# Frontend- and backendurls published in well-known/openid-configuration

**URL:** <https://forum.keycloak.org/t/frontend-and-backendurls-published-in-well-known-openid-configuration/18612>\
**Category:** Configuring the server\
**Created:** [November 25, 2022, 1:55pm UTC](https://forum.keycloak.org/t/frontend-and-backendurls-published-in-well-known-openid-configuration/18612 "2022-11-25T13:55:56Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jona](https://avatars.discourse-cdn.com/v4/letter/j/3d9bf3/32.png) [@jona](https://forum.keycloak.org/u/jona)\
**Post date:** [November 25, 2022, 1:55pm UTC](https://forum.keycloak.org/t/frontend-and-backendurls-published-in-well-known-openid-configuration/18612/1 "2022-11-25T13:55:56Z")

</div>

I got my Keycloak 20.01 running in quarkus.  
it is running with a LB who is exposing the the root path internally and only the recommended paths externally.  
the LB is terminating the TLS connection and therefore keycloak is set up with proxy= edge and http enabled.  
we set the hostname and hostname-admin as well as hostname-strict-backchannel=true.  
if i call the well-known/openid-configuration the following values (not exhaustive) use the hostname-admin as their baseurl:

token\_endpoint  
introspection\_endpoint  
userinfo\_endpoint  
jwks\_uri  
registration\_endpoint  
backchannel\_authentication\_endpoint  
pushed\_authorization\_request\_endpoint

as the hostname-admin is using our internal naming scheme we would prefer not to publish it this openly.  
How can i configure the keycloak, that it is only using the hostname in the well-known/openid-configuration?
