# External service authentication

**URL:** <https://forum.keycloak.org/t/external-service-authentication/1012>\
**Category:** Getting advice\
**Tags:** oidc\
**Created:** [January 21, 2020, 2:45pm UTC](https://forum.keycloak.org/t/external-service-authentication/1012 "2020-01-21T14:45:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tmanninger](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@tmanninger](https://forum.keycloak.org/u/tmanninger)\
**Post date:** [January 21, 2020, 2:45pm UTC](https://forum.keycloak.org/t/external-service-authentication/1012/1 "2020-01-21T14:45:32Z")

</div>

Hi,

i have a keycloak server in my local network, which is only reachable from my local network and i also have an external service, which cannot reach my local keycloak server, but i need to enable oidc authentication for this service.

At the keycloak clients configuration, i found the access-type option “public”. If i unterstand it correctly, this should be possible with this option?

I also tried it with keycloak-gatekeeper, but gatekeeper needs an secret key (which is not available in the public mode).

What’s the correct configuration?

Thanks for help!

---

<div class="post-metadata">

**Author:** ![g0ha](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@g0ha](https://forum.keycloak.org/u/g0ha)\
**Post date:** [January 22, 2020, 6:41am UTC](https://forum.keycloak.org/t/external-service-authentication/1012/2 "2020-01-22T06:41:57Z")

</div>

I’m not shure, but i think you shoud configure port forward for accessing to keycloak instance via external service. I don’t think, that “public” switch can resolve your issue. This is just network access problem.

---

<div class="post-metadata">

**Author:** ![tmanninger](https://avatars.discourse-cdn.com/v4/letter/t/ecccb3/32.png) [@tmanninger](https://forum.keycloak.org/u/tmanninger)\
**Post date:** [January 22, 2020, 7:31am UTC](https://forum.keycloak.org/t/external-service-authentication/1012/3 "2020-01-22T07:31:58Z")

</div>

Hello g0ha,

For security reasons i want to avoid, that my keycloak server is public accessable.

Is there no other way?

Best regards,  
Thomas

---

<div class="post-metadata">

**Author:** ![g0ha](https://avatars.discourse-cdn.com/v4/letter/g/74df32/32.png) [@g0ha](https://forum.keycloak.org/u/g0ha)\
**Post date:** [January 22, 2020, 9:07am UTC](https://forum.keycloak.org/t/external-service-authentication/1012/4 "2020-01-22T09:07:32Z")

</div>

If external service have “white” ip address, you can make access only for this IP (Via firewall on your gate)
