Skip to content

[EOEPCA/IAM] Evaluate Token Exchange (RFC8693) #85

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
w-scho opened this issue Feb 21, 2025 · 0 comments
Open

[EOEPCA/IAM] Evaluate Token Exchange (RFC8693) #85

w-scho opened this issue Feb 21, 2025 · 0 comments
Labels
enhancement New feature or request

Comments

@w-scho
Copy link
Collaborator

w-scho commented Feb 21, 2025

The Keycloak community is currently working on making Token Exchange (RFC8693) a fully supported and stable feature (see keycloak/keycloak#31546). This is currently associated with the Keycloak 26.2.0 milestone, which is due by 2025-03-31. So there is a good chance that it will be available soon enough to be leveraged by EOEPCA.
Token Exchange addresses typical delegation and impersonation use cases and may thus fit well for our delegated access scenarios.

This ticket aims at evaluating the applicability of Token Exchange for EOEPCA use cases and its interoperability with other techniques. This should probably be evaluated when Token Exchange is officially available and reasonably stable in Keycloak.

Details to be evaluated include:

Note that some features that would be quite interesting for EOEPCA are covered by optional tickets and may not make it into Keycloak 26.2. These include:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants