# Help with adminAuth config for OpenID based authentication

**URL:** <https://discourse.nodered.org/t/help-with-adminauth-config-for-openid-based-authentication/6058>\
**Category:** General\
**Created:** [22 December 2018 05:48 UTC](https://discourse.nodered.org/t/help-with-adminauth-config-for-openid-based-authentication/6058 "2018-12-22T05:48:01Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![riplatt](https://avatars.discourse-cdn.com/v4/letter/r/77aa72/32.png) [@riplatt](https://discourse.nodered.org/u/riplatt)\
**Post date:** [17 June 2020 22:29 UTC](https://discourse.nodered.org/t/help-with-adminauth-config-for-openid-based-authentication/6058/7 "2020-06-17T22:29:13Z")

</div>

I have this working with:

```javascript
adminAuth: {
    type: "strategy",
    strategy: {
        name: "Keycloak",
        label: 'Sign in with KeyCloak',
        icon: "fa-key",
        strategy: require("@exlinc/keycloak-passport"),
        options: {
            host: "https://nodered.example.com",
            realm: "myRealm",
            clientID: "node-red",
            clientSecret: "761a35f4-f2bf-48ee-b2cb-999351d0242f",
            callbackURL: "/auth/strategy/callback",
            authorizationURL: "https://auth.example.com/auth/realms/myRealm/protocol/openid-connect/auth",
            tokenURL: "https://auth.example.com/auth/realms/myRealm/protocol/openid-connect/token",
            userInfoURL: "https://auth.example.com/auth/realms/myRealm/protocol/openid-connect/userinfo"
        },
        verify: function (accessToken, refreshToken, profile, done) {
            done(null, profile);
        }
    },
    users: [
        { username: "me@example.com", permissions: ["*"] }
    ]
},

```

and Keycloak settings of:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/b/6ba535751892f6eb62844f4aa2200a15cb181fcb.png)

Note the http and not https in the redirect URL, as node-red was sending a redirect\_uri of

```nohighlight
https://auth.example.com/auth/realms/YendorINC/protocol/openid-connect/auth?
response_type=code&
redirect_uri=http%3A%2F%2Fnodered.example.com%2Fauth%2Fstrategy%2Fcallback&
client_id=node-red

```

this could be from running behind a proxy (Traefik) doing the tls for my sites.

@sarosh maybe try setting you `callbackURL` to just `/auth/strategy/callback` and your host to the host url of the nodered server [but I don't know how keycloak can call back to a localhost???]

Regards,

---

_[View the full topic](https://discourse.nodered.org/t/help-with-adminauth-config-for-openid-based-authentication/6058)._
