# Using Keycloak with 1EdTech

**URL:** <https://forum.keycloak.org/t/using-keycloak-with-1edtech/27831>\
**Category:** Getting advice\
**Created:** [September 11, 2024, 6:38pm UTC](https://forum.keycloak.org/t/using-keycloak-with-1edtech/27831 "2024-09-11T18:38:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![fsjovatsen](https://avatars.discourse-cdn.com/v4/letter/f/eb9ed0/32.png) [@fsjovatsen](https://forum.keycloak.org/u/fsjovatsen)\
**Post date:** [September 11, 2024, 6:38pm UTC](https://forum.keycloak.org/t/using-keycloak-with-1edtech/27831/1 "2024-09-11T18:38:00Z")

</div>

Hi,

we’re using Keycloak to secure our api’s. The api’s is an implementation of the [OneRoster 1.2 Standard](https://www.imsglobal.org/spec/oneroster/v1p2) from 1EdTech. This standard requires client credentials flow and the security specs is taken from their [1EdTech Security Framework](https://www.imsglobal.org/spec/security/v1p1/#using-oauth-2-0-client-credentials-grant).

We’re now in the certification process and we’re failing on two issues regarding the token issuing.

RFC6749 says:

“If the client omits the scope parameter when requesting  
authorization, the authorization server MUST either process the  
request using a pre-defined default value or fail the request  
indicating an invalid scope.”

Keycloak, out of the box, processes the request and returns a token. 1EdTech requires the second option. Fail the request indicating an invalid scope. Is there a way to change this behavior in KeyCloak so that if you request a token and don’t provide any scopes the request will fail?

The second issue is that if you send in several scopes and some/one of the is not valid, 1EdTech want’s the IDP to process the request and return a token with the valid scopes and ignore the not valid scopes. Is there a way to do this in KeyCloak?

Regs,  
Frode Sjovatsen
