# adminAuth config for OpenID based Authentication on Keycloak

**URL:** <https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442>\
**Category:** General\
**Created:** [20 January 2021 13:44 UTC](https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442 "2021-01-20T13:44:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![strmar](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@strmar](https://discourse.nodered.org/u/strmar)\
**Post date:** [20 January 2021 13:44 UTC](https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442/1 "2021-01-20T13:44:39Z")

</div>

Hello to all,

Would like to secure Node-Red using Keycloak.  
I followed the post "Help with adminAuth config for OpenID based authentication" in this forum.

However, get the following error message after logging into my Keycloak server:

> Blockquote  
> InternalOAuthError: Failed to obtain access token  
> at Strategy.OAuth2Strategy.\_createOAuthError (/usr/src/node-red/node\_modules/passport-oauth2/lib/strategy.js:408:17)  
> at /usr/src/node-red/node\_modules/passport-oauth2/lib/strategy.js:175:45  
> at /usr/src/node-red/node\_modules/oauth/lib/oauth2.js:191:18  
> at ClientRequest. (/usr/src/node-red/node\_modules/oauth/lib/oauth2.js:162:5)  
> at ClientRequest.emit (events.js:198:13)  
> at Socket.socketErrorListener (\_http\_client.js:401:9)  
> at Socket.emit (events.js:198:13)  
> at emitErrorNT (internal/streams/destroy.js:91:8)  
> at emitErrorAndCloseNT (internal/streams/destroy.js:59:3)  
> at process.\_tickCallback (internal/process/next\_tick.js:63:19)

Output Inspector Google-Chrome:

 ![Bildschirmfoto 2021-01-14 um 12.20.05](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/7/e757db3b0ab3062850b8810b16810498e4daf9e4.png)

my adminAuth in settings.js looks like this:

> Blockquote  
> adminAuth: {  
> type: "strategy",  
> strategy: {  
> name: "Keycloak",  
> label: "Authenticate with Identity Provider",  
> icon: "fa-lock",  
> strategy: require("@exlinc/keycloak-passport"),  
> options: {  
> host: "[http://localhost:8300](http://localhost:8300)",  
> realm: "caberra",  
> clientID: "caberra-core-node-red-client",  
> clientSecret: "e08053d4-2736-413e-a67e-5805c29e89e0",  
> callbackURL: "/auth/strategy/callback",  
> authorizationURL:  
> "[http://localhost:8300/auth/realms/caberra/protocol/openid-connect/auth](http://localhost:8300/auth/realms/caberra/protocol/openid-connect/auth)",  
> tokenURL:  
> "[http://localhost:8300/auth/realms/caberra/protocol/openid-connect/token](http://localhost:8300/auth/realms/caberra/protocol/openid-connect/token)",  
> userInfoURL:  
> "[http://localhost:8300/auth/realms/caberra/protocol/openid-connect/userinfo](http://localhost:8300/auth/realms/caberra/protocol/openid-connect/userinfo)",  
> },  
> verify: function (accessToken, refreshToken, profile, done) {  
> done(null, profile);  
> },  
> },  
> users: [{ username: "iot40-node-red", permissions: ["\*"] }],  
> },

I also tried with the email address of this keycloak-user, but unfortunately without success and with the same result.

Attached are the settings of Keycloak.

 ![Bildschirmfoto 2021-01-14 um 11.41.50](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/e/8ef3203af047ba34cbf2e8ae01296d01dd5e1c33.png)

I am grateful for any help

---

<div class="post-metadata">

**Author:** ![strmar](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@strmar](https://discourse.nodered.org/u/strmar)\
**Post date:** [12 February 2021 10:04 UTC](https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442/2 "2021-02-12T10:04:16Z")

</div>

Has no one here ever had this problem??  
Can't anyone help me?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![heincar](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/heincar/32/37299_2.png) [@heincar](https://discourse.nodered.org/u/heincar)\
**Post date:** [16 February 2021 08:02 UTC](https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442/3 "2021-02-16T08:02:51Z")

</div>

Same here.. I am struggling with the same issue since some days.

Tested already with postman the token generation in Keycloak. Works perfect.  
But there seems to be a problem in Node-Red to receive the token back.

Still looking for a solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 April 2021 08:03 UTC](https://discourse.nodered.org/t/adminauth-config-for-openid-based-authentication-on-keycloak/39442/4 "2021-04-17T08:03:14Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
