K

Keycloak Client Registration Service

REST discovered

Details
URL
{base url}/realms/{realm}/clients-registrations/{provider}
Docs
https://www.keycloak.org/securing-apps/client-registration
Authentication
Keycloak bearer access token for admin or client-registration APIs bearer discovered
Authorization: Bearer <credential>

Create a confidential client or use a user/service account in your Keycloak realm, then obtain an access token from the realm token endpoint described in the OpenID Connect endpoints guide. For admin or client-registration access, grant the needed realm-management roles as described in Using the client registration service and Automating client registration with the CLI.

Keycloak initial access token bearer discovered Get token ↗
Authorization: Bearer <credential> /Authorization: Bearer <credential>

In the Admin Console for a realm, open Clients → Initial access token, click Create, optionally set expiration and client count limits, then copy the token value immediately; Keycloak only shows it once. Use it as Authorization: bearer ... for the client registration service as documented in Using the client registration service.

Keycloak confidential client ID and client secret basic discovered Get credentials ↗
Authorization: Basic <credential>

In your realm, create or open a confidential client and enable client authentication, then use the client ID and its secret from the client's Credentials tab. The client registration docs show this can be used with HTTP Basic auth for the installation provider, and the CLI guide shows passing the secret with kcreg config credentials --secret. See Using the client registration service and Automating client registration with the CLI.