Token exchange option #3197
|
Hi I am trying token exchange with Azure Entra ID.
private SDK buildClientCredentialsSdk(String token) throws Exception {
return SDKBuilder.newBuilder()
.platformEndpoint(config.platformEndpoint)
.clientSecret(config.clientId, config.clientSecret)
.useInsecurePlaintextConnection(false)
.tokenExchange(token)
.sslFactory(config.sslFactory)
.build();
}I see warning in Keycloak logs 2026-03-22 03:32:22,204 WARN [org.keycloak.events] (executor-thread-323) type="TOKEN_EXCHANGE_ERROR", realmId="4c0030ae-8774-4dc7-a319-dddd863d1360", realmName="opentdf", clientId="opentdf", userId="null", ipAddress="xxxxxx", error="not_allowed", reason="client is not within the token audience", auth_method="token_exchange", grant_type="urn:ietf:params:oauth:grant-type:token-exchange", client_auth_method="client-secret" Please suggest Regards |
Replies: 2 comments
|
I also tried using the CLI: gave error Both platform and keycloak certs are added to the local certificate store, and the browser does not show any warnings. And FYI, I otdfctl auth login --client-id=cli-client complains cert error but atleast "otdfctl auth login --client-id=cli-client --tls-no-verify" take me to login page, but still fails later with the error above. regards |
|
This looks like two separate issues, and both are in the IdP/client configuration layer rather than anything OpenTDF-specific. On the token exchange side, the Keycloak error (client is not within the token audience) typically means the subject token you’re presenting wasn’t issued for the client that’s trying to perform the exchange, or that the client isn’t permitted to exchange it. I’d start by decoding the original token and checking the aud claim, confirming which client is actually performing the exchange, and then verifying token exchange permissions and audience configuration on the Keycloak side. In some cases, explicitly setting the target audience in the exchange request can also help validate whether it’s purely a configuration issue. Separately, the otdfctl failure (x509: certificate signed by unknown authority) is a TLS trust issue when the CLI calls the Keycloak token endpoint. That’s usually related to CA chain, hostname/SAN, or local trust store differences between your browser and the CLI. I’d double check that the full cert chain is being presented and trusted, and try reproducing the call with something like curl from the same machine to isolate it. Since both of these are really about the Keycloak ↔ Azure Entra ID integration and token handling, you’ll likely get more targeted help in the Keycloak or Azure Entra ID communities than in the OpenTDF discussions. |
This looks like two separate issues, and both are in the IdP/client configuration layer rather than anything OpenTDF-specific.
On the token exchange side, the Keycloak error (client is not within the token audience) typically means the subject token you’re presenting wasn’t issued for the client that’s trying to perform the exchange, or that the client isn’t permitted to exchange it. I’d start by decoding the original token and checking the aud claim, confirming which client is actually performing the exchange, and then verifying token exchange permissions and audience configuration on the Keycloak side. In some cases, explicitly setting the target audience in the exchange request can als…