Skip to main content

Introduction

Keycloak is an open-source identity provider that supports OpenID Connect. TIB connects to Keycloak using SocialProvider with the openid-connect provider type. Before configuring your IdP and TIB profile, read Dashboard SSO or Portal SSO to understand the ActionType, ReturnURL, and IdentityHandlerConfig fields required for your use case. This page covers the Keycloak-specific configuration only.

Configure Keycloak

  1. In your Keycloak Admin Console, navigate to the realm you want to use and select Clients. Create Client
  2. Click Create client, set the Client type to OpenID Connect, enter a Client ID, and click Next. Set Client Type and ID
  3. Enable Client authentication and click Next, then Save. Enable Client Auth
  4. From the client’s Credentials tab, copy the Client Secret. Retrieve Client Secret
  5. From the client’s Settings tab, add the TIB callback URL to Valid redirect URIs:
    Replace {tib-host} with the hostname of your TIB instance and {profile-id} with the ID you will assign to the TIB profile.
  6. Click Save.
The Keycloak OIDC discovery URL for your realm is accessible from Realm Settings > General > OpenID Endpoint Configuration:
Keycloak discovery endpoint

TIB Profile

The Keycloak-specific configuration goes in the ProviderConfig block of the TIB profile. Set ProviderName to SocialProvider and Type to redirect.
The Keycloak-specific ProviderConfig fields are:

JSON Web Encryption (JWE)

If Keycloak is configured to encrypt ID tokens, TIB can decrypt them using JWE. Add a JWE block to ProviderConfig to enable this:
For embedded TIB in Tyk Dashboard, set PrivateKeyLocation to the certificate ID from the Tyk Dashboard certificate manager. For standalone TIB, set it to the file path of a PEM file containing the private key. The key must correspond to the public key registered with Keycloak for token encryption. Requires Tyk Identity Broker v1.6.1+ and Tyk Dashboard v5.7.0+.

Worked Examples

These examples use embedded TIB, so the CallbackBaseURL is the same as the Dashboard or Portal respectively; TIB handles requests on the same host and port.
In this example, Tyk Dashboard is running at http://dashboard.example.com on port 3000; replace the example values with your own.Tyk Dashboard configuration
With this configuration, registered users (with a Tyk Dashboard user account) get their own permissions; unregistered users fall back to the group specified in sso_default_group_id. See Dashboard SSO for full details.TIB profileThe TIB profile is created via the Tyk Identity Broker API or the Tyk Dashboard UI.
  • set Key to the Keycloak Client ID
  • set Secret to the Keycloak Client Secret
  • set DashboardCredential to the TIB service account’s Dashboard credentials
Keycloak redirect URIEnsure the following URL is listed in Valid redirect URIs in your Keycloak client settings. The ID in the registered URL must exactly match the ID in your TIB profile; a mismatch will result in a 400 Bad Request error:
Login URLThis URL initiates the SSO login flow:
In production, present this as a “Log in with Keycloak” button or link on a custom login page, rather than expecting users to navigate to it directly.See Dashboard SSO for details on session behavior, permissions, and user group mapping.