Configure Authorization
This guide walks through configuring Keycloak Authorization Services to protect resources with fine-grained policies. For background concepts, see Authorization Services.
TOC
PrerequisitesStep 1: Define ResourcesStep 2: Define ScopesStep 3: Create PoliciesCreate a Role-Based PolicyCreate a Group-Based PolicyCreate a Time-Based PolicyCreate a User-Based PolicyCreate an Aggregated PolicyStep 4: Create PermissionsCreate a Resource-Based PermissionCreate a Scope-Based PermissionStep 5: Test PoliciesObtaining Authorization from Your ApplicationRequest a Requesting Party Token (RPT)Introspect an RPTExport and ImportPrerequisites
- A Keycloak Realm with a confidential OIDC client (see Manage Clients).
- Authorization enabled on the client (client Settings > Authorization toggle).
Step 1: Define Resources
Resources represent the entities your application protects.
- In the client's Authorization tab, click Resources.
- Click Create resource.
- Configure:
- Click Save.
Step 2: Define Scopes
If you need scopes beyond those created inline with resources:
- Click Authorization scopes.
- Click Create authorization scope.
- Enter a Name (for example,
approve). - Click Save.
Step 3: Create Policies
Policies define the conditions under which access is granted.
Create a Role-Based Policy
- Click Policies > Create policy > Role.
- Enter a Name (for example,
Managers Only). - Add the required realm or client roles (for example,
manager). - Set Logic to
Positive(grant when the condition is met) orNegative(deny when met). - Click Save.
Create a Group-Based Policy
- Click Create policy > Group.
- Enter a Name.
- Select the groups that should have access.
- Enable Extend to Children to include sub-groups.
- Click Save.
Create a Time-Based Policy
- Click Create policy > Time.
- Configure the time window:
- Not Before / Not On or After — Date range.
- Day of Month / Month / Year — Calendar constraints.
- Hour / Minute — Time of day constraints.
- Click Save.
Create a User-Based Policy
- Click Create policy > User.
- Select specific users who should have access.
- Click Save.
Create an Aggregated Policy
An aggregated policy combines multiple sub-policies with a decision strategy.
- Click Create policy > Aggregated.
- Enter a Name.
- Set Decision Strategy to
Unanimous,Affirmative, orConsensus. - Add the sub-policies.
- Click Save.
Step 4: Create Permissions
Permissions bind resources and scopes to policies.
Create a Resource-Based Permission
- Click Permissions > Create resource-based permission.
- Enter a Name (for example,
Document Access). - Select the Resources this permission applies to.
- Select the Policies to evaluate.
- Set the Decision Strategy for combining policy results.
- Click Save.
Create a Scope-Based Permission
- Click Create scope-based permission.
- Enter a Name (for example,
Document Edit Permission). - Select the Resources (optional — applies to all resources if omitted).
- Select the Scopes (for example,
edit). - Select the Policies.
- Click Save.
Step 5: Test Policies
Use the built-in policy evaluation tool to test your authorization configuration before deploying.
- Click the Evaluate tab in the Authorization section.
- Select or create a test user.
- Select the client scope context.
- Add resource and scope permissions to evaluate.
- Click Evaluate.
- Review the results:
- PERMIT — Access is granted.
- DENY — Access is denied.
- Expand each result to see which policies contributed to the decision.
Obtaining Authorization from Your Application
Request a Requesting Party Token (RPT)
The response contains an RPT (access token with embedded permissions).
Introspect an RPT
The response includes a permissions array listing granted resources and scopes.
Export and Import
Authorization configurations (resources, scopes, policies, permissions) can be exported as JSON for version control or migration:
- In the Authorization tab, click Export settings.
- The JSON includes all resources, scopes, policies, and permissions.
- To import, use the Import button or include the authorization configuration in the client definition within a
KeycloakRealmImportCR.