# How to integrate keycloak with rocketchat

**URL:** <https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554>\
**Category:** Rocket.Chat Apps\
**Created:** [November 9, 2021, 6:30am UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554 "2021-11-09T06:30:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![arunodhayam](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@arunodhayam](https://forums.rocket.chat/u/arunodhayam)\
**Post date:** [November 9, 2021, 6:30am UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/1 "2021-11-09T06:30:15Z")

</div>

I am using rocket chat and keycloak both are in docker and hosted under domain name like [https://test1.com](https://test1.com)(rocket chat) and [https://test2.com](https://test2.com)(keycloak)  
I want to integrate the rocket-chat with keycloak

---

<div class="post-metadata">

**Author:** ![arunodhayam](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@arunodhayam](https://forums.rocket.chat/u/arunodhayam)\
**Post date:** [November 9, 2021, 6:39am UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/2 "2021-11-09T06:39:05Z")

</div>

I have followed this blog, But its not working

> **[Keycloak](https://docs.rocket.chat/guides/administration/misc.-admin-guides/authentication/open-id-connect/keycloak)**

**keycloak configuration**

1. Provide a client ID: `rocket-chat-client`
2. Select the client protocol as openid-connect
3. Select the client access type as confidential
4. Standard flow implemented: ON  
5 .Valid Redirect URL: `https:test1.com/*`

**Rocket-chat configurations**

1. URL: `https://test2.com/auth`
2. Token Path: `/realms/{realm_name}/protocol/openid-connect/token`
3. Token sent via: Header
4. Identity Token Sent Via: Same As “Token Sent Via”
5. Identity Path: `/realms/{realm_name}/protocol/openid-connect/userinfo`
6. Authorize Path: `/realms/{realm_name}/protocol/openid-connect/auth`
7. Scope: `openid`
8. Param Name for access token: `access_token`
9. Id: This is the id of the Rocket.Chat client created in the keycloak `rocket-chat-client`
10. Secret: Secret key provided in the credentials tab when creating the Rocket.Chat client
11. Button Text: `Login with Keycloak`

---

<div class="post-metadata">

**Author:** ![dudanogueira](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/dudanogueira/32/2529_2.png) [@dudanogueira](https://forums.rocket.chat/u/dudanogueira)\
**Post date:** [November 9, 2021, 4:43pm UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/3 "2021-11-09T16:43:12Z")

</div>

Hi!

Have you seen this thread post?

> [@HELP! Setting up oauth with keycloack](https://forums.rocket.chat/t/help-setting-up-oauth-with-keycloack/10202):
>
> Description I have installed keycloack openid and configured it with rocket.chat using oath. I followed the guide in the documentation all the configurations are 100% correct yet i cant make it to work. Steps to reproduce the issue: Go to rocketchat home page (localhost:3000) . Press login using keycloack . enter keycloack credentials (username/password) After that i am getting an undefined error on top right corner. See error logs below Server Setup Information Version of Rocket.Chat S…

Maybe it can shade some light about your issue.

I have not experience in keycloak, but I can ping some from our team regarding that.

---

<div class="post-metadata">

**Author:** ![stefan.badenhorst](https://avatars.discourse-cdn.com/v4/letter/s/ad7895/32.png) [@stefan.badenhorst](https://forums.rocket.chat/u/stefan.badenhorst)\
**Post date:** [November 10, 2021, 4:32pm UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/4 "2021-11-10T16:32:57Z")

</div>

These are the settings (Environment variables) that I’m using:

```auto
      - Accounts_OAuth_Custom_keycloak=true
      - Accounts_OAuth_Custom_keycloak_id=$APPLICATION_DOMAIN
      - Accounts_OAuth_Custom_keycloak_secret=
      - Accounts_OAuth_Custom_keycloak_url=$APPLICATION_SCHEME://$APPLICATION_DOMAIN/iam/auth
      - Accounts_OAuth_Custom_keycloak_token_path=/realms/$APPLICATION_REALM/protocol/openid-connect/token
      - Accounts_OAuth_Custom_keycloak_identity_path=/realms/$APPLICATION_REALM/protocol/openid-connect/userinfo
      - Accounts_OAuth_Custom_keycloak_authorize_path=/realms/$APPLICATION_REALM/protocol/openid-connect/auth
      - Accounts_OAuth_Custom_keycloak_scope=openid
      - Accounts_OAuth_Custom_keycloak_access_token_param=access_token
      - Accounts_OAuth_Custom_keycloak_button_label_text=$APPLICATION_NAME
      - Accounts_OAuth_Custom_keycloak_button_label_color=#FFFFFF
      - Accounts_OAuth_Custom_keycloak_login_style=redirect
      - Accounts_OAuth_Custom_keycloak_button_color=#13679A
      - Accounts_OAuth_Custom_keycloak_token_sent_via=payload
      - Accounts_OAuth_Custom_keycloak_identity_token_sent_via=header
      - Accounts_OAuth_Custom_keycloak_key_field=username
      - Accounts_OAuth_Custom_keycloak_username_field=preferred_username
      - Accounts_OAuth_Custom_keycloak_name_field=name
      - Accounts_OAuth_Custom_keycloak_email_field=email
      - Accounts_OAuth_Custom_keycloak_roles_claim=
      - Accounts_OAuth_Custom_keycloak_groups_claim=
      - Accounts_OAuth_Custom_keycloak_groups_channel_map=
      - Accounts_OAuth_Custom_keycloak_channels_admin=rocket.cat
      - Accounts_OAuth_Custom_keycloak_merge_users=true
      - Accounts_OAuth_Custom_keycloak_map_channels=
      - Accounts_OAuth_Custom_keycloak_merge_roles=false
      - Accounts_OAuth_Custom_keycloak_show_button=true
      - Accounts_OAuth_Custom_keycloak_avatar_field=

```

$APPLICATION\_DOMAIN = My Keycloak Client ID  
$APPLICATION\_SCHEME = http or https  
$APPLICATION\_REALM = The realm name in Keycloak  
Please note that Accounts\_OAuth\_Custom\_keycloak\_url may be different for you. We have an additional `/iam/` that you probably don’t need.  
Also we are using a client with access type set to public, so there is no access\_token for us.

Some additional settings that may be handy if you only want to allow keycloak:

```auto
      - Accounts_AllowUsernameChange=false
      - Accounts_AllowEmailChange=false
      - Accounts_AllowPasswordChange=false
      - Accounts_AllowPasswordChangeForOAuthUsers=false

```

Hope this helps you.

---

<div class="post-metadata">

**Author:** ![arunodhayam](https://avatars.discourse-cdn.com/v4/letter/a/6de8d8/32.png) [@arunodhayam](https://forums.rocket.chat/u/arunodhayam)\
**Post date:** [November 15, 2021, 11:52am UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/5 "2021-11-15T11:52:18Z")

</div>

Thanks @dudanogueira and @stefan.badenhorst I have successfully integrate keycloak with Rocket chat

---

<div class="post-metadata">

**Author:** ![dxxof](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dxxof](https://forums.rocket.chat/u/dxxof)\
**Post date:** [October 17, 2023, 4:22am UTC](https://forums.rocket.chat/t/how-to-integrate-keycloak-with-rocketchat/12554/6 "2023-10-17T04:22:07Z")

</div>

Are you using nginx as a reverse proxy? I am trying to get this setup as well and need help. I am new to both rocket chat and keycloak. I have keycloak and rocket chat setup with containers on the same docker network, did extra\_hosts, and it seems like I come to the login page, I get redirected to keycloak, I login and then get brought back to the login page. Any insights would help greatly. 🙂
