# How to create a new Group with realmRoles mapping

**URL:** <https://forum.keycloak.org/t/how-to-create-a-new-group-with-realmroles-mapping/27560>\
**Category:** Configuring the server\
**Created:** [August 23, 2024, 9:51am UTC](https://forum.keycloak.org/t/how-to-create-a-new-group-with-realmroles-mapping/27560 "2024-08-23T09:51:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![w1ll-i-code](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/w1ll-i-code/32/11122_2.png) [@w1ll-i-code](https://forum.keycloak.org/u/w1ll-i-code)\
**Post date:** [August 23, 2024, 9:51am UTC](https://forum.keycloak.org/t/how-to-create-a-new-group-with-realmroles-mapping/27560/1 "2024-08-23T09:51:52Z")

</div>

Hi y’all.

I’m currently trying to automatize the creation of some Groups in [over the REST-API](https://www.keycloak.org/docs-api/25.0.2/rest-api/index.html#_post_adminrealmsrealmgroups). The documentation explicitly links to the [GroupRepresentation](https://www.keycloak.org/docs-api/25.0.2/rest-api/index.html#GroupRepresentation), that allows for the specification of the `realmRoles` for the group. This is exactly the feature I need, however when I make the call, the Group is created, as expected, but without the mapping.

The payload for the call is as follows:

```json
{
    "name": "administrators",
    "attributes": {
        "created_by": "automatic-install"
    },
    "realmRoles": ["admin"]
}

```

Is there something I’m missing? Keycloak doesn’t return no error, it seems to just ignore the parameter entirely. I can’t even find a mention of the realmRoles in the trace logs.

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [August 23, 2024, 4:16pm UTC](https://forum.keycloak.org/t/how-to-create-a-new-group-with-realmroles-mapping/27560/2 "2024-08-23T16:16:42Z")

</div>

Looking in the code (`GroupsResource.addTopLevelGroup` and `GroupResource.updateGroup`), it appears that it ignores everything but the name, id, and attributes.

---

<div class="post-metadata">

**Author:** ![w1ll-i-code](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/w1ll-i-code/32/11122_2.png) [@w1ll-i-code](https://forum.keycloak.org/u/w1ll-i-code)\
**Post date:** [August 26, 2024, 7:18am UTC](https://forum.keycloak.org/t/how-to-create-a-new-group-with-realmroles-mapping/27560/3 "2024-08-26T07:18:55Z")

</div>

I have solved it by using the [Client Role Mapping API](https://www.keycloak.org/docs-api/25.0.2/rest-api/index.html#_client_role_mappings).
