# Logging out with OIDC, post\_redirect\_uri and client\_id

**URL:** <https://forum.keycloak.org/t/logging-out-with-oidc-post-redirect-uri-and-client-id/19343>\
**Category:** Configuring the server\
**Created:** [December 30, 2022, 12:48pm UTC](https://forum.keycloak.org/t/logging-out-with-oidc-post-redirect-uri-and-client-id/19343 "2022-12-30T12:48:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nkodenko](https://avatars.discourse-cdn.com/v4/letter/n/7ea924/32.png) [@nkodenko](https://forum.keycloak.org/u/nkodenko)\
**Post date:** [December 30, 2022, 12:48pm UTC](https://forum.keycloak.org/t/logging-out-with-oidc-post-redirect-uri-and-client-id/19343/1 "2022-12-30T12:48:00Z")

</div>

Hi everyone,

I have KeyCloak operating as an identity provider for my web-based application via OIDC. Currently I’m struggling with configuring the loging out from the system. Here is my scenario:

1. User clicks “Log out” button in the browser
2. Ther browser opens [https://keycloak.example.com//realms/myrealm/protocol/openid-connect/logout?post\_logout\_redirect\_uri=https://myapp.example.com&client\_id=myclient](https://keycloak.example.com//realms/myrealm/protocol/openid-connect/logout?post_logout_redirect_uri=https://myapp.example.com&client_id=myclient)
3. User is redirected to the main page of my app after successful logout

Currently, when a user clicks “Log Out”, the keycloak logout page opens and then user is redirected to the main page without any confirmation. The lack of confirmation is undesired, however it’s not the critical issue. The real problem is that user session doesn’t disappear in the keycloak administration console (myrealm → users → myuser → sessions).

It’s also seems strange to me that if a user open keycloak logout page without parameters (i.e. without post\_logout\_redirect\_uri and client\_id) then there is a confirmation form and the user session is destroyed after user logs out.

---

<div class="post-metadata">

**Author:** ![regilero](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/regilero/32/5411_2.png) [@regilero](https://forum.keycloak.org/u/regilero)\
**Post date:** [January 4, 2023, 11:08am UTC](https://forum.keycloak.org/t/logging-out-with-oidc-post-redirect-uri-and-client-id/19343/2 "2023-01-04T11:08:55Z")

</div>

logout has changed after version 18.

It should now include `id_token_hint`, with the access\_token to avoid the confirmation screen and to really log out the user. `id_token_hint=(...)&post_logout_redirect_uri=(...)`.  
Try first with this and see itf the session gets destroyed. Your problem is quite strange, let’s hope it’s just because you lack this hint (but the official should be to show the confirmation screen if something is missing…).

Then, in a second time, for always showing the confirmation logout you can read and track this proposition, with a client having a ‘confirm’ mode enabled but only in logout screen (else it will also be on login).

> **[Use only id\_token\_hint to check if logout confirmation screen should be...](https://github.com/keycloak/keycloak/discussions/12183)**
>
> With the changes in Keycloak 18 around the support of RP-Initiated Logout, we introduced the "Logout confirmation screen", which can be displayed to the user. The logout confirmation screen is curr...

---

<div class="post-metadata">

**Author:** ![liamdiprose](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/liamdiprose/32/9932_2.png) [@liamdiprose](https://forum.keycloak.org/u/liamdiprose)\
**Post date:** [March 5, 2024, 4:34am UTC](https://forum.keycloak.org/t/logging-out-with-oidc-post-redirect-uri-and-client-id/19343/3 "2024-03-05T04:34:08Z")

</div>

After struggling with this too, I wanted to leave this StackOverflow answer that solved my problem:

> <https://stackoverflow.com/questions/46689034/logout-user-via-keycloak-rest-api-doesnt-work/46769801#46769801>
