Pain point · Integrations · Blocks work
External IdP tokens not refreshed when retrieved
1 source thread · first seen 2022-09
Summary
The broker token endpoint returns the stored expired GitHub access token; refreshing manually invalidates Keycloak's refresh token with no way to update it.
- Affects
- Developers using GitHub apps as external IdP
- Workaround
- Manually refresh with the provider, which breaks the stored refresh token.
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Keycloak appears to just return the exact response that it originally receives from Github, which is most likely an expired access token”