Parameters
See plugin common configurations for configuration options available to all plugins.
This plugin supports referencing parameter values from environment variables using the env:// prefix, or from a secret manager, such as HashiCorp Vault’s KV secrets engine, using the secret:// prefix. For more information, see environment variables in plugin and secrets.
client_id
Client ID.
client_secret
Client secret used when the plugin authenticates to the token endpoint. When field encryption is enabled and configuration is stored in etcd, the gateway encrypts this value before storage.
discovery
URL to the discovery document. At least one of
discoveryandtoken_endpointis required.token_endpoint
Token endpoint that supports the
urn:ietf:params:oauth:grant-type:uma-ticketgrant type for permission evaluation. If provided, it overrides the value from the discovery document. At least one ofdiscoveryandtoken_endpointis required.resource_registration_endpoint
A UMA-compliant resource registration endpoint. When
lazy_load_pathsistrue, the plugin uses this value first and otherwise obtains the endpoint from the discovery document. Dynamic path loading requiresdiscovery, or bothtoken_endpointandresource_registration_endpoint.grant_type
vaild vaule:
urn:ietf:params:oauth:grant-type:uma-ticket
UMA ticket grant used for permission evaluation. This is the default and only accepted value.
policy_enforcement_mode
vaild vaule:
ENFORCINGorPERMISSIVEControls how the plugin handles an empty permission list before it requests a decision from Keycloak.
In
ENFORCINGmode, an empty permission list returns403 Forbidden, or307 Temporary Redirectwhenaccess_denied_redirect_uriis configured.In
PERMISSIVEmode, the plugin continues to the UMA token request without a permission parameter. Keycloak still determines whether the request is authorized.permissions
Permissions representing the resources and scopes the client is seeking access to. Supported forms are
RESOURCE_ID#SCOPE_ID,RESOURCE_ID, and#SCOPE_ID. Used whenlazy_load_pathsisfalse. See obtaining permissions.lazy_load_paths
If
true, dynamically resolve the request URI to Keycloak resources through the resource registration endpoint. See lazy load paths.Dynamic loading requires the plugin to obtain a service-account access token. Enable Service account roles for the Keycloak client and ensure the token contains the
uma_protectionrole before using the Protection API.http_method_as_scope
If true, use the HTTP method of the request as the scope to check whether access should be granted.
In the case where
lazy_load_pathsis set to false, the plugin adds the mapped scope to any of the static permissions configured in thepermissionsattribute, even when they contain one or more scopes already.timeout
vaild vaule:
greater than or equal to 1000
Timeout in milliseconds for the HTTP connection with the identity provider.
access_token_expires_in
vaild vaule:
greater than or equal to 1
Lifetime of the access token in seconds if no
expires_inattribute is present in the token endpoint response.access_token_expires_leeway
vaild vaule:
greater than or equal to 0
Expiration leeway in seconds for access token renewal. When set to a value greater than 0, token renewal will take place the set amount of time before token expiration. This avoids errors in case the access token just expires when arriving to the resource server.
refresh_token_expires_in
vaild vaule:
greater than 0
Expiration time of the refresh token in seconds.
refresh_token_expires_leeway
vaild vaule:
greater than or equal to 0
Expiration leeway in seconds for refresh token renewal. When set to a value greater than 0, token renewal will take place the set amount of time before token expiration. This avoids errors in case the access token just expires when arriving to the resource server.
ssl_verify
If true, verify the OpenID provider's SSL certificates.
cache_ttl_seconds
vaild vaule:
greater than 0
TTL in seconds for the plugin to cache discovery document and access tokens.
keepalive
If
true, keep HTTP connections to the identity provider open for reuse.keepalive_timeout
vaild vaule:
greater than or equal to 1000
Idle time in milliseconds after which an established HTTP connection is closed.
keepalive_pool
vaild vaule:
greater than or equal to 1
Maximum number of connections in the connection pool.
access_denied_redirect_uri
URI used for a
307 Temporary Redirectwhen the permission list is empty inENFORCINGmode or Keycloak returns403 Forbidden.password_grant_token_generation_incoming_uri
Legacy compatibility option that exposes an endpoint for the OAuth Resource Owner Password Credentials grant. When a form-encoded
POSTcontainingusernameandpasswordmatches this URI, the plugin submits a password-grant request to the configuredtoken_endpointand returns its response. OAuth 2.0 Security Best Current Practice states that this grant must not be used. Do not configure this field for new deployments. See RFC 9700, section 2.4.max_req_body_size
vaild vaule:
greater than or equal to 1
Maximum request body size in bytes buffered into memory when the plugin generates a password-grant token. If the body exceeds the limit or cannot be read, the plugin returns
503 Service Unavailable. Available in API7 Gateway 3.9.17 and 3.10.4, and in APISIX 3.18.0.