Friction

Pain point · Integrations · Blocks work

External IdP tokens not refreshed when retrieved

1 source thread · first seen 2022-09

Summary

The broker token endpoint returns the stored expired GitHub access token; refreshing manually invalidates Keycloak's refresh token with no way to update it.

Affects
Developers using GitHub apps as external IdP
Workaround
Manually refresh with the provider, which breaks the stored refresh token.

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Keycloak appears to just return the exact response that it originally receives from Github, which is most likely an expired access token”

Report this item