Skip to content

API access under a third-party client keycloak #4138

Answered by carlesarnal
mikhail-0330 asked this question in Q&A
Discussion options

You must be logged in to vote

If you do not set up any roles restriction at the client level yes, any other client within the same realm will be able to access the Apicurio Registry API, that's the whole point of the client credentials grant and having separate clients for each application, so you can identify which application is doing what. The KEYCLOAK_API_CLIENT_ID is just the identifier for the Registry application itself against keycloak.

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by carlesarnal
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
type/bug Something isn't working area/auth
3 participants
Converted from issue

This discussion was converted from issue #3677 on December 18, 2023 09:08.