# Is Keycloak right solution for my usecase

**URL:** <https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055>\
**Category:** Getting advice\
**Created:** [June 1, 2020, 7:16am UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055 "2020-06-01T07:16:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![brijchavda](https://avatars.discourse-cdn.com/v4/letter/b/74df32/32.png) [@brijchavda](https://forum.keycloak.org/u/brijchavda)\
**Post date:** [June 1, 2020, 7:16am UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/1 "2020-06-01T07:16:07Z")

</div>

My Usecase is.

I have this saas solution. Lets say

**[web.foo.com](http://web.foo.com)**

Users of this solution should be able to login using Github, Gitlab and few other Identity providers.

Each user logged in belongs to a particular tenant. and it has its own way to access the product.

for e.g

**[tenant.foo.com](http://tenant.foo.com)**

When user logs in to web .foo.com and then goes to tenant .foo.com , it should automatically be logged in.

tenant .foo.com is also oauth enabled, which means, it needs to have the same access token , returned by github or gitlab, which user has used to login.

Can this be achieved using keycloak.

Thanks a lot in advance.

---

<div class="post-metadata">

**Author:** ![trotman23](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/trotman23/32/821_2.png) [@trotman23](https://forum.keycloak.org/u/trotman23)\
**Post date:** [June 1, 2020, 4:49pm UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/2 "2020-06-01T16:49:19Z")

</div>

You can configure Keycloak to store external IDP tokens, and then your tenant applications can retrieve them after a login:  
[https://www.keycloak.org/docs/latest/server\_admin/index.html#retrieving-external-idp-tokens](https://www.keycloak.org/docs/latest/server_admin/index.html#retrieving-external-idp-tokens)

---

<div class="post-metadata">

**Author:** ![polfilm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/polfilm/32/1047_2.png) [@polfilm](https://forum.keycloak.org/u/polfilm)\
**Post date:** [June 23, 2020, 6:47pm UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/3 "2020-06-23T18:47:37Z")

</div>

@trotman23 I’m having issues retrieving external idp tokens. Is there any way we could confirm steps? I have described them here.

> [@Unable to retrieve (upstream) Identity Provider's original token](http://forum.keycloak.org/t/unable-to-retrieve-upstream-identity-providers-original-token/2267/2):
>
> I am having exactly the same issue. Cannot solve it. I’m attempting to do this with Discord (beta) provider. Everything works except brokering. Not sure if this is related to unimplemented features. However judging by what @FireDrunk is saying, this is exactly same thing. Link to original post is here: [https://github.com/wadahiro/keycloak-discord/issues/6](https://github.com/wadahiro/keycloak-discord/issues/6) (provider itself is working great, i have been using it for few months now) Problem Restated Below: I’m having issues retrieving stored toke…

---

<div class="post-metadata">

**Author:** ![trotman23](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/trotman23/32/821_2.png) [@trotman23](https://forum.keycloak.org/u/trotman23)\
**Post date:** [June 24, 2020, 10:50pm UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/4 "2020-06-24T22:50:33Z")

</div>

Sure I’ll attempt to describe my setup and the steps I took from the documentation.

1. IDP

- “Store Tokens” enabled
- “Stored Tokens Readable” enabled (only matters for new users so could skip 4)

1. broker client

- create a client role named `read-token`

1. other client (can be any OIDC client that gets an access token)

- make sure there is a mapper for “client roles”. By default, this is part of the client scope called “roles”. If you don’t have that client scope assigned to this client, you can create a mapper with this configuration:  
 ![Screen Shot 2020-06-24 at 5.41.49 PM](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/3/385a4be42d02b665557e7f3230afa29704708257.png)

1. User (can skip if user was imported after “Stored Tokens Readable” was enabled

- Assign the broker `read-token` role to your user  
 ![Screen Shot 2020-06-24 at 5.46.58 PM](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/c/cc090d9ac7d5ce0473d61c767b276f384dfa908e.png)

1. Complete a login and get the access token. Send a request to `/auth/realms/{realm}/broker/{provider_alias}/token` with the authorization header set to `Bearer ${token}` as described in [the docs](https://github.com/keycloak/keycloak-documentation/blob/master/server_development/topics/identity-brokering/tokens.adoc)

Your token should contain client roles for the `broker` client in the `resource_access` claim:

```auto
"resource_access": {
    "broker": {
      "roles": [
        "read-token"
      ]
    }
}

```

FWIW, i’m on keycloak 9.0.3, but have performed these steps on previous versions as well with no issues.

---

<div class="post-metadata">

**Author:** ![polfilm](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/polfilm/32/1047_2.png) [@polfilm](https://forum.keycloak.org/u/polfilm)\
**Post date:** [June 25, 2020, 2:43am UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/5 "2020-06-25T02:43:49Z")

</div>

Dear @trotman23

I am very grateful for your hint. Your words from point #3 should really make it into Keycloak documentation.

I first tried the mapper and it worked, then I dropped the mapper and simply added “roles” from list to Assigned Default Client Scopes in my OIDC client.

 ![Screenshot 2020-06-25 at 03.34.11](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/b/bc97edb0ee123a9a72cd8f74e26b5d414214b4e6.png)

Many many thanks.  
Peter

---

<div class="post-metadata">

**Author:** ![enima](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enima/32/2062_2.png) [@enima](https://forum.keycloak.org/u/enima)\
**Post date:** [January 21, 2021, 8:54am UTC](https://forum.keycloak.org/t/is-keycloak-right-solution-for-my-usecase/3055/7 "2021-01-21T08:54:05Z")

</div>

> [@trotman23](#):
>
> Complete a login and get the access token

how Keycloak can request token with authorization code received from external Identity provider?
