1.0 KiB
1.0 KiB
Creating Client
-
Download the client config file here{target=_blank}
-
Open Keycloak Admin Console
-
Go to Clients tab. Create new client
-
On Client Creation page, import the downloaded config.
Configuration
The Client will be created with default url http://localhost:5000/login for Valid Redirect URIs, Base URL, and Web Origins
Update this to your actual domain url e.g https://aws.example.com/login
AWS Config
-
Go to AWS IAM Console and add an Identity Provider
-
Use following configuration
- Provider Type: OpenID Connect
- Provider URL: OIDC Provider URL, must be a internet accessible TLS secured enpoint (e.g
https://auth.example.com/realms/masterfor Keycloak) - Audience: Client ID issued by OIDC Provider (e.g
aws-oidcKeycloak Client )
!!! info
Ensure you add Provider URL without any Trailing slash `/` -
Get Thumbprint once
Provider URLis set. and ClickAdd provider
