Authentication - Staff Portal
Key Design Principles
Modules Accessed via Staff Portal
Identity Provider
Keycloak as IAM
Realm Strategy
Benefits of Realm Isolation
Staff Portal Realm Design
Realm: openg2p-staff
Client Model
Client Types
Role & Authorization Model
Role Types
Authorization Enforcement
Token Types & Responsibilities
Authentication Flow – Staff Portal Login
Authorization Code Flow (OIDC)
Step-by-Step
Module Access Flow (Single Sign-On)
Shared Access Token Model
Flow Details
Example Access Token Claims
Logout Flow (Single Logout)
Theming Strategy
High-Level Architecture Diagram
Last updated
Was this helpful?

