# How is logout really working and can we bypass the logout-confirm page?

**URL:** <https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314>\
**Category:** Tips and tricks\
**Tags:** oidc\
**Created:** [May 2, 2022, 9:56pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314 "2022-05-02T21:56:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![edwint88](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/edwint88/32/1103_2.png) [@edwint88](https://forum.keycloak.org/u/edwint88)\
**Post date:** [May 2, 2022, 9:56pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/1 "2022-05-02T21:56:51Z")

</div>

I’m trying to get a grasp on how to logout from a java adapter. Currently what I do is to call the endpoint [https://localhost:8444/realms/test/protocol/openid-connect/logout](https://localhost:8444/realms/test/protocol/openid-connect/logout) and then I get a logout confirmation page.  
First question: **how can I bypass that? to not be shown and go directly to the logout page?**  
In my setup I have a client with minimal setup, that all the information are loaded in the application from the well-known endpoint (so no java deployment and I will want to not change that).

— Next part is more fore understanding purpose & hopefully to clarify some stuff for others too—  
Secondly when it comes to the documentation I didn’t find very good examples of how to do the frontend logout or backend logout? (I suppose the backend logout makes sense when you write the Java adapter and call the Keycloak class with the logout function. Right?)  
And frontend logout is something that you probably have in a React/Angular application as js adapter?

So if that is the case, none of this solutions will fit my use case to just use the openid-connect and not extend the application, right?

---

<div class="post-metadata">

**Author:** ![thomasdarimont](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/thomasdarimont/32/37_2.png) [@thomasdarimont](https://forum.keycloak.org/u/thomasdarimont)\
**Post date:** [May 17, 2022, 2:02pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/2 "2022-05-17T14:02:24Z")

</div>

Hello,

Keycloak recently changed the logout behavior as documented in [this blog post on Keycloak 18.0.0](https://www.keycloak.org/2022/04/keycloak-1800-released).

You now have to provide additonal URL parameters when you invoke the endsession endpoint:  
[https://www.keycloak.org/docs/latest/server\_admin/#\_oidc-logout](https://www.keycloak.org/docs/latest/server_admin/#_oidc-logout)

- `id_token_hint` = idtoken received by your client
- `post_logout_redirect_uri` = url where you want to go after logout

For example in some SPAs that use keycloak.js I provide the required URL parameters as follows:

```auto
        // workaround for changes with oidc logout in Keycloak 18.0.0
        // See https://www.keycloak.org/docs/latest/upgrading/index.html#openid-connect-logout
        keycloak.createLogoutUrl = function(options) {
            return keycloak.endpoints.logout()
                + '?id_token_hint=' + keycloak.idToken
                + '&post_logout_redirect_uri=' + encodeURIComponent(window.location.href);
        }

```

Cheers,  
Thomas

---

<div class="post-metadata">

**Author:** ![edwint88](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/edwint88/32/1103_2.png) [@edwint88](https://forum.keycloak.org/u/edwint88)\
**Post date:** [May 18, 2022, 9:51am UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/3 "2022-05-18T09:51:07Z")

</div>

Thank you for the response. I’ve seen that, but in our case I’m not sure that it will work. We are using Pega and there you have just a configuration where you can put an URL, so the extra data like `id_token_hint` we cannot dynamically calculate (I think …or is there a way?).

---

<div class="post-metadata">

**Author:** ![Nandika](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/nandika/32/3113_2.png) [@Nandika](https://forum.keycloak.org/u/Nandika)\
**Post date:** [June 22, 2022, 12:13pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/4 "2022-06-22T12:13:33Z")

</div>

You have to obtain a token first, but in token request, set “scope” parameter as “openid”.

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/2/23ae21bcfbc17691c5cff11d9fe2a9c5c18b7eae.png)

The token format will be  
{  
“access\_token”: “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx”,  
“expires\_in”: 600,  
“refresh\_expires\_in”: 0,  
“token\_type”: “Bearer”,  
“id\_token”: “xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx”,  
“not-before-policy”: 1597246820,  
“scope”: “openid”  
}

Use “id\_token” as “id\_token-hint” in your logout url parameter.

---

<div class="post-metadata">

**Author:** ![anbraten](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/anbraten/32/7072_2.png) [@anbraten](https://forum.keycloak.org/u/anbraten)\
**Post date:** [November 22, 2022, 7:01pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/5 "2022-11-22T19:01:08Z")

</div>

I got a nice hint from this page: [keycloak-documentation/logout.adoc at main · keycloak/keycloak-documentation · GitHub](https://github.com/keycloak/keycloak-documentation/blob/main/securing_apps/topics/oidc/java/logout.adoc). Instead of using the `id_token_hint` and directly getting redirected to the url from `post_logout_redirect_uri`. You can also set `client_id`. In this case the user has to press the Logout button on the Keycloak page, but you can skip all of that token passing.

---

<div class="post-metadata">

**Author:** ![german-st](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/german-st/32/8460_2.png) [@german-st](https://forum.keycloak.org/u/german-st)\
**Post date:** [May 3, 2023, 1:21pm UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/6 "2023-05-03T13:21:23Z")

</div>

Hello.

We use the version 18.0.2.  
Trying to logout by opening the address (from our NextJS app by router): **[https://ourkeycloak/realms/myrealm/protocol/openid-connect/logout?id\_token\_hint=eyJhbG&post\_logout\_redirect\_uri==http%3A%2F%2F127.0.0.1%3A3000%2Flogin%2F](https://ourkeycloak/realms/myrealm/protocol/openid-connect/logout?id_token_hint=eyJhbG&post_logout_redirect_uri==http%3A%2F%2F127.0.0.1%3A3000%2Flogin%2F)**

Redirect URI also listed  
(the address is unimportant, even if the localhost is any other specified in the list of redirects, the error will be the same)

We get an error: Invalid redirect uri

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/d/dc6665625c6c383b2cb7ad02dd3a3e906732ac62.png)

Can you please tell me, maybe there are some parameters or settings missing?  
Thank you in advance

P.S  
we have the id\_token in the client. therefore we know it and transmit it correctly

---

<div class="post-metadata">

**Author:** ![ffroliva](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/ffroliva/32/10441_2.png) [@ffroliva](https://forum.keycloak.org/u/ffroliva)\
**Post date:** [May 17, 2024, 10:19am UTC](https://forum.keycloak.org/t/how-is-logout-really-working-and-can-we-bypass-the-logout-confirm-page/15314/7 "2024-05-17T10:19:16Z")

</div>

In case you are working with Spring boot, here is a snipet that does exactly that:

```java
@Configuration
@EnableWebSecurity
@EnableMethodSecurity
public class KeycloakWebSecurityConfig {

    @Bean
    public SecurityFilterChain filterChain(
            HttpSecurity http,
            ClientRegistrationRepository clientRegistrationRepository) throws Exception {
        http.authorizeHttpRequests(authorize -> authorize.anyRequest().authenticated());

        http.logout(logout -> logout.logoutSuccessHandler(oidcLogoutSuccessHandler()));
        return http.build();
    }

    private LogoutSuccessHandler oidcLogoutSuccessHandler(ClientRegistrationRepository clientRegistrationRepository) {
        OidcClientInitiatedLogoutSuccessHandler oidcLogoutSuccessHandler =
                new OidcClientInitiatedLogoutSuccessHandler(clientRegistrationRepository);
        // Sets the location that the End-User's User Agent will be redirected to
        // after the logout has been performed at the Provider
        oidcLogoutSuccessHandler.setPostLogoutRedirectUri("{baseUrl}");

        return oidcLogoutSuccessHandler;
    }

}

```
