# Keycloak: 401,"error":"Unauthorized","message":"Unauthorized"

**URL:** <https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457>\
**Category:** Security\
**Created:** [August 20, 2025, 10:42am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457 "2025-08-20T10:42:07Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 20, 2025, 10:42am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/1 "2025-08-20T10:42:07Z")

</div>

I’m facing the same issue with OpenID like many others. Checked a lot of related topics here, but have not found a solution. My Opensearch and Openseach-dashboards v. 2.10.  
Keycloak is 26.2.  
When I’m trying to login through Keycloak I get “401 Unauthorized with Keycloak OpenID”. In keycloak logs:  
`2025-08-20 11:51:28,371 WARN [org.keycloak.services] (executor-thread-139) KC-SERVICES0046: Multiple values found ‘[view-realm, view-identity-providers, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value`  
(as I can see in the log above there is no my os\_role “os\_admin“ in the list I created within the client opensearch1.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/b/baf306d43acf54076de6661c78f478ce03b9dc7f.png)

My **keycloak**  **client** config attached:

```json
{
  "clientId": "opensearch1",
  "name": "opensearch1",
  "description": "",
  "rootUrl": "https://keyvault.mycorp.local/",
  "adminUrl": "https://keyvault.mycorp.local/",
  "baseUrl": "",
  "surrogateAuthRequired": false,
  "enabled": true,
  "alwaysDisplayInConsole": false,
  "clientAuthenticatorType": "client-secret",
  "secret": "vjbLwYK9ANfSWLmE7yxxoJic3pcFL16E",
  "redirectUris": \[
    "https://logging.mycorp.local/*"
  \],
  "webOrigins": \[
    "https://logging.mycorp.local"
  \],
  "notBefore": 0,
  "bearerOnly": false,
  "consentRequired": false,
  "standardFlowEnabled": true,
  "implicitFlowEnabled": true,
  "directAccessGrantsEnabled": true,
  "serviceAccountsEnabled": true,
  "authorizationServicesEnabled": true,
  "publicClient": false,
  "frontchannelLogout": true,
  "protocol": "openid-connect",
  "attributes": {
    "realm_client": "false",
    "oidc.ciba.grant.enabled": "false",
    "client.secret.creation.time": "1755247233",
    "backchannel.logout.session.required": "true",
    "standard.token.exchange.enabled": "false",
    "frontchannel.logout.session.required": "true",
    "oauth2.device.authorization.grant.enabled": "false",
    "display.on.consent.screen": "false",
    "backchannel.logout.revoke.offline.tokens": "false"
  },
  "authenticationFlowBindingOverrides": {},
  "fullScopeAllowed": true,
  "nodeReRegistrationTimeout": -1,
  "protocolMappers": \[
    {
      "name": "opensearch1-mapper",
      "protocol": "openid-connect",
      "protocolMapper": "oidc-usermodel-client-role-mapper",
      "consentRequired": false,
      "config": {
        "introspection.token.claim": "false",
        "multivalued": "true",
        "userinfo.token.claim": "true",
        "id.token.claim": "true",
        "lightweight.claim": "false",
        "access.token.claim": "true",
        "claim.name": "os_roles",
        "jsonType.label": "String",
        "usermodel.clientRoleMapping.clientId": "opensearch1"
      }
    }
  \],
  "defaultClientScopes": \[
    "web-origins",
    "service_account",
    "acr",
    "profile",
    "roles",
    "basic",
    "email"
  \],
  "optionalClientScopes": \[
    "address",
    "phone",
    "offline_access",
    "microprofile-jwt"
  \],
  "access": {
    "view": true,
    "configure": true,
    "manage": true
  }
}

```

My **opensearch\_dashboards.yml** :

```yml
opensearch.hosts: \[http://localhost:9200\]
opensearch.ssl.verificationMode: none
opensearch.username: admin
opensearch.password: b6rb_nnm4_55Cx1
opensearch.requestHeadersWhitelist:
  \["Authorization", "securitytenant", "WWW-Authenticate"\]
opensearch_security.multitenancy.enabled: true
opensearch_security.multitenancy.tenants.enable_global: true
opensearch_security.multitenancy.tenants.enable_private: true
opensearch_security.multitenancy.tenants.preferred: \[Global, Private\]
opensearch_security.multitenancy.enable_filter: false
opensearch_security.readonly_mode.roles: \[kibana_read_only\]
\# Use this setting if you are running opensearch-dashboards without https
opensearch_security.cookie.secure: false
\# keycloak:
opensearch_security.auth.multiple_auth_enabled: true
opensearch_security.auth.type: \["basicauth", "openid"\]
opensearch_security.ui.openid.login.buttonname: "Log in with Keycloak"
opensearch_security.openid.connect_url: https://keycloak.mycorp.local/auth/realms/master/.well-known/openid-configuration
opensearch_security.openid.base_redirect_url: https://logging.mycorp.local
opensearch_security.openid.client_id: opensearch1
opensearch_security.openid.client_secret: vjbLwYK9ANfSWLmE7yxxoJic3pcFL16E
opensearch_security.openid.verify_hostnames: false
opensearch_security.openid.refresh_tokens: false
#opensearch_security.openid.scope: "opensearch1-dedicated"
opensearch_security.openid.header: "Authorization"
opensearch_security.cookie.ttl: "3600"

```

My **opensearch-security/config.yml** :

```yml
    authc:
      \# <1>
      basic_internal_auth_domain:
        description: "Authenticate via HTTP Basic against internal users database"
        http_enabled: true
        transport_enabled: true
        order: 0
        http_authenticator:
          type: basic
          challenge: false
        authentication_backend:
          type: intern
      \# <2>
      openid_auth_domain:
        http_enabled: true
        transport_enabled: true
        order: 1
        http_authenticator:
          type: openid
          challenge: true
          config:
            subject_key: preferred_username
            roles_key: os_roles
            openid_connect_url: https://keycloak.mycorp.local/auth/realms/master/.well-known/openid-configuration
            #scope: "openid profile email"
            openid_connect_idp:
              enable_ssl: true
              verify_hostnames: false
            jwt_clock_skew_tolerance_seconds: 60
            client_id: opensearch1
            client_secret: vjbLwYK9ANfSWLmE7yxxoJic3pcFL16E
        authentication_backend:
          type: noop
      \#

```

And **internal\_users.yml** :

```yml
---
\_meta:
  type: "internalusers"
  config_version: 2
\# Define your internal users here
admin:
  hash: "$2y$12$S1.EVgMoneoDhT5\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*WFM9aKpIuDBD12d2"
  reserved: true
  backend_roles:
    - "admin"
    - "os_admin"
  description: "Demo admin user"
kibanaro:
  hash: "$2a$12$JJSXNfTowz7Uu5ttXfeYpeYE0arACvcwlPBStB1F.MI7f0U9Z4DGC"
  reserved: false
  backend_roles:
    - "kibanauser"
    - "readall"
    - "os_kibanauser"
  attributes:
    attribute1: "value1"
    attribute2: "value2"
    attribute3: "value3"
  description: "Demo OpenSearch Dashboards read only user, using external role mapping"
readall:
  hash: "$2a$12$ae4ycwzwvLtZxwZ82RmiEunBbIPiAmGZduBAjKN0TXdwQFtCwARz2"
  reserved: false
  backend_roles:
    - "readall"
    - "os_readall"
  description: "Demo readall user, using external role mapping"

```

**Could somebody be so kind and help my find a solution?**

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 20, 2025, 11:21am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/2 "2025-08-20T11:21:58Z")

</div>

@wh1test This is expected. These are only labels and you can either use it to assign Realm roles and make it a composite role.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/1/1b2e821ea93c67ee1825e954de27cc21b395e233.png)

Or, create Realm roles and then assign to the user directly.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f2299a96a7565ac11d1aba0d00353ac4ba64b85c.png)

Could you send screen shot of your client scopes full list in opensearch1 client?

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/9/9e2b3543f6bf0a9f6fdae5f43f212c854c020f81.png)

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 20, 2025, 12:14pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/3 "2025-08-20T12:14:28Z")

</div>

> [@pablo](#):
>
> Could you send screen shot of your client scopes full list in opensearch1 client?

Thank you very much, Pablo. I’ll check your suggestions and reply.  
Here is my list (recently I tried to remove all roles except dedicated), but it didn’t help. Therefore I re-joined them as Optional.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f8c5a8c44d1a0fe179cf37e3cb7d70c73aca3e02.png)

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 20, 2025, 12:31pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/4 "2025-08-20T12:31:19Z")

</div>

@wh1test Thank you.  
Please access roles, go to Mappers and take a screenshot of that list.  
If you have os\_roles in it, please access it and take a screenshot of that too.

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 20, 2025, 2:13pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/5 "2025-08-20T14:13:22Z")

</div>

> [@pablo](#):
>
> Please access roles, go to Mappers and take a screenshot of that list.

Here is Mappers of my client:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/a/a3fe65c3d9001faf9a5d5c22abd56e7ba3a37ad3.png)

Here is my real roles (default):

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/4/4dbbf203e2c64967953096cc4c105180d4c029dd.png)

My user is associated with the role os\_admin:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/d/d04238db1450ace96e3ffed77db12172fb9fefc4.png)

---

<div class="post-metadata">

**Author:** ![sebastian-thorn](https://avatars.discourse-cdn.com/v4/letter/s/958977/32.png) [@sebastian-thorn](https://forum.opensearch.org/u/sebastian-thorn)\
**Post date:** [August 20, 2025, 2:27pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/6 "2025-08-20T14:27:42Z")

</div>

A great thing in Keycloak that is somewhat hard to find but useful when debugging auth is this:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/a/aa033f3333ec034148e88769d41da73c66b2ba79.png)

Scroll down and look in `groups` or what field you have in your settings.

Br Sebastian

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 20, 2025, 2:33pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/7 "2025-08-20T14:33:13Z")

</div>

great tool!

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/0/0b6854dd636efe913b4c14574d7685b05d3614cc.png)

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 20, 2025, 7:20pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/8 "2025-08-20T19:20:53Z")

</div>

@wh1test You’ve used `User Client Role`. Try creating a mapper of the `User Realm Role` type.  
Also, your os\_roles has the Multivalued option disabled. As a result, you get the reported error. Opensearch won’t handle an array as it needs single values.

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/c/c79b55b591ae14cc40c6fd8268a936b59f780daf.png)

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 21, 2025, 9:17am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/9 "2025-08-21T09:17:16Z")

</div>

> [@pablo](#):
>
> This is expected. These are only labels and you can either use it to assign Realm roles and make it a composite role.
> 
> ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/1/1b2e821ea93c67ee1825e954de27cc21b395e233.png)
> 
> Or, create Realm roles and then assign to the user directly.
> 
> ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f2299a96a7565ac11d1aba0d00353ac4ba64b85c.png)

Hi Pablo. It’s not clear for me =| I’m trying to configure keycloak client from scratch.

> [@pablo](#):
>
> You’ve used `User Client Role`. Try creating a mapper of the `User Realm Role` type.

Added it into my fresh client config.

> [@pablo](#):
>
> Also, your os\_roles has the Multivalued option disabled. As a result, you get the reported error. Opensearch won’t handle an array as it needs single values.

I tried Multivalued in ON and OFF states without luck.

P.S. Initially I tried to sutup using the guide: [Enabling OpenSearch OIDC Authentication for Single Sign-On](https://nsalexamy.github.io/service-foundry/pages/documents/sso-foundry/opensearch-oidc/)

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 21, 2025, 10:43am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/10 "2025-08-21T10:43:08Z")

</div>

It’s nightmare =\ I’ve created client from scratch, created roles there and created realm role “os-admin”. Then associated it with client role, but still unable to pass through authentication: {“statusCode”:401,“error”:“Unauthorized”,“message”:“Unauthorized”}

Full config of my keycloak client opensearch1:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f1528629fae9de71de0c1ca97485e5e491e657d6.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/3/3d5b60f0bbfe286744fc6a598b8f781dce969a3a.png) ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/0/028173837ce1adf5c620950bb1ed8bf794661bad.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/f/f49204ecba574b12d78df608415abc7ed5aafc67.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/2/2fbad724add7a921358bfa773c167cc9b025e073.png)  
 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/0/0ba6054fb7d56af4fec5b52b2897737669ea605f.png)

**Those messages are in keycloak log:**  
2025-08-21 12:55:28,217 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-realm, view-identity-providers, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value

> **rest logs**
>
> 2025-08-21 12:55:28,218 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,218 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,218 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[manage-account, manage-account-links, view-profile]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,219 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-realm, view-identity-providers, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,219 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,219 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-21 12:55:28,219 WARN [org.keycloak.services] (executor-thread-34) KC-SERVICES0046: Multiple values found ‘[manage-account, manage-account-links, view-profile]’ for protocol mapper ‘client roles’ but expected just single value

Here is output of Client scope Evaluate tool. BTW I don’t understand why **os\_roles”: []** doesn’t contain “ **os\_admin** ” role. =\  
{  
“exp”: 1755771764,  
“iat”: 1755771704,  
“jti”: “cdf6e473-c82f-5555-9999-4cd52780e741”,  
“iss”: “[https://keycloak.mycorp.com/auth/realms/master”](https://keycloak.mycorp.com/auth/realms/master%E2%80%9D),  
“aud”: “opensearch1”,  
“sub”: “8f805225-799b-3333-2222-ad35d6fa6a4c”,  
“typ”: “ID”,  
“azp”: “opensearch1”,  
“sid”: “f2c2e56a-9461-4444-4444-c121634ce622”,  
“acr”: “1”,  
“resource\_access”: {  
“opensearch1”: {  
“roles”: “os\_admin”  
},  
“Parking-realm”: {  
“roles”: “view-realm”  
},  
“external-realm”: {  
“roles”: “view-identity-providers”  
},  
“master-realm”: {  
“roles”: “view-identity-providers”  
},  
“account”: {  
“roles”: “manage-account”  
}  
},  
“email\_verified”: false,  
“os\_roles”: [  
“create-realm”,  
“default-roles-master”,  
“offline\_access”,  
“admin”,  
“uma\_authorization”  
],  
“name”: “MyNameMySurname”,  
“preferred\_username”: “myusername”,  
“locale”: “en”,  
“given\_name”: “MyName”,  
“family\_name”: “MySurname”,  
“email”: “\*\*\*\*@mycorp.com”  
}

My **opensearch\_dashboards.yml** :

> **opensearch\_dashboards.yml**
>
> ```auto
> opensearch.hosts: \[http://localhost:9200\]
> opensearch.ssl.verificationMode: none
> opensearch.username: admin
> opensearch.password: mypasss
> opensearch.requestHeadersWhitelist: \[“Authorization”, “securitytenant”, “WWW-Authenticate”\]
> opensearch_security.multitenancy.enabled: true
> opensearch_security.multitenancy.tenants.enable_global: true
> opensearch_security.multitenancy.tenants.enable_private: true
> opensearch_security.multitenancy.tenants.preferred: \[Global, Private\]
> opensearch_security.multitenancy.enable_filter: false
> opensearch_security.readonly_mode.roles: \[kibana_read_only\]
> 
> # Use this setting if you are running opensearch-dashboards without https
> 
> opensearch_security.cookie.secure: false
> 
> \# keycloak:
> opensearch_security.auth.multiple_auth_enabled: true
> opensearch_security.auth.type: \[“basicauth”, “openid”\]
> opensearch_security.ui.openid.login.buttonname: “Log in with Keycloak”
> opensearch_security.openid.connect_url: [https://keycloak.mycorp.com/auth/realms/master/.well-known/openid-configuration](https://keycloak.mycorp.com/auth/realms/master/.well-known/openid-configuration)
> opensearch_security.openid.base_redirect_url: [https://logging.mycorp.com](https://logging.mycorp.com)
> opensearch_security.openid.client_id: opensearch1
> opensearch_security.openid.client_secret: f1CZ7202gpLezh66666639yx5m0l
> opensearch_security.openid.verify_hostnames: false
> opensearch_security.openid.refresh_tokens: false
> opensearch_security.openid.scope: “openid email profile”
> opensearch_security.openid.header: “Authorization”
> opensearch_security.cookie.ttl: “3600”
> 
> ```

And my **config/opensearch-security/config.ym** l:

> **config.yml**
>
> ```auto
> authc:
> # <1>
> basic_internal_auth_domain:
> description: “Authenticate via HTTP Basic against internal users database”
> http_enabled: true
> transport_enabled: true
> order: 0
> http_authenticator:
> type: basic
> challenge: false
> authentication_backend:
> type: intern
> 
> openid_auth_domain:
> http_enabled: true
> transport_enabled: true
> order: 1
> http_authenticator:
> type: openid
> challenge: true
> config:
> subject_key: preferred_username
> roles_key: os_roles
> openid_connect_url: https://keycloak.mycorp.com/auth/realms/master/.well-known/openid-configuration
> scope: “openid email profile”
> openid_connect_idp:
> enable_ssl: true
> verify_hostnames: false
> jwt_clock_skew_tolerance_seconds: 60
> client_id: opensearch1
> client_secret: f1CZ7202gpLez666666639yx5m0l
> authentication_backend:
> type: noop
> 
> ```

My **roles\_mapping.yml** :

> **roles\_mapping.yml**
>
> ```auto
> all_access:
> reserved: false
> backend_roles:
> - “admin”
> - “os_admin”
> description: “Maps admin to all_access”
> kibana_user:
> reserved: false
> backend_roles:
> - “kibanauser”
> - “os_kibanauser”
> description: “Maps kibanauser to kibana_user”
> readall:
> reserved: false
> backend_roles:
> - “readall”
> - “os_readall”
> 
> ```

And my **internal\_users.yml** :

> **internal\_users.yml**
>
> ```auto
> admin:
> hash: “$2y$12$S1.EVgMone\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*DBD12d2”
> reserved: true
> backend_roles:
> - “admin”
> - “os_admin”
> description: “Demo admin user”
> kibanaro:
> hash: “$2a$12$JJSXNfTowz7Uu55555555555555F.MI7f0U9Z4DGC”
> reserved: false
> backend_roles:
> - “kibanauser”
> - “readall”
> - “os_kibanauser”
> attributes:
> attribute1: “value1”
> attribute2: “value2”
> attribute3: “value3”
> description: “Demo OpenSearch Dashboards read only user, using external role mapping”
> readall:
> hash: “$2a$12$ae4ycwzwvLtZxwZ82Rm8888888888888888N0TXdwQFtCwARz2”
> reserved: false
> backend_roles:
> - “readall”
> - “os_readall”
> description: “Demo readall user, using external role mapping”
> 
> ```

Could somebody help? I cannot find out what is wrong =|  
P.S. Opensearch and opensearch-dashboards (both are v 2.10) has been restarted after client re-created.

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 21, 2025, 8:02pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/11 "2025-08-21T20:02:45Z")

</div>

@wh1test JWT looks fine. When you click on the `Log in with single sign-on` button, are you redirected successfully to Keycloak?

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 21, 2025, 8:21pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/12 "2025-08-21T20:21:17Z")

</div>

@wh1test Try switching this

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/c/ce2c89f58bfcba6c09baed9813b90f6d17fa8567.png)

to this

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/b/b4e8960d767ae6ad7279ee9bdc518a37382e4846.png)

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 22, 2025, 5:56am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/13 "2025-08-22T05:56:25Z")

</div>

> [@pablo](#):
>
> JWT looks fine. When you click on the `Log in with single sign-on` button, are you redirected successfully to Keycloak?

Yes, Pablo. Everything works as expected: redirect to keycloak page, input login/password, input OTP and then {“statusCode”:401,“error”:“Unauthorized”,“message”:“Unauthorized”}.  
Other clients works perfectly (I use integrations with vCloud, Grafana, ArgoCD, sonarqube, zabbix).

> [@pablo](#):
>
> Try switching this

The same error((

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 22, 2025, 8:58am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/14 "2025-08-22T08:58:17Z")

</div>

@wh1test Do you use a reverse proxy between OSD and Keycloak?

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 22, 2025, 10:17am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/15 "2025-08-22T10:17:41Z")

</div>

> [@pablo](#):
>
> Do you use a reverse proxy between OSD and Keycloak?

Yes. Envoy. I can connect them without reverse proxy. Those hosts located in the same subnet, but all the rest Keycloak clients work properly =|

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 22, 2025, 11:03am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/16 "2025-08-22T11:03:34Z")

</div>

@wh1test Does your reverse proxy pass Authorization header as OpenSearch Dashboards does?

> [@wh1test](#):
>
> ```auto
> opensearch.requestHeadersWhitelist: \[“Authorization”, “securitytenant”, “WWW-Authenticate”\]
> 
> ```

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 22, 2025, 11:31am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/17 "2025-08-22T11:31:01Z")

</div>

Okay, I’ve changed settings in config/opensearch-security/config.yml to access keycloak directly:  
`openid_connect_url: ``http://172.16.1.15:8080/auth/realms/master/.well-known/openid-configuration`  
and opensearch\_dashboards.yml  
`opensearch_security.openid.connect_url: ``http://172.16.1.15:8080/auth/realms/master/.well-known/openid-configuration`  
.

Restart opensearch and opensearch-dashboards.

Login attempt failed:  
**This page isn’t working**

**172.16.1.15** redirected you too many times.

ERR\_TOO\_MANY\_REDIRECTS

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 22, 2025, 11:55am UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/18 "2025-08-22T11:55:54Z")

</div>

@wh1test Do you see any 401 in the logs?

This could be related to `securitytenant` header. That is also whitelisted in opensearch\_dashboards.yml

---

<div class="post-metadata">

**Author:** ![pablo](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/pablo/32/10363_2.png) [@pablo](https://forum.opensearch.org/u/pablo)\
**Post date:** [August 22, 2025, 1:11pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/19 "2025-08-22T13:11:34Z")

</div>

@wh1test I’ve just noticed that you connect directly to your Keycloak, but issue is on the other end when Keycloak is redirecting back to OpenSearch Dashboards. In this case you’re still using reverse proxy to access OpenSearch Dashboards.

---

<div class="post-metadata">

**Author:** ![wh1test](https://avatars.discourse-cdn.com/v4/letter/w/e274bd/32.png) [@wh1test](https://forum.opensearch.org/u/wh1test)\
**Post date:** [August 22, 2025, 1:59pm UTC](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457/20 "2025-08-22T13:59:16Z")

</div>

Yeap, Pablo you are right. Adjusted settings on opensearch-dashboards side:  
`opensearch_security.openid.base_redirect_url: ``http://172.16.1.7:5601`  
restarted opensearch-dashboards.  
And keycloak client:

 ![image](https://us1.discourse-cdn.com/flex019/uploads/mauve_hedgehog/original/2X/9/94a531ce5f76b0d1dcbd378c649206b27cbc1c74.png)  
But still getting the same 401 error page and messages in keycloak logs.

> **logs**
>
> 2025-08-22 16:56:28,189 WARN [org.keycloak.cookie.DefaultCookieProvider] (executor-thread-75) Non-secure context detected; cookies are not secured, and will not be available in cross-origin POST requests  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-realm, view-identity-providers, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[manage-account, manage-account-links, view-profile]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-realm, view-identity-providers, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[view-identity-providers, view-realm, manage-identity-providers, impersonation, create-client, manage-users, query-realms, view-authorization, query-clients, query-users, manage-events, manage-realm, view-events, view-users, view-clients, manage-authorization, manage-clients, query-groups]’ for protocol mapper ‘client roles’ but expected just single value  
> 2025-08-22 16:56:28,211 WARN [org.keycloak.services] (executor-thread-75) KC-SERVICES0046: Multiple values found ‘[manage-account, manage-account-links, view-profile]’ for protocol mapper ‘client roles’ but expected just single value

Maybe I have to switch opensearch from opensearch.hosts: [[http://localhost:9200](http://localhost:9200)] to opensearch.hosts: [[https://localhost:9200](https://localhost:9200)] and adjust logstash settings =|

[Next page](https://forum.opensearch.org/t/keycloak-401-error-unauthorized-message-unauthorized/26457.md?page=2)
