Configure OIDC with Keycloak

This page explains how to integrate Keycloak as an OpenID Connect (OIDC) identity provider to authenticate your users on Reemo.

Note

Depending on your deployment mode, SSO can be enabled at the instance level (Private Cloud / On-Prem) or at the organization level (Public Cloud).
Screenshots and labels may vary slightly depending on your interface version.

Configure SSO in Reemo

Case 1: Instance level (Private Cloud / On-Prem)
From verified_user Admin Area > dashboard General > passkey SSO Connectors, configure SSO for the instance.
Access SSO Connectors in the instance Admin Area

Access SSO Connectors in the instance Admin Area.

Case 2: Organization level (Public Cloud)
From domain Organization > dashboard General > passkey SSO Connectors, configure SSO for that organization.
Configure SSO in Organization > SSO Connectors

Configure SSO in Organization > SSO Connectors.

Create the OIDC connector in Reemo

  1. From verified_user Admin Area > domain Organizations, select your organization, then go to dashboard General > passkey SSO Connectors and click New Connector > New OIDC Connector.

  2. Enter the Friendly Name (e.g. Keycloak). The Issuer URL, Client ID and Client Secret fields will be filled in after the Keycloak configuration.

OIDC connector creation form

OIDC connector creation form.

  1. Click Create to generate the connector’s callback URL. You will need it in Keycloak.

Retrieving the OIDC callback URL

Copy the callback URL generated by the OIDC connector.

Configure the OIDC client in Keycloak

  1. Log in to your Keycloak Admin Console and select the target Realm.

  2. In Clients > Create client, choose OpenID Connect and set a Client ID (e.g. reemo-api).

  3. On the Capability config step:

    • Client authentication: On (confidential client — Reemo uses a client secret).

    • Standard flow: enabled (Authorization Code Flow).

  4. In Access settings > Valid redirect URIs, paste the callback URL from the Reemo connector.

Keycloak OIDC client settings

Set the Client ID and the callback URL under Valid redirect URIs.

  1. Open the Credentials tab and copy the Client secret.

Keycloak OIDC client secret

Retrieve the Client secret from the Credentials tab.

  1. Note the Issuer, in the format:

    https://[keycloak_url]/realms/[realm]
    

Complete the OIDC connector in Reemo

Complete the connector with the Keycloak information:

  • Issuer URL: https://[keycloak_url]/realms/[realm]. Reemo auto-discovers the endpoints from <issuer>/.well-known/openid-configuration.

  • Client ID and Client Secret retrieved in Keycloak.

  • Scopes: leave empty to use openid profile email by default.

  • Attributes (optional): leave empty to use the standard OIDC attributes (preferred_username, email, name).

Complete the OIDC connector in Reemo

Enter Issuer URL, Client ID and Client Secret, then enable the connector.

Enable the connector (check Enabled) then click Update (or Create) to save.

Declare users

Two approaches are available to grant SSO access to users.

Approach A: Explicit provisioning from the organization
From verified_user Admin Area > domain Organizations, select your organization, then go to inventory_2 Inventory > person Users and click New User > Provision SAML User to add users by entering their email.
New User menu with the Provision SAML User option

Select Provision SAML User from the New User menu.

The same button provisions both SAML and OIDC users.

Approach B: Just-In-Time (JIT) Provisioning
From verified_user Admin Area > domain Organizations, select your organization, then go to dashboard General > passkey SSO Connectors, click the connector then enable Just In Time Provisioning: accounts are created automatically on the first successful login.
Just In Time Provisioning option on the OIDC connector

Enable Just In Time Provisioning to create accounts on first login.

Manage rights dynamically from the directory

Reemo can read each user’s group membership and automatically assign access to the corresponding collections.

In Keycloak

  1. Open your client (e.g. reemo-api), Client scopes tab > click the dedicated scope (e.g. reemo-api-dedicated) > Add mapper > By configuration > Group Membership.

  2. Configure the mapper:

    • Name: a label (e.g. groups).

    • Token Claim Name: groups.

    • Full group path: Off.

Warning

The Token Claim Name must match the attribute name entered on the Reemo side (groups). In OIDC, Reemo reads the claim exactly under that name (no URI fallback like in SAML).

In Reemo

  1. Open the OIDC connector form (Admin Area > General > SSO Connectors), Extra mapping section.

  2. In the Collection field, enter the group claim name (e.g. groups), then click Update.

Extra Mapping section of the connector

Enter the group claim name in the Collection field of Extra Mapping.

  1. In Inventory > Collections, edit a collection and fill the SSO Mapping Identifier field with the corresponding group name.

Log in via OIDC

Once the connector is active and users are declared (or JIT is enabled), your users select the OIDC tab on the login screen, pick the connector, and are redirected to Keycloak.

OIDC tab on the login screen

Select the OIDC tab then the connector to be redirected to Keycloak.