# KeyCloak (OpenID) authentication issue for OpenSearch Dashboards

**URL:** https://forum.opensearch.org/t/keycloak-openid-authentication-issue-for-opensearch-dashboards/13670
**Category:** Security
**Tags:** troubleshoot
**Created:** [March 28, 2023, 3:36pm UTC](https://forum.opensearch.org/t/keycloak-openid-authentication-issue-for-opensearch-dashboards/13670 "2023-03-28T15:36:58Z")
**Posts on this page:** 1
**Showing post:** 7

<div class="post-metadata">

### Author: ![Gsmitt](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.opensearch.org/gsmitt/32/1718_2.png) [@Gsmitt](https://forum.opensearch.org/u/Gsmitt)
#### Post date: [June 24, 2023, 1:52am UTC](https://forum.opensearch.org/t/keycloak-openid-authentication-issue-for-opensearch-dashboards/13670/7 "2023-06-24T01:52:54Z")

</div>

Hey @Amith

This might help, I found this post.

> [@Role mappings not working when using OIDC](https://forum.opensearch.org/t/role-mappings-not-working-when-using-oidc/10594/2):
>
> @Raki I’ve just tested your settings and it seems that your Role Mapper is incorrectly set. You don’t have Multivalued enabled. Roles are sent as an array in JWT token. i.e. [image] Multivalued must be enabled even when you send only single role. That’s why you have square brackets in the roles view in OpenSearch Dashboards UI. [image] Also, you should use kibanauser instead of kibana\_user for the built-in backend role.

---

_[View the full topic](https://forum.opensearch.org/t/keycloak-openid-authentication-issue-for-opensearch-dashboards/13670)._
