# Using client secret to signing tokens instead of realm keys

**URL:** <https://forum.keycloak.org/t/using-client-secret-to-signing-tokens-instead-of-realm-keys/16266>\
**Category:** Getting advice\
**Tags:** authentication, oidc\
**Created:** [July 1, 2022, 2:32pm UTC](https://forum.keycloak.org/t/using-client-secret-to-signing-tokens-instead-of-realm-keys/16266 "2022-07-01T14:32:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![manaaa](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@manaaa](https://forum.keycloak.org/u/manaaa)\
**Post date:** [July 1, 2022, 2:32pm UTC](https://forum.keycloak.org/t/using-client-secret-to-signing-tokens-instead-of-realm-keys/16266/1 "2022-07-01T14:32:49Z")

</div>

Hello together,

I already want to thank you for your advices and hints.  
Currently I am trying to fetch a token from the token endpoint of keycloak with a java app using pac4j and nimbus.

The app is configured with HS256 as preferred signature algorithm.  
I configured keycloak with a client id and a secret and also entered both into the configuration of pac4j.

When I try to authenticate with keycloak I receive the following error message:  
_Signed JWT rejected: Another algorithm expected, or no matching key(s) found_  
The reason for that is, that the kid and the client secret (which is used by nimbus) do not match.

So there are basically 2 approaches which I have tried.

1. I tried to add a 2nd secret to pac4j which fits the kid defined in the realm keys for hmac-generated  

2. I tried to change the kid which is sent by keycloak to the client secret.

Unfortunately I have not managed to force keycloak to use the client secret instead of the generated kid.

Is there are any chance or another approach how I can connect these two applications?

Again thank you very much and best regards,  
Timo

---

<div class="post-metadata">

**Author:** ![weltonrodrigo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/weltonrodrigo/32/3104_2.png) [@weltonrodrigo](https://forum.keycloak.org/u/weltonrodrigo)\
**Post date:** [July 1, 2022, 3:12pm UTC](https://forum.keycloak.org/t/using-client-secret-to-signing-tokens-instead-of-realm-keys/16266/2 "2022-07-01T15:12:19Z")

</div>

Not sure why Nimbus would be using client secret as key to validate the JWT Token.

I used Pac4J a little and it could do the jwt validation ok, but I was using it as an OIDC client, so not sure how to configure it in your use case.

I suppose you can download the keys yourself from the `jwks_uri` endpoint. For keycloak, that would be:

`<KEYCLOAK_BASE_URL>/realms/<REALM_NAME>/protocol/openid-connect/certs`

See item 4 of this doc: [pac4j: security for Java](https://www.pac4j.org/docs/authenticators/jwt.html) on how to use a JWK endpoint for key validation.

---

<div class="post-metadata">

**Author:** ![manaaa](https://avatars.discourse-cdn.com/v4/letter/m/43a26b/32.png) [@manaaa](https://forum.keycloak.org/u/manaaa)\
**Post date:** [July 1, 2022, 3:19pm UTC](https://forum.keycloak.org/t/using-client-secret-to-signing-tokens-instead-of-realm-keys/16266/3 "2022-07-01T15:19:38Z")

</div>

Thank you very much.  
I think this is a good hint. To be honest I do also not know why it is taking the secret instead of going to such an endpoint.  
But this is a good approach.

Basically I also just want to use it as an OIDC client. But it turns out it’s not working out of the box for me with such weird issues.

Thanks again

Edit: In pac4j there is a class TokenValidator() which sets up an IDTokenValidator with the oidc configuration, the jws algo, cliend id and secret (Tokenvalidator.java, Line 74)  
I guess I should not use this one.
