{"repo":"bannaarr01/nestjs-keycloak-auth","free":true,"listed":false,"github":"https://github.com/bannaarr01/nestjs-keycloak-auth","clone":"git clone https://github.com/bannaarr01/nestjs-keycloak-auth.git","description":"Keycloak authentication and authorization module for NestJS","language":"TypeScript","stars":16,"topics":["access-control","authentication","authorization","guard","jwt","keycloak","multi-tenant","nestjs","nestjs-module","oauth2"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"NestJS Keycloak Auth A bearer-only Keycloak authentication and authorization module for NestJS. Uses standard OIDC discovery and has zero runtime dependency on keycloak-connect . Features - Bearer-token API authentication and authorization for NestJS. - OIDC discovery — endpoints resolved from .well-known/openid-configuration (with fallback). - ONLINE and OFFLINE token validation (introspection + JWKS signature verification). - Algorithm allowlist — only RS, ES, and PS family algorithms are accepted during offline validation. - Per-realm notBefore revocation state for multi-tenant safety. - Resource/scope authorization via UMA ( @Resource , @Scopes , @ConditionalScopes ). - Role authorization ( @Roles ) with configurable role merge and match modes. - OIDC back-channel logout ( sid / sub revocation). - Typed error hierarchy — all library errors extend KeycloakAuthError for easy catching. - Compatible with Fastify platform. Runtime Scope (Important) - This package is designed for bearer-only API/server flows. - It does not implement browser/session middleware flows such as login redirects, auth-code callback exchange, session/cookie grant stores, or logout endpoints. - It implements Keycloak admin callback endpoints: - POST /k push not before for realm notBefore revocation updates (used by OFFLINE token validation). - POST /k logout for OIDC back-channel logout token handling ( sid / sub revocation). Installation Yarn NPM Getting Started Module registration Registering the modu","default_branch":null,"files":null,"tree":[],"storefront":"/r/bannaarr01","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bannaarr01/nestjs-keycloak-auth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}