycloak.org/t/evaluation-of-posibilities/11021>\
**Category:** Getting advice\
**Tags:** authentication, saml\
**Created:** [September 16, 2021, 10:54am UTC](https://forum.keycloak.org/t/evaluation-of-posibilities/11021 "2021-09-16T10:54:40Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![alpe](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@alpe](https://forum.keycloak.org/u/alpe)\
**Post date:** [September 16, 2021, 10:54am UTC](https://forum.keycloak.org/t/evaluation-of-posibilities/11021/1 "2021-09-16T10:54:40Z")

</div>

Hi all,

we are planning to implement keycloak in our company.

- the main goal is to have one login for all (four) web applications.
- one App is working with session/cookie, one has only a SAML adapter and the rest ist with JWT
- two Apps are available from public internet
- users have different roles across the apps i.e. UserA has noAdminRole in App1 and AdminRole in App2
- users may have access to App1 but not to App2
- all apps can be refactored

Before i give everything a try in testsystems i would ask you kindly some questions:  
**Q1:** if i switch from App1(jwt) to App2(jwt) i assume that i dont have to login again in App2 right?

**Q2:** if i switch from App1(jwt) to App3(session/cookie) do i need to relogin here? Or will the session cookie somehow generated in App1 and then used by App3?

**Q3:** can the rolemanagement of the users administrated via the apps themselves? on some apps the roleconfiguration could be really difficult

**Q4:** is it possible that some users have access to App1 but not to App3 and vice versa?  
is there a general View on not allowed? or does this has to be implemented app by app?
