# Federated OAuth Support

**URL:** <https://forum.keycloak.org/t/federated-oauth-support/13835>\
**Category:** Miscellanaeous\
**Created:** [February 23, 2022, 6:31pm UTC](https://forum.keycloak.org/t/federated-oauth-support/13835 "2022-02-23T18:31:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![j2eeservices](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/j2eeservices/32/5150_2.png) [@j2eeservices](https://forum.keycloak.org/u/j2eeservices)\
**Post date:** [February 23, 2022, 6:31pm UTC](https://forum.keycloak.org/t/federated-oauth-support/13835/1 "2022-02-23T18:31:33Z")

</div>

Hello,

I am new to KeyCloak and want opinion if the following flow is possible with KeyCloak?

KeyCloak Client (OIDC) → KeyCloak IAM (SAML) \<-\> Customer IDP

Basically, all internal apps will always interface with KeyCloak IAM(via Keycloak client adapter) using OIDC, but the customer may want to use SAML protocol for Federation.  
So, the expectation is that client will always trigger the OIDC Flow to KeyCloak IAM, but KeyCloak should trigger the SAML flow with the IDP. Once the user is logged in at their IDP and directed back to KeyCloak with valid SAML response, KeyCloak should resume the OIDC flow and return the token back to Keycloak client.

Any help in this regard appreciated.

---

<div class="post-metadata">

**Author:** ![mbonn](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/mbonn/32/5755_2.png) [@mbonn](https://forum.keycloak.org/u/mbonn)\
**Post date:** [February 24, 2022, 7:05am UTC](https://forum.keycloak.org/t/federated-oauth-support/13835/2 "2022-02-24T07:05:28Z")

</div>

Yes, that is possible, it is all in the docs:

[https://www.keycloak.org/docs/latest/server\_admin/index.html#\_identity\_broker](https://www.keycloak.org/docs/latest/server_admin/index.html#_identity_broker)  
[https://www.keycloak.org/docs/latest/server\_admin/index.html#saml-v2-0-identity-providers](https://www.keycloak.org/docs/latest/server_admin/index.html#saml-v2-0-identity-providers)

What will not work: Automatic integration of identity providers described in a standard SAML federation metadata file. Everything has to be configured manually.

|matthias
