# Replacement for 'Script Mapper' in Client Mappers

**URL:** <https://forum.keycloak.org/t/replacement-for-script-mapper-in-client-mappers/14559>\
**Category:** Getting advice\
**Created:** [March 24, 2022, 9:18pm UTC](https://forum.keycloak.org/t/replacement-for-script-mapper-in-client-mappers/14559 "2022-03-24T21:18:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [March 24, 2022, 9:18pm UTC](https://forum.keycloak.org/t/replacement-for-script-mapper-in-client-mappers/14559/1 "2022-03-24T21:18:01Z")

</div>

Planning on replacing **Token Client Name** _ **sub** _ with a random value (for privacy reason we can’t use the default **ID** ). Under the old ‘Script Mapper’ option for **Mapper Type** , I could have created a random vialu by script – what could be an option in lieu of ‘Script Mapper’? Thank you.

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/2/21f61777b2500229408dc25a8c5a373f7a78518d.jpeg)

---

<div class="post-metadata">

**Author:** ![mbonn](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/mbonn/32/5755_2.png) [@mbonn](https://forum.keycloak.org/u/mbonn)\
**Post date:** [March 25, 2022, 7:27am UTC](https://forum.keycloak.org/t/replacement-for-script-mapper-in-client-mappers/14559/2 "2022-03-25T07:27:00Z")

</div>

Hallo,

There’s a predefined claim mapper for this: “pairwise subject identifier”. It creates a cryptographic hash based on local user’s ID, client’s redirect URI and a salt, if I understand it correctly.

If that is not sufficient for you, JavaScript mappers can be implemented according to the documentation:  
[https://www.keycloak.org/docs/latest/server\_development/#\_script\_providers](https://www.keycloak.org/docs/latest/server_development/#_script_providers)  
(you have to start KC with ` -Dkeycloak.profile.feature.scripts=enabled`)  
In the script, the sub value can be set with `token.setSubject("my random value")`

As far as I know, setting the sub using a standard user property or attribute mapper will not work.

regards,  
Matthias

---

<div class="post-metadata">

**Author:** ![melancholia](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@melancholia](https://forum.keycloak.org/u/melancholia)\
**Post date:** [March 25, 2022, 4:50pm UTC](https://forum.keycloak.org/t/replacement-for-script-mapper-in-client-mappers/14559/3 "2022-03-25T16:50:09Z")

</div>

So far, populating **Token Client Name** _ **sub** _ with ‘email’ value appears to work.

Thank you for your post and suggestion.

To comply with privacy policies, we would have to create an opaque immutable hash value per user to populate the **Token Client Name** _ **sub** _ value (i.e. the value will be unique to a user per service).
