# Having Authentication Token and Login Credentials, How we can automatically login user or how to generate a login-actions/authenticate url

**URL:** <https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825>\
**Category:** Tips and tricks\
**Tags:** adapter-javascript, oidc\
**Created:** [September 11, 2020, 9:44am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825 "2020-09-11T09:44:52Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![behrooz-tahanzadeh](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/behrooz-tahanzadeh/32/883_2.png) [@behrooz-tahanzadeh](https://forum.keycloak.org/u/behrooz-tahanzadeh)\
**Post date:** [September 11, 2020, 9:44am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/1 "2020-09-11T09:44:52Z")

</div>

In the last step of our custom registration flow, users will gain an authentication token (access\_token and refresh\_token) after entering their new password.  
Having that we can initialize a logged-in instance of Keycloak javascript class. However; this won’t set the sso cookies (KEYCLOAK\_IDENTITY, …).

Is there a solution to set these cookies or can we generate a `login-actions/authenticate` URL and post the user’s credentials in a post request (custom login form)?

---

<div class="post-metadata">

**Author:** ![gitdode](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gitdode/32/1178_2.png) [@gitdode](https://forum.keycloak.org/u/gitdode)\
**Post date:** [September 13, 2020, 10:11pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/2 "2020-09-13T22:11:16Z")

</div>

Did you have a look at this [suggestion](https://stackoverflow.com/a/63154387/709426)? Given an access token, it sets the SSO cookies.

---

<div class="post-metadata">

**Author:** ![behrooz-tahanzadeh](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/behrooz-tahanzadeh/32/883_2.png) [@behrooz-tahanzadeh](https://forum.keycloak.org/u/behrooz-tahanzadeh)\
**Post date:** [September 28, 2020, 10:53am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/4 "2020-09-28T10:53:09Z")

</div>

Thank you for the suggestion  
After some changes to handle the CORS issue, now the _/SSO_ end-point return the expected Cookies; However, they are sent without expiry date which means they are not persistence.

Looking into keycloak implementation of [AuthenticationManager.java (Line 664)](https://github.com/keycloak/keycloak/blob/a9a719b88c67bb8575dca3b980582f9610b12257/services/src/main/java/org/keycloak/services/managers/AuthenticationManager.java#L664) you can see the following code  
_if (session != null && session.isRememberMe()) {_  
_maxAge = realm.getSsoSessionMaxLifespanRememberMe() \> 0 ? realm.getSsoSessionMaxLifespanRememberMe() : realm.getSsoSessionMaxLifespan();_  
_}_  
Did you have same issue? Any suggestion how can I change cookies lifespan?

---

<div class="post-metadata">

**Author:** ![gitdode](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gitdode/32/1178_2.png) [@gitdode](https://forum.keycloak.org/u/gitdode)\
**Post date:** [October 3, 2020, 6:10pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/5 "2020-10-03T18:10:35Z")

</div>

We don’t use “Remember Me” and I currently don’t know how `Session#rememberMe` can be set to `true` besides by the user checking the “Remember me” checkbox on the login page.

In our use case, we set the SSO cookies with an access token obtained through token exchange and direct access grants, and I have no idea if it is possible to set `rememberMe` when a session is created this way and unfortunately I don’t have the chance to try and find out at the moment 🙁  
Of course I’d be interested if you find out something!

---

<div class="post-metadata">

**Author:** ![Tikko](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@Tikko](https://forum.keycloak.org/u/Tikko)\
**Post date:** [October 19, 2020, 8:46pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/6 "2020-10-19T20:46:17Z")

</div>

Could you share how you handle CORS? I run in the same issue and cant figure it out ☹

---

<div class="post-metadata">

**Author:** ![Tikko](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@Tikko](https://forum.keycloak.org/u/Tikko)\
**Post date:** [October 19, 2020, 10:26pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/7 "2020-10-19T22:26:24Z")

</div>

Nevermind, the problem was that no `storageProviders` are found and hence the `user` is always `null`.  
We now just use the following line to obtain the `user`:

```auto
UserModel user = keycloakSession.users().getUserById(token.getSubject(), realm);

```

And this is how we handle Cors using `org.keycloak.services.resources.Cors`:

```auto
    @GET
    @Produces(MediaType.APPLICATION_JSON)
    @Path("/sso")
    public Response sso(@Context final HttpRequest request) {
      // ... stuff to set the cookie ...
      Cors cors = Cors.add(request, Response.noContent()).auth()
                .allowedMethods("GET")
                .allowedOrigins(token)
                .auth().exposedHeaders();
        return cors.build();

```

Also, we needed to add an `@OPTIONS` endpoint:

```auto
    @OPTIONS
    @Path("/sso")
    public Response preflight(@Context final HttpRequest request) {
        return Cors.add(request, Response.ok()).auth().preflight()
                .allowAllOrigins()
                .allowedMethods("GET", "OPTIONS").build();
    }

```

So, now we are also have the issue with the rememberMe / session-dropping on page reload.

---

<div class="post-metadata">

**Author:** ![Tikko](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@Tikko](https://forum.keycloak.org/u/Tikko)\
**Post date:** [October 20, 2020, 7:18am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/8 "2020-10-20T07:18:28Z")

</div>

I tried copying the `AuthenticationManager.createLoginCookie(...)` to set `maxAge` but the cookies are not set anyway ☹ The response header looks fine, but they do not show up in devtools \> Application \> Cookies.

![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/e/e45c9a93ff1a7116871b5b70c4ff766a9aa3d5bc.png)

---

<div class="post-metadata">

**Author:** ![Tikko](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@Tikko](https://forum.keycloak.org/u/Tikko)\
**Post date:** [October 20, 2020, 8:00am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/9 "2020-10-20T08:00:39Z")

</div>

I was missing the `credentials: 'include'` flag for the `fetch` call on the frontend. For me it’s working now (including a persistent session on page refresh and without hacking a `maxAge` for the cookies).

---

<div class="post-metadata">

**Author:** ![behrooz-tahanzadeh](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/behrooz-tahanzadeh/32/883_2.png) [@behrooz-tahanzadeh](https://forum.keycloak.org/u/behrooz-tahanzadeh)\
**Post date:** [November 11, 2020, 11:01pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/10 "2020-11-11T23:01:58Z")

</div>

Thank you Tikko for the suggestion, It works!  
Regarding CORS I tried to implement your approach however I’m missing the module dependencies. Here’s my current module addition command.

```
module add ... --dependencies=org.keycloak.keycloak-core,org.keycloak.keycloak-server-spi,org.keycloak.keycloak-server-spi-private,javax.ws.rs.api,org.keycloak.keycloak-services

```

I believe the missing one is for `import org.jboss.resteasy.spi.HttpRequest;` library.  
Thank you in advance for any hint…

---

<div class="post-metadata">

**Author:** ![behrooz-tahanzadeh](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/behrooz-tahanzadeh/32/883_2.png) [@behrooz-tahanzadeh](https://forum.keycloak.org/u/behrooz-tahanzadeh)\
**Post date:** [November 12, 2020, 10:01am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/11 "2020-11-12T10:01:23Z")

</div>

`org.jboss.resteasy.resteasy-jaxrs` was the missing dependency. 🙂

---

<div class="post-metadata">

**Author:** ![vdeygas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/vdeygas/32/1257_2.png) [@vdeygas](https://forum.keycloak.org/u/vdeygas)\
**Post date:** [December 8, 2020, 9:41am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/12 "2020-12-08T09:41:59Z")

</div>

Hi all,

Thanks for your solution. It works ! I use it to establish a session in a embedded browser (javafx) using access token previously obtained by keycloak desktop adapter and authorization grant flow.

But, is there any security issues implied by this implementation ?

---

<div class="post-metadata">

**Author:** ![solonik](https://avatars.discourse-cdn.com/v4/letter/s/22d042/32.png) [@solonik](https://forum.keycloak.org/u/solonik)\
**Post date:** [April 25, 2021, 10:37pm UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/13 "2021-04-25T22:37:25Z")

</div>

@gitdode Thank you for your answer 🙂 I try to set up your solution. But when I try to insert the resteasy dependency, I get the following error:

ERROR [org.keycloak.services.error.KeycloakErrorHandler] (default task-1) Uncaught server error: java.lang.NoClassDefFoundError: org / keycloak / common / util / Resteasy.

This is my dependency list:

 ![Bildschirmfoto 2021-04-26 um 00.26.24](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/b/b20ecca55794494386d41126b2290b59b7df0df7.png)

I tried to import the module using the following command:

module add … --dependencies=org.keycloak.keycloak-core,org.keycloak.keycloak-server-spi,org.keycloak.keycloak-server-spi-private,javax.ws.rs.api,org.keycloak.keycloak-services,org.jboss.resteasy.resteasy-jaxrs

Unfortunately my SPI is not displayed in the admin. But if I add my .jar in jboss/keycloak/standalone/deployments, then I see my SPI in the admin. But with the error mentioned above.

I am new to the Java/Keycloak world. I am happy for any help.

---

<div class="post-metadata">

**Author:** ![gitdode](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/gitdode/32/1178_2.png) [@gitdode](https://forum.keycloak.org/u/gitdode)\
**Post date:** [April 26, 2021, 11:46am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/14 "2021-04-26T11:46:58Z")

</div>

@solonik here’s the depencies that I have in my project (besides some specific stuff, test dependencies and so on), hope it is of any help:

```
    <depencencies>
    <!-- JEE dependencies -->
    <dependency>
        <groupId>javax</groupId>
        <artifactId>javaee-api</artifactId>
        <version>7.0</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.jboss.ejb3</groupId>
        <artifactId>jboss-ejb3-ext-api</artifactId>
        <version>2.2.0.Final</version>
        <scope>provided</scope>
    </dependency>

    <dependency>
        <groupId>org.slf4j</groupId>
        <artifactId>slf4j-api</artifactId>
        <version>1.7.7</version>
        <scope>provided</scope>
    </dependency>

    <!-- Keycloak dependencies -->
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-core</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-common</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-model-infinispan</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-server-spi</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-server-spi-private</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
    <dependency>
        <groupId>org.keycloak</groupId>
        <artifactId>keycloak-services</artifactId>
        <version>${version.keycloak}</version>
        <scope>provided</scope>
    </dependency>
</dependencies>
```

---

<div class="post-metadata">

**Author:** ![pnvskp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/pnvskp/32/5838_2.png) [@pnvskp](https://forum.keycloak.org/u/pnvskp)\
**Post date:** [May 17, 2022, 10:44am UTC](https://forum.keycloak.org/t/having-authentication-token-and-login-credentials-how-we-can-automatically-login-user-or-how-to-generate-a-login-actions-authenticate-url/4825/15 "2022-05-17T10:44:33Z")

</div>

Is there a way to proceed with the steps mentioned in the link using keycloak-js?
