hashicorp / vault

A tool for secrets management, encryption as a service, and privileged access management
https://www.vaultproject.io/
Other
30.64k stars 4.14k forks source link

Using OIDC Access token for authenticating APIs #13858

Open aakashgaur01 opened 2 years ago

aakashgaur01 commented 2 years ago

I am trying to integrate Keycloak-OIDC for authentication and authorization.

I have created a client for vault ("vault-secrets") and added a user and role, which are also added under "auth/oidc". Also, policies are mapped and all other required steps are done.

From what I see, OIDC based integration is only with Vault UI. I want to make VAULT API calls using "access token" instead of VAULT Token.

How can I achieve that? Is there any provision or wishlist to add this provision?

hsimon-hashicorp commented 2 years ago

Hi there! I'll check into this with the team, but you may also wish to ask on the Discuss forum, as that's where we tend to encourage questions. https://discuss.hashicorp.com/c/vault/30