# NodeRed authentication using Keycloak

**URL:** <https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023>\
**Category:** General\
**Created:** [6 August 2024 14:20 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023 "2024-08-06T14:20:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lisa](https://avatars.discourse-cdn.com/v4/letter/l/f08c70/32.png) [@lisa](https://discourse.nodered.org/u/lisa)\
**Post date:** [6 August 2024 14:20 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023/1 "2024-08-06T14:20:03Z")

</div>

Hi!  
I keep getting 401 (Unauthorized) when trying to login to NodeRed using Keycloak. Has anyone else encountered this?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/5/655864424c62bed946980d0237b3135980fa4547.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [6 August 2024 16:30 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023/2 "2024-08-06T16:30:03Z")

</div>

How have you got it configured?

That error tells us it has failed to communicate with your keycloak server. Are you running keycloak on the same machine as Node-RED? Is it running in docker or anything else relevant like that?

---

<div class="post-metadata">

**Author:** ![lisa](https://avatars.discourse-cdn.com/v4/letter/l/f08c70/32.png) [@lisa](https://discourse.nodered.org/u/lisa)\
**Post date:** [7 August 2024 09:07 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023/3 "2024-08-07T09:07:02Z")

</div>

The setup is in Kubernetes managed by Rancher. Node-RED and Keycloak are running in separate containers within the same Kubernetes cluster.

I got it configured in the settings file like this:

```auto
adminAuth: {
             type: "strategy",
             strategy: {
             name: "Keycloak",
             label: 'Authenticate with Keycloak',
             icon: "fa-lock",
             strategy: require("@exlinc/keycloak-passport"),
             options: {
                 authorizationURL: "https://127.0.0.1:8443/realms/test-realm/protocol/openid-connect/auth",
                 tokenURL: "https://127.0.0.1:8443/realms/test-realm/protocol/openid-connect/token",
                 userInfoURL: "https://127.0.0.1:8443/realms/test-realm/protocol/openid-connect/userinfo",
                 host: "http://localhost:1880",
                 realm: "test-realm",
                 clientID: "nodered",
                 clientSecret: " ****************",
                 callbackURL: "/auth/strategy/callback",
                 verify: function (accessToken, refreshToken, profile, done) {
                     done(null, profile);
             }
           }
         },
         users: [{ username: "lisa", permissions: ["*"] }]
       },

```

Keycloak client config:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/f/7f95ceb649590d29d7420fb46d740adcd89e5474.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [7 August 2024 09:09 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023/4 "2024-08-07T09:09:22Z")

</div>

If they are running in separate containers, then you need to use the external IP of keycloak rather than `127.0.0.1` in your Node-RED configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [5 November 2024 09:09 UTC](https://discourse.nodered.org/t/nodered-authentication-using-keycloak/90023/5 "2024-11-05T09:09:42Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
