# User Registration and Login from Native Flutter screens

**URL:** <https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249>\
**Category:** Getting advice\
**Tags:** authentication, oidc\
**Created:** [December 17, 2024, 8:38am UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249 "2024-12-17T08:38:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmharish](https://avatars.discourse-cdn.com/v4/letter/k/91b2a8/32.png) [@kmharish](https://forum.keycloak.org/u/kmharish)\
**Post date:** [December 17, 2024, 8:38am UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/1 "2024-12-17T08:38:14Z")

</div>

I have a Mobile app build with Flutter for both Android and iOS which currently uses standard Oauth2 Registration Flow and Authorisation code grant flow for login by redirecting users to a browser webview for Keycloak UI screens  
Mobile app team now wants to use native Flutter screens for User registration and Login,

Are there ways to expose Rest API from keycloak other that the Keycloaks Admin API (Exposing this API is not and option) for User Registration and Login(other than Password/Direct Grant flow)

Without enabling Admin API and Direct Grant Flow is there any way to expose REST API for my mobile app for these 2 flows. May be a Custom Resource Provider endpoint for User Registration and Login, Please advice.

I understand that we are butchering the standard OIDC Oauth2 flow, but this is our requirement and I am tasked to solution this.

Any help would be helpful.

---

<div class="post-metadata">

**Author:** ![bpedersen2](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/bpedersen2/32/3934_2.png) [@bpedersen2](https://forum.keycloak.org/u/bpedersen2)\
**Post date:** [December 17, 2024, 12:29pm UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/2 "2024-12-17T12:29:47Z")

</div>

Short answer: No.

The only valid (but not recommended option) would be the direct grant flow.

The main idea behind OIDC authentication is, that the app never even gets to see the user credentials, so what you want to do would actually circumvent this.

---

<div class="post-metadata">

**Author:** ![mbonn](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/mbonn/32/5755_2.png) [@mbonn](https://forum.keycloak.org/u/mbonn)\
**Post date:** [December 17, 2024, 1:36pm UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/3 "2024-12-17T13:36:50Z")

</div>

Strictly speaking, not even embedded web views should be used, but always the operating system’s standard browser. Nothing else.

---

<div class="post-metadata">

**Author:** ![kmharish](https://avatars.discourse-cdn.com/v4/letter/k/91b2a8/32.png) [@kmharish](https://forum.keycloak.org/u/kmharish)\
**Post date:** [December 23, 2024, 6:13pm UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/4 "2024-12-23T18:13:23Z")

</div>

@bpedersen2 Thanks for your response, Do you know if we can impliment Email OTP for direct grant flow?

---

<div class="post-metadata">

**Author:** ![kmharish](https://avatars.discourse-cdn.com/v4/letter/k/91b2a8/32.png) [@kmharish](https://forum.keycloak.org/u/kmharish)\
**Post date:** [December 23, 2024, 6:13pm UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/5 "2024-12-23T18:13:46Z")

</div>

@mbonn Thanks for your response, I will recomond the mobile team to use the OS’s default browser.

---

<div class="post-metadata">

**Author:** ![tristan](https://avatars.discourse-cdn.com/v4/letter/t/96bed5/32.png) [@tristan](https://forum.keycloak.org/u/tristan)\
**Post date:** [February 24, 2025, 9:55am UTC](https://forum.keycloak.org/t/user-registration-and-login-from-native-flutter-screens/29249/6 "2025-02-24T09:55:49Z")

</div>

Maybe this new specification could answer to your case but I thinks is not yet implemented within Keycloak and it’s still draft.

[draft-ietf-oauth-first-party-apps-00](https://datatracker.ietf.org/doc/html/draft-ietf-oauth-first-party-apps)

Regards
