Skip to content
Discussion options

You must be logged in to vote

This looks like two separate issues, and both are in the IdP/client configuration layer rather than anything OpenTDF-specific.

On the token exchange side, the Keycloak error (client is not within the token audience) typically means the subject token you’re presenting wasn’t issued for the client that’s trying to perform the exchange, or that the client isn’t permitted to exchange it. I’d start by decoding the original token and checking the aud claim, confirming which client is actually performing the exchange, and then verifying token exchange permissions and audience configuration on the Keycloak side. In some cases, explicitly setting the target audience in the exchange request can als…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by jrschumacher
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants