@ -0,0 +1,6 @@
This project adheres to [Semantic Versioning](
# Changelog for "keycloak-client"
## [0.0.1-SNAPSHOT]
- First release (#21389)

@ -0,0 +1,26 @@
# Acknowledgments
The projects leading to this software have received funding from a series of European Union programmes including:
- the Sixth Framework Programme for Research and Technological Development
- [DILIGENT]( (grant no. 004260).
- the Seventh Framework Programme for research, technological development and demonstration
- [D4Science]( (grant no. 212488);
- [D4Science-II]( (grant no.239019);
- [ENVRI]( (grant no. 283465);
- [iMarine]( (grant no. 283644);
- [EUBrazilOpenBio]( (grant no. 288754).
- the H2020 research and innovation programme
- [SoBigData]( (grant no. 654024);
- [PARTHENOS]( (grant no. 654119);
- [EGI-Engage]( (grant no. 654142);
- [ENVRI PLUS]( (grant no. 654182);
- [BlueBRIDGE]( (grant no. 675680);
- [PerformFISH]( (grant no. 727610);
- [AGINFRA PLUS]( (grant no. 731001);
- [DESIRA]( (grant no. 818194);
- [ARIADNEplus]( (grant no. 823914);
- [RISIS 2]( (grant no. 824091);
- [EOSC-Pillar]( (grant no. 857650);
- [Blue Cloud]( (grant no. 862409);
- [SoBigData-PlusPlus]( (grant no. 871042);

@ -0,0 +1,44 @@
# Keycloak Client
**Keycloak Clienty** provides the basic common classes for OpenId Connect (OIDC) integration and some helper abstract functions for the gCube framework integration
## Structure of the project
The source code is present in `src` folder.
## Built With
* [OpenJDK]( - The JDK used
* [Maven]( - Dependency Management
## Documentation
To build the library JAR it is sufficient to type
mvn clean package
## Change log
See [Releases](
## Authors
* **Mauro Mugnaini** ([Nubisware S.r.l.](
## How to Cite this Software
[Intentionally left blank]
## License
This project is licensed under the EUPL V.1.1 License - see the []( file for details.
## About the gCube Framework
This software is part of the [gCubeFramework]( "gCubeFramework"): an
open-source software toolkit used for building and operating Hybrid Data
Infrastructures enabling the dynamic deployment of Virtual Research Environments
by favouring the realisation of reuse oriented policies.
The projects leading to this software have received funding from a series of European Union programmes see [](
## Acknowledgments
[Intentionally left blank]

@ -0,0 +1,110 @@
<project xmlns=""
<relativePath />
<build />

@ -0,0 +1,25 @@
package org.gcube.common.keycloak;
import org.gcube.common.clients.fw.plugin.Plugin;
public abstract class AbstractPlugin<S, P> implements Plugin<S, P>, KeycloakClient {
public final String name;
public AbstractPlugin(String name) { = name;
public String serviceClass() {
return CATEGORY;
public String serviceName() {
return NAME;
public String name() {
return name;

@ -0,0 +1,161 @@
package org.gcube.common.keycloak;
import static org.gcube.resources.discovery.icclient.ICFactory.clientFor;
import static org.gcube.resources.discovery.icclient.ICFactory.queryFor;
import java.util.Arrays;
import java.util.Base64;
import java.util.Collections;
import java.util.HashMap;
import java.util.List;
import java.util.Map;
import org.gcube.common.gxrest.request.GXHTTPStringRequest;
import org.gcube.common.gxrest.response.inbound.GXInboundResponse;
import org.gcube.common.keycloak.model.TokenResponse;
import org.gcube.common.resources.gcore.ServiceEndpoint;
import org.gcube.common.resources.gcore.ServiceEndpoint.AccessPoint;
import org.gcube.common.scope.api.ScopeProvider;
import org.gcube.resources.discovery.client.api.DiscoveryClient;
import org.gcube.resources.discovery.client.queries.api.SimpleQuery;
public class DefaultKeycloakClient implements KeycloakClient {
private static final String PERMISSION_PARAMETER = "permission";
private static final String GRANT_TYPE_PARAMETER = "grant_type";
private static final String UMA_TOKEN_GRANT_TYPE = "urn:ietf:params:oauth:grant-type:uma-ticket";
private static final String AUDIENCE_PARAMETER = "audience";
public URL findTokenEndpointURL() throws KeycloakClientException {
logger.debug("Creating simple query");
SimpleQuery query = queryFor(ServiceEndpoint.class);
String.format("$resource/Profile/Category/text() eq '%s'", CATEGORY))
.addCondition(String.format("$resource/Profile/Name/text() eq '%s'", NAME))
.setResult(String.format("$resource/Profile/AccessPoint[Description/text() eq '%s']", DESCRIPTION));
logger.debug("Creating client for AccessPoint");
DiscoveryClient<AccessPoint> client = clientFor(AccessPoint.class);
logger.trace("Submitting query: {}", query);
List<AccessPoint> accessPoints = client.submit(query);
if (accessPoints.size() == 0) {
throw new KeycloakClientException("Service endpoint not found");
} else if (accessPoints.size() > 1) {
throw new KeycloakClientException("Found more than one endpoint with query");
String address = accessPoints.iterator().next().address();
logger.debug("Found address: {}", address);
try {
return new URL(address);
} catch (MalformedURLException e) {
throw new KeycloakClientException("Cannot create URL from address: " + address, e);
public TokenResponse queryUMAToken(String clientId, String clientSecret, List<String> permissions)
throws KeycloakClientException {
return queryUMAToken(clientId, clientSecret, ScopeProvider.instance.get(), permissions);
public TokenResponse queryUMAToken(String clientId, String clientSecret, String audience,
List<String> permissions) throws KeycloakClientException {
return queryUMAToken(findTokenEndpointURL(), clientId, clientSecret, audience, permissions);
public TokenResponse queryUMAToken(URL tokenURL, String clientId, String clientSecret, String audience,
List<String> permissions) throws KeycloakClientException {
return queryUMAToken(tokenURL,
"Basic " + Base64.getEncoder().encodeToString((clientId + ":" + clientSecret).getBytes()),
audience, permissions);
public TokenResponse queryUMAToken(URL tokenURL, String authorization, String audience,
List<String> permissions) throws KeycloakClientException {
logger.debug("Querying token from Keycloak server with URL: {}", tokenURL);
Map<String, List<String>> params = new HashMap<>();
try {
params.put(AUDIENCE_PARAMETER, Arrays.asList(URLEncoder.encode(checkAudience(audience), "UTF-8")));
} catch (UnsupportedEncodingException e) {
logger.error("Cannot URL encode 'audience'", e);
if (permissions != null && !permissions.isEmpty()) {
try {
return URLEncoder.encode(s, "UTF-8");
} catch (UnsupportedEncodingException e) {
return "";
// Constructing request object
GXHTTPStringRequest request;
try {
String queryString = params.entrySet().stream()
.flatMap(p -> p.getValue().stream().map(v -> p.getKey() + "=" + v))
.reduce((p1, p2) -> p1 + "&" + p2).orElse("");
request = GXHTTPStringRequest.newRequest(tokenURL.toString())
.header("Content-Type", "application/x-www-form-urlencoded").withBody(queryString);
if (authorization != null) {
logger.debug("Adding authorization header as: {}", authorization);
request = request.header("Authorization", authorization);
} catch (Exception e) {
throw new KeycloakClientException("Cannot construct the request object correctly", e);
GXInboundResponse response;
try {
response =;
} catch (Exception e) {
throw new KeycloakClientException("Cannot send request correctly", e);
if (response.isSuccessResponse()) {
try {
return response.tryConvertStreamedContentFromJson(TokenResponse.class);
} catch (Exception e) {
throw new KeycloakClientException("Cannot construct token response object correctly", e);
} else {
throw KeycloakClientException.create("Unable to get token", response.getHTTPCode(),
.getOrDefault("Content-Type", Collections.singletonList("unknown/unknown")).get(0),
private static String checkAudience(String audience) {
if (audience.startsWith("/")) {
try {
logger.trace("Audience was provided in non URL encoded form, encoding it");
return URLEncoder.encode(audience, "UTF-8");
} catch (UnsupportedEncodingException e) {
logger.error("Cannot URL encode 'audience'", e);
return audience;

@ -0,0 +1,82 @@
package org.gcube.common.keycloak;
import java.util.List;
import org.gcube.common.keycloak.model.TokenResponse;
import org.gcube.common.scope.api.ScopeProvider;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public interface KeycloakClient {
Logger logger = LoggerFactory.getLogger(KeycloakClient.class);
String CATEGORY = "Auth";
String NAME = "IAM";
String DESCRIPTION = "oidc-token endpoint";
* Finds the keycloak endpoint {@link URL} discovering it in the current scope provided by {@link ScopeProvider}
* @return the keycloak endpoint URL in the current scope
* @throws KeycloakClientException if something goes wrong discovering the endpoint URL
URL findTokenEndpointURL() throws KeycloakClientException;
* Queries an UMA token from the Keycloak server, by using provided authorization, for the given audience (context),
* in URLEncoded form or not, and optionally a list of permissions.
* @param tokenUrl the token endpoint {@link URL} of the OIDC server
* @param authorization the authorization to be set as header (e.g. a "Basic ...." auth or an encoded JWT access token preceded by the "Bearer " string)
* @param audience the audience (context) where to request the issuing of the ticket (URLEncoded)
* @param permissions a list of permissions, can be <code>null</code>
* @return the issued token as {@link TokenResponse} object
* @throws KeycloakClientException if something goes wrong performing the query
TokenResponse queryUMAToken(URL tokenURL, String authorization, String audience, List<String> permissions)
throws KeycloakClientException;
* Queries an UMA token from the Keycloak server, by using provided clientId and client secret for the given audience
* (context), in URLEncoded form or not, and optionally a list of permissions.
* @param tokenURL the token endpoint {@link URL} of the Keycloak server
* @param clientId the client id
* @param clientSecret the client secret
* @param audience the audience (context) where to request the issuing of the ticket
* @param permissions a list of permissions, can be <code>null</code>
* @return the issued token as {@link TokenResponse} object
* @throws KeycloakClientException if something goes wrong performing the query
TokenResponse queryUMAToken(URL tokenURL, String clientId, String clientSecret, String audience,
List<String> permissions)
throws KeycloakClientException;
* Queries an UMA token from the discovered Keycloak server in the current scope, by using provided clientId and client secret
* for the given audience (context), in URLEncoded form or not, and optionally a list of permissions.
* @param clientId the client id
* @param clientSecret the client secret
* @param audience the audience (context) where to request the issuing of the ticket
* @param permissions a list of permissions, can be <code>null</code>
* @return the issued token as {@link TokenResponse} object
* @throws KeycloakClientException if something goes wrong performing the query
TokenResponse queryUMAToken(String clientId, String clientSecret, String audience, List<String> permissions)
throws KeycloakClientException;
* Queries an UMA token from the discovered Keycloak server in the current scope, by using provided clientId and client secret
* for the current scope audience (context), in URLEncoded form or not, and optionally a list of permissions.
* @param clientId the client id
* @param clientSecret the client secret
* @param permissions a list of permissions, can be <code>null</code>
* @return the issued token as {@link TokenResponse} object
* @throws KeycloakClientException if something goes wrong performing the query
TokenResponse queryUMAToken(String clientId, String clientSecret, List<String> permissions)
throws KeycloakClientException;

@ -0,0 +1,70 @@
package org.gcube.common.keycloak;
public class KeycloakClientException extends Exception {
private static final long serialVersionUID = -1615745541003534684L;
private int status = -1;
private String contentType = null;
private String responseString = null;
public static KeycloakClientException create(String message, int status, String contentType,
String textResponse) {
return create(message, status, contentType, textResponse, null);
public static KeycloakClientException create(String message, int status, String contentType,
String textResponse, Exception cause) {
String exMessage = "[" + status + "] " + message + " (" + contentType + "): " + textResponse;
KeycloakClientException e = cause != null ? new KeycloakClientException(exMessage, cause)
: new KeycloakClientException(exMessage);
return e;
public KeycloakClientException() {
public KeycloakClientException(String message) {
public KeycloakClientException(String message, Exception cause) {
super(message, cause);
public void setStatus(int status) {
this.status = status;
public int getStatus() {
return status;
public void setContentType(String contentType) {
this.contentType = contentType;
public String getContentType() {
return contentType;
public boolean hasJSONPayload() {
return getContentType().endsWith("json");
public void setResponseString(String responseString) {
this.responseString = responseString;
public String getResponseString() {
return responseString;

@ -0,0 +1,15 @@
package org.gcube.common.keycloak;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class KeycloakClientFactory {
protected static final Logger logger = LoggerFactory.getLogger(KeycloakClientFactory.class);
public static KeycloakClient newInstance() {
logger.debug("Instantiating a new keycloak client instance");
return new DefaultKeycloakClient();

@ -0,0 +1,154 @@
package org.gcube.common.keycloak.model;
import java.util.Collections;
import java.util.HashMap;
import java.util.HashSet;
import java.util.Map;
import java.util.Set;
public class AccessToken extends IDToken {
private static final long serialVersionUID = 6364784008775737335L;
public static class Access implements Serializable {
private static final long serialVersionUID = 1634782115467850693L;
protected Set<String> roles;
protected Boolean verifyCaller;
public Access() {
public Access clone() {
Access access = new Access();
access.verifyCaller = verifyCaller;
if (roles != null) {
access.roles = new HashSet<>();
return access;
public Set<String> getRoles() {
return roles;
public Access roles(Set<String> roles) {
this.roles = roles;
return this;
public boolean isUserInRole(String role) {
if (roles == null)
return false;
return roles.contains(role);
public Access addRole(String role) {
if (roles == null)
roles = new HashSet<>();
return this;
public Boolean getVerifyCaller() {
return verifyCaller;
public Access verifyCaller(Boolean required) {
this.verifyCaller = required;
return this;
protected Set<String> trustedCertificates;
protected Set<String> allowedOrigins;
protected Access realmAccess;
protected Map<String, Access> resourceAccess;
protected String scope;
public Map<String, Access> getResourceAccess() {
return resourceAccess == null ? Collections.<String, Access>emptyMap() : resourceAccess;
public void setResourceAccess(Map<String, Access> resourceAccess) {
this.resourceAccess = resourceAccess;
public Access addAccess(String service) {
if (resourceAccess == null) {
resourceAccess = new HashMap<>();
Access access = resourceAccess.get(service);
if (access != null)
return access;
access = new Access();
resourceAccess.put(service, access);
return access;
public AccessToken id(String id) {
return (AccessToken);
public AccessToken issuer(String issuer) {
return (AccessToken) super.issuer(issuer);
public AccessToken subject(String subject) {
return (AccessToken) super.subject(subject);
public AccessToken type(String type) {
return (AccessToken) super.type(type);
public Set<String> getAllowedOrigins() {
return allowedOrigins;
public void setAllowedOrigins(Set<String> allowedOrigins) {
this.allowedOrigins = allowedOrigins;
public Access getRealmAccess() {
return realmAccess;
public void setRealmAccess(Access realmAccess) {
this.realmAccess = realmAccess;
public Set<String> getTrustedCertificates() {
return trustedCertificates;
public void setTrustedCertificates(Set<String> trustedCertificates) {
this.trustedCertificates = trustedCertificates;

@ -0,0 +1,80 @@
package org.gcube.common.keycloak.model;
public class AddressClaimSet {
public static final String FORMATTED = "formatted";
public static final String STREET_ADDRESS = "street_address";
public static final String LOCALITY = "locality";
public static final String REGION = "region";
public static final String POSTAL_CODE = "postal_code";
public static final String COUNTRY = "country";
protected String formattedAddress;
protected String streetAddress;
protected String locality;
protected String region;
protected String postalCode;
protected String country;
public String getFormattedAddress() {
return this.formattedAddress;
public void setFormattedAddress(String formattedAddress) {
this.formattedAddress = formattedAddress;
public String getStreetAddress() {
return this.streetAddress;
public void setStreetAddress(String streetAddress) {
this.streetAddress = streetAddress;
public String getLocality() {
return this.locality;
public void setLocality(String locality) {
this.locality = locality;
public String getRegion() {
return this.region;
public void setRegion(String region) {
this.region = region;
public String getPostalCode() {
return this.postalCode;
public void setPostalCode(String postalCode) {
this.postalCode = postalCode;
public String getCountry() {
public void setCountry(String country) { = country;

@ -0,0 +1,337 @@
package org.gcube.common.keycloak.model;
public class IDToken extends JsonWebToken {
private static final long serialVersionUID = 8406175387651749097L;
public static final String NONCE = "nonce";
public static final String AUTH_TIME = "auth_time";
public static final String SESSION_STATE = "session_state";
public static final String AT_HASH = "at_hash";
public static final String C_HASH = "c_hash";
public static final String NAME = "name";
public static final String GIVEN_NAME = "given_name";
public static final String FAMILY_NAME = "family_name";
public static final String MIDDLE_NAME = "middle_name";
public static final String NICKNAME = "nickname";
public static final String PREFERRED_USERNAME = "preferred_username";
public static final String PROFILE = "profile";
public static final String PICTURE = "picture";
public static final String WEBSITE = "website";
public static final String EMAIL = "email";
public static final String EMAIL_VERIFIED = "email_verified";
public static final String GENDER = "gender";
public static final String BIRTHDATE = "birthdate";
public static final String ZONEINFO = "zoneinfo";
public static final String LOCALE = "locale";
public static final String PHONE_NUMBER = "phone_number";
public static final String PHONE_NUMBER_VERIFIED = "phone_number_verified";
public static final String ADDRESS = "address";
public static final String UPDATED_AT = "updated_at";
public static final String CLAIMS_LOCALES = "claims_locales";
public static final String ACR = "acr";
public static final String S_HASH = "s_hash";
public IDToken() {
protected String nonce;
protected Long auth_time;
protected String sessionState;
protected String accessTokenHash;
protected String codeHash;
protected String name;
protected String givenName;
protected String familyName;
protected String middleName;
protected String nickName;
protected String preferredUsername;
protected String profile;
protected String picture;
protected String website;
protected String email;
protected Boolean emailVerified;
protected String gender;
protected String birthdate;
protected String zoneinfo;
protected String locale;
protected String phoneNumber;
protected Boolean phoneNumberVerified;
protected AddressClaimSet address;
protected Long updatedAt;
protected String claimsLocales;
protected String acr;
protected String stateHash;
public String getNonce() {
return nonce;
public void setNonce(String nonce) {
this.nonce = nonce;
public Long getAuth_time() {
return auth_time;
public void setAuth_time(Long auth_time) {
this.auth_time = auth_time;
public String getSessionState() {
return sessionState;
public void setSessionState(String sessionState) {
this.sessionState = sessionState;
public String getAccessTokenHash() {
return accessTokenHash;
public void setAccessTokenHash(String accessTokenHash) {
this.accessTokenHash = accessTokenHash;
public String getCodeHash() {
return codeHash;
public void setCodeHash(String codeHash) {
this.codeHash = codeHash;
public String getName() {
public void setName(String name) { = name;
public String getGivenName() {
return this.givenName;
public void setGivenName(String givenName) {
this.givenName = givenName;
public String getFamilyName() {
return this.familyName;
public void setFamilyName(String familyName) {
this.familyName = familyName;
public String getMiddleName() {
return this.middleName;
public void setMiddleName(String middleName) {
this.middleName = middleName;
public String getNickName() {
return this.nickName;
public void setNickName(String nickName) {
this.nickName = nickName;
public String getPreferredUsername() {
return this.preferredUsername;
public void setPreferredUsername(String preferredUsername) {
this.preferredUsername = preferredUsername;
public String getProfile() {
return this.profile;
public void setProfile(String profile) {
this.profile = profile;
public String getPicture() {
return this.picture;
public void setPicture(String picture) {
this.picture = picture;
public String getWebsite() {
public void setWebsite(String website) { = website;
public String getEmail() {
public void setEmail(String email) { = email;
public Boolean getEmailVerified() {
return this.emailVerified;
public void setEmailVerified(Boolean emailVerified) {
this.emailVerified = emailVerified;
public String getGender() {
return this.gender;
public void setGender(String gender) {
this.gender = gender;
public String getBirthdate() {
return this.birthdate;
public void setBirthdate(String birthdate) {
this.birthdate = birthdate;
public String getZoneinfo() {
return this.zoneinfo;
public void setZoneinfo(String zoneinfo) {
this.zoneinfo = zoneinfo;
public String getLocale() {
return this.locale;
public void setLocale(String locale) {
this.locale = locale;
public String getPhoneNumber() {
return this.phoneNumber;
public void setPhoneNumber(String phoneNumber) {
this.phoneNumber = phoneNumber;
public Boolean getPhoneNumberVerified() {
return this.phoneNumberVerified;
public void setPhoneNumberVerified(Boolean phoneNumberVerified) {
this.phoneNumberVerified = phoneNumberVerified;
public AddressClaimSet getAddress() {
return address;
public void setAddress(AddressClaimSet address) {
this.address = address;
public Long getUpdatedAt() {
return this.updatedAt;
public void setUpdatedAt(Long updatedAt) {
this.updatedAt = updatedAt;
public String getClaimsLocales() {
return this.claimsLocales;
public void setClaimsLocales(String claimsLocales) {
this.claimsLocales = claimsLocales;
public String getAcr() {
return acr;
public void setAcr(String acr) {
this.acr = acr;
public String getStateHash() {
return stateHash;
public void setStateHash(String stateHash) {
this.stateHash = stateHash;

@ -0,0 +1,211 @@
package org.gcube.common.keycloak.model;
import java.util.Arrays;
import java.util.HashMap;
import java.util.Map;
import org.gcube.common.keycloak.model.util.StringOrArrayDeserializer;
import org.gcube.common.keycloak.model.util.StringOrArraySerializer;
import org.gcube.common.keycloak.model.util.Time;
public class JsonWebToken implements Serializable {
private static final long serialVersionUID = -8136409077130940942L;
protected String id;
protected Long exp;
protected Long nbf;
protected Long iat;
protected String issuer;
@JsonSerialize(using = StringOrArraySerializer.class)
@JsonDeserialize(using = StringOrArrayDeserializer.class)
protected String[] audience;
protected String subject;
protected String type;
public String issuedFor;
protected Map<String, Object> otherClaims = new HashMap<>();
public String getId() {
return id;
public JsonWebToken id(String id) { = id;
return this;
public Long getExp() {
return exp;
public JsonWebToken exp(Long exp) {
this.exp = exp;
return this;
public boolean isExpired() {
return exp != null && exp != 0 ? Time.currentTime() > exp : false;
public Long getNbf() {
return nbf;
public JsonWebToken nbf(Long nbf) {
this.nbf = nbf;
return this;
public boolean isNotBefore(int allowedTimeSkew) {
return nbf != null ? Time.currentTime() + allowedTimeSkew >= nbf : true;
* Tests that the token is not expired and is not-before.
* @return
public boolean isActive() {
return isActive(0);
public boolean isActive(int allowedTimeSkew) {
return !isExpired() && isNotBefore(allowedTimeSkew);
public Long getIat() {
return iat;
* Set issuedAt to the current time
public JsonWebToken issuedNow() {
iat = Long.valueOf(Time.currentTime());
return this;
public JsonWebToken iat(Long iat) {
this.iat = iat;
return this;
public String getIssuer() {
return issuer;
public JsonWebToken issuer(String issuer) {
this.issuer = issuer;
return this;
public String[] getAudience() {
return audience;
public boolean hasAudience(String audience) {
if (this.audience == null)
return false;
for (String a : this.audience) {
if (a.equals(audience)) {
return true;
return false;
public JsonWebToken audience(String... audience) {
this.audience = audience;
return this;
public JsonWebToken addAudience(String audience) {
if (this.audience == null) {
this.audience = new String[] { audience };
} else {
// Check if audience is already there
for (String aud : this.audience) {
if (audience.equals(aud)) {
return this;
String[] newAudience = Arrays.copyOf(this.audience, this.audience.length + 1);
newAudience[this.audience.length] = audience;
this.audience = newAudience;
return this;
public String getSubject() {
return subject;
public JsonWebToken subject(String subject) {
this.subject = subject;
return this;
public void setSubject(String subject) {
this.subject = subject;
public String getType() {
return type;
public JsonWebToken type(String type) {
this.type = type;
return this;
* OAuth client the token was issued for.
* @return
public String getIssuedFor() {
return issuedFor;
public JsonWebToken issuedFor(String issuedFor) {
this.issuedFor = issuedFor;
return this;
* This is a map of any other claims and data that might be in the IDToken. Could be custom claims set up by the auth server
* @return
public Map<String, Object> getOtherClaims() {
return otherClaims;
public void setOtherClaims(String name, Object value) {
otherClaims.put(name, value);

@ -0,0 +1,97 @@
package org.gcube.common.keycloak.model;
import java.util.Base64;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class ModelUtils {
protected static final Logger logger = LoggerFactory.getLogger(ModelUtils.class);
private static final ObjectMapper mapper = new ObjectMapper();
static {
public static String toJSONString(Object object) {
return toJSONString(object, false);
public static String toJSONString(Object object, boolean prettyPrint) {
ObjectWriter writer = prettyPrint ? mapper.writerWithDefaultPrettyPrinter() : mapper.writer();
try {
return writer.writeValueAsString(object);
} catch (JsonProcessingException e) {
logger.error("Cannot pretty print object", e);
return null;
private static byte[] getDecodedPayload(String value) {
return getBase64Decoded(getEncodedPayload(value));
public static String getAccessTokenPayloadStringFrom(TokenResponse tokenResponse) throws Exception {
return getAccessTokenPayloadStringFrom(tokenResponse, true);
public static String getAccessTokenPayloadStringFrom(TokenResponse tokenResponse, boolean prettyPrint) throws Exception {
return toJSONString(getAccessTokenFrom(tokenResponse, Object.class), prettyPrint);
public static AccessToken getAccessTokenFrom(TokenResponse tokenResponse) throws Exception {
return getAccessTokenFrom(tokenResponse, RefreshToken.class);
private static <T> T getAccessTokenFrom(TokenResponse tokenResponse, Class<T> clazz) throws Exception {
return mapper.readValue(getDecodedPayload(tokenResponse.getAccessToken()), clazz);
public static String getRefreshTokenPayloadStringFrom(TokenResponse tokenResponse) throws Exception {
return getRefreshTokenPayloadStringFrom(tokenResponse, true);
public static String getRefreshTokenPayloadStringFrom(TokenResponse tokenResponse, boolean prettyPrint) throws Exception {
return toJSONString(getRefreshTokenFrom(tokenResponse, Object.class), prettyPrint);
public static RefreshToken getRefreshTokenFrom(TokenResponse tokenResponse) throws Exception {
return getRefreshTokenFrom(tokenResponse, RefreshToken.class);
private static <T> T getRefreshTokenFrom(TokenResponse tokenResponse, Class<T> clazz) throws Exception {
return mapper.readValue(getDecodedPayload(tokenResponse.getRefreshToken()), clazz);
protected static byte[] getBase64Decoded(String string) {
return Base64.getDecoder().decode(string);
protected static String splitAndGet(String encodedJWT, int index) {
String[] split = encodedJWT.split("\\.");
if (split.length == 3) {
return split[index];
} else {
return null;
public static String getEncodedHeader(String encodedJWT) {
return splitAndGet(encodedJWT, 0);
public static String getEncodedPayload(String encodedJWT) {
return splitAndGet(encodedJWT, 1);
public static String getEncodedSignature(String encodedJWT) {
return splitAndGet(encodedJWT, 2);

@ -0,0 +1,21 @@
package org.gcube.common.keycloak.model;
public class RefreshToken extends AccessToken {
private static final long serialVersionUID = 2646534143077862960L;
public RefreshToken() {
public RefreshToken(AccessToken token) {
this.issuer = token.issuer;
this.subject = token.subject;
this.issuedFor = token.issuedFor;
this.sessionState = token.sessionState;
this.nonce = token.nonce;
this.audience = new String[] { token.issuer };
this.scope = token.scope;

@ -0,0 +1,133 @@
package org.gcube.common.keycloak.model;
import java.util.HashMap;
import java.util.Map;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class TokenResponse implements Serializable {
protected static Logger logger = LoggerFactory.getLogger(TokenResponse.class);
private static final long serialVersionUID = -7063122428186284827L;
protected String accessToken;
protected long expiresIn;
protected long refreshExpiresIn;
protected String refreshToken;
protected String tokenType;
protected String idToken;
protected int notBeforePolicy;
protected String sessionState;
protected Map<String, Object> otherClaims = new HashMap<>();
protected String scope;
public TokenResponse() {
public String getScope() {
return scope;
public void setScope(String scope) {
this.scope = scope;
public String getAccessToken() {
return accessToken;
public void setSccessToken(String accessToken) {
this.accessToken = accessToken;
public long getExpiresIn() {
return expiresIn;
public void setExpiresIn(long expiresIn) {
this.expiresIn = expiresIn;
public long getRefreshExpiresIn() {
return refreshExpiresIn;
public void setRefreshExpiresIn(long refreshExpiresIn) {
this.refreshExpiresIn = refreshExpiresIn;
public String getRefreshToken() {
return refreshToken;
public void setRefreshToken(String refreshToken) {
this.refreshToken = refreshToken;
public String getTokenType() {
return tokenType;
public void setTokenType(String tokenType) {
this.tokenType = tokenType;
public String getIdToken() {
return idToken;
public void setIdToken(String idToken) {
this.idToken = idToken;
public int getNotBeforePolicy() {
return notBeforePolicy;
public void setNotBeforePolicy(int notBeforePolicy) {
this.notBeforePolicy = notBeforePolicy;
public String getSessionState() {
return sessionState;
public void setSessionState(String sessionState) {
this.sessionState = sessionState;
public Map<String, Object> getOtherClaims() {
return otherClaims;
public void setOtherClaims(String name, Object value) {
otherClaims.put(name, value);

@ -0,0 +1,309 @@
package org.gcube.common.keycloak.model;
import java.util.HashMap;
import java.util.Map;
import org.gcube.common.keycloak.model.util.StringOrArrayDeserializer;
import org.gcube.common.keycloak.model.util.StringOrArraySerializer;
* @author pedroigor
public class UserInfo {
// Should be in signed UserInfo response
protected String issuer;
@JsonSerialize(using = StringOrArraySerializer.class)
@JsonDeserialize(using = StringOrArrayDeserializer.class)
protected String[] audience;
protected String sub;
protected String name;
protected String givenName;
protected String familyName;
protected String middleName;
protected String nickName;
protected String preferredUsername;
protected String profile;
protected String picture;
protected String website;
protected String email;
protected Boolean emailVerified;
protected String gender;
protected String birthdate;
protected String zoneinfo;
protected String locale;
protected String phoneNumber;
protected Boolean phoneNumberVerified;
protected AddressClaimSet address;
protected Long updatedAt;
protected String claimsLocales;
protected Map<String, Object> otherClaims = new HashMap<>();
public String getIssuer() {
return issuer;
public void setIssuer(String issuer) {
this.issuer = issuer;
public String[] getAudience() {
return audience;
public boolean hasAudience(String audience) {
for (String a : this.audience) {
if (a.equals(audience)) {
return true;
return false;
public void setAudience(String... audience) {
this.audience = audience;
public String getSubject() {
return this.sub;
public void setSubject(String subject) {
this.sub = subject;
public String getName() {
public void setName(String name) { = name;
public String getGivenName() {
return this.givenName;
public void setGivenName(String givenName) {
this.givenName = givenName;
public String getFamilyName() {
return this.familyName;
public void setFamilyName(String familyName) {
this.familyName = familyName;
public String getMiddleName() {
return this.middleName;
public void setMiddleName(String middleName) {
this.middleName = middleName;
public String getNickName() {
return this.nickName;
public void setNickName(String nickName) {
this.nickName = nickName;
public String getPreferredUsername() {
return this.preferredUsername;
public void setPreferredUsername(String preferredUsername) {
this.preferredUsername = preferredUsername;
public String getProfile() {
return this.profile;
public void setProfile(String profile) {
this.profile = profile;
public String getPicture() {
return this.picture;
public void setPicture(String picture) {
this.picture = picture;
public String getWebsite() {
public void setWebsite(String website) { = website;
public String getEmail() {
public void setEmail(String email) { = email;
public Boolean getEmailVerified() {
return this.emailVerified;
public void setEmailVerified(Boolean emailVerified) {
this.emailVerified = emailVerified;
public String getGender() {
return this.gender;
public void setGender(String gender) {
this.gender = gender;
public String getBirthdate() {
return this.birthdate;
public void setBirthdate(String birthdate) {
this.birthdate = birthdate;
public String getZoneinfo() {
return this.zoneinfo;
public void setZoneinfo(String zoneinfo) {
this.zoneinfo = zoneinfo;
public String getLocale() {
return this.locale;
public void setLocale(String locale) {
this.locale = locale;
public String getPhoneNumber() {
return this.phoneNumber;
public void setPhoneNumber(String phoneNumber) {
this.phoneNumber = phoneNumber;
public Boolean getPhoneNumberVerified() {
return this.phoneNumberVerified;
public void setPhoneNumberVerified(Boolean phoneNumberVerified) {
this.phoneNumberVerified = phoneNumberVerified;
public AddressClaimSet getAddress() {
return address;
public void setAddress(AddressClaimSet address) {
this.address = address;
public Long getUpdatedAt() {
return this.updatedAt;
public void setUpdatedAt(Long updatedAt) {
this.updatedAt = updatedAt;
public String getSub() {
return this.sub;
public void setSub(String sub) {
this.sub = sub;
public String getClaimsLocales() {
return this.claimsLocales;
public void setClaimsLocales(String claimsLocales) {
this.claimsLocales = claimsLocales;
* This is a map of any other claims and data that might be in the UserInfo. Could be custom claims set up by the auth server
* @return
public Map<String, Object> getOtherClaims() {
return otherClaims;
public void setOtherClaims(String name, Object value) {
otherClaims.put(name, value);

@ -0,0 +1,41 @@
package org.gcube.common.keycloak.model.util;
import java.util.HashMap;
import java.util.Iterator;
import java.util.LinkedList;
import java.util.List;
import java.util.Map;
public class StringListMapDeserializer extends JsonDeserializer<Object> {
public Object deserialize(JsonParser jsonParser, DeserializationContext deserializationContext) throws IOException {
JsonNode jsonNode = jsonParser.readValueAsTree();
Iterator<Map.Entry<String, JsonNode>> itr = jsonNode.fields();
Map<String, List<String>> map = new HashMap<>();
while (itr.hasNext()) {
Map.Entry<String, JsonNode> e =;
List<String> values = new LinkedList<>();
if (!e.getValue().isArray()) {
values.add((e.getValue().isNull()) ? null : e.getValue().asText());
} else {
ArrayNode a = (ArrayNode) e.getValue();
Iterator<JsonNode> vitr = a.elements();
while (vitr.hasNext()) {
JsonNode node =;
values.add((node.isNull() ? null : node.asText()));
map.put(e.getKey(), values);
return map;

@ -0,0 +1,29 @@
package org.gcube.common.keycloak.model.util;
import java.util.ArrayList;
import java.util.Iterator;
public class StringOrArrayDeserializer extends JsonDeserializer<Object> {
public Object deserialize(JsonParser jsonParser, DeserializationContext deserializationContext) throws IOException {
JsonNode jsonNode = jsonParser.readValueAsTree();
if (jsonNode.isArray()) {
ArrayList<String> a = new ArrayList<>(1);
Iterator<JsonNode> itr = jsonNode.iterator();
while (itr.hasNext()) {
return a.toArray(new String[a.size()]);
} else {
return new String[] { jsonNode.textValue() };

@ -0,0 +1,25 @@
package org.gcube.common.keycloak.model.util;
public class StringOrArraySerializer extends JsonSerializer<Object> {
public void serialize(Object o, JsonGenerator jsonGenerator, SerializerProvider serializerProvider) throws IOException {
String[] array = (String[]) o;
if (array == null) {
} else if (array.length == 1) {
} else {
for (String s : array) {

@ -0,0 +1,67 @@
package org.gcube.common.keycloak.model.util;
import java.util.Date;
public class Time {
private static int offset;
* Returns current time in seconds adjusted by adding {@link #offset) seconds.
* @return see description
public static int currentTime() {
return ((int) (System.currentTimeMillis() / 1000)) + offset;
* Returns current time in milliseconds adjusted by adding {@link #offset) seconds.
* @return see description
public static long currentTimeMillis() {
return System.currentTimeMillis() + (offset * 1000L);
* Returns {@link Date} object, its value set to time
* @param time Time in milliseconds since the epoch
* @return see description
public static Date toDate(int time) {
return new Date(time * 1000L);
* Returns {@link Date} object, its value set to time
* @param time Time in milliseconds since the epoch
* @return see description
public static Date toDate(long time) {
return new Date(time);
* Returns time in milliseconds for a time in seconds. No adjustment is made to the parameter.
* @param time Time in seconds since the epoch
* @return Time in milliseconds
public static long toMillis(int time) {
return time * 1000L;
* @return Time offset in seconds that will be added to {@link #currentTime()} and {@link #currentTimeMillis()}.
public static int getOffset() {
return offset;
* Sets time offset in seconds that will be added to {@link #currentTime()} and {@link #currentTimeMillis()}.
* @param offset Offset (in seconds)
public static void setOffset(int offset) {
Time.offset = offset;

@ -0,0 +1,69 @@
package org.gcube.common.keycloak;
import org.gcube.common.keycloak.model.ModelUtils;
import org.gcube.common.keycloak.model.TokenResponse;
import org.gcube.common.scope.api.ScopeProvider;
import org.junit.After;
import org.junit.Assert;
import org.junit.Before;
import org.junit.Test;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class TestKeycloakClient {
protected static final Logger logger = LoggerFactory.getLogger(TestKeycloakClient.class);
private static final String DEV_ENDPOINT = "";
private static final String CLIENT_ID = "keycloak-client";
private static final String CLIENT_SECRET = "38f76152-2b7c-418f-9b67-66f4cc2f401e";
private static final String TEST_AUDIENCE = "conductor-server";
public void setUp() throws Exception {
public void tearDown() throws Exception {
public void testEndpointDiscovery() throws Exception {"Start testing Keycloak endpoint discovery...");
URL url = KeycloakClientFactory.newInstance().findTokenEndpointURL();
public void testQueryUMATokenWithDiscoveryInCurrentScope() throws Exception {"Start testing query UMA token from Keycloak with endpoint discovery and current scope...");
TokenResponse tr = KeycloakClientFactory.newInstance().queryUMAToken(CLIENT_ID, CLIENT_SECRET, null);
TestModels.checkAccessToken(ModelUtils.getAccessTokenFrom(tr), "service-account-" + CLIENT_ID);
public void testQueryUMATokenWithDiscovery() throws Exception {"Start testing query UMA token from Keycloak with endpoint discovery...");
TokenResponse tr = KeycloakClientFactory.newInstance().queryUMAToken(CLIENT_ID, CLIENT_SECRET, TEST_AUDIENCE,
TestModels.checkAccessToken(ModelUtils.getAccessTokenFrom(tr), "service-account-" + CLIENT_ID);
public void testQueryUMAToken() throws Exception {"Start testing query UMA token from Keycloak with URL...");
TokenResponse tr = KeycloakClientFactory.newInstance()
TestModels.checkAccessToken(ModelUtils.getAccessTokenFrom(tr), "service-account-" + CLIENT_ID);

@ -0,0 +1,89 @@
package org.gcube.common.keycloak;
import org.gcube.common.keycloak.model.TokenResponse;
import org.gcube.common.keycloak.model.AccessToken;
import org.gcube.common.keycloak.model.ModelUtils;
import org.gcube.common.keycloak.model.RefreshToken;
import org.junit.After;
import org.junit.Assert;
import org.junit.Before;
import org.junit.Test;
import org.slf4j.Logger;
import org.slf4j.LoggerFactory;
public class TestModels {
protected static final Logger logger = LoggerFactory.getLogger(TestModels.class);
public void setUp() throws Exception {
public void tearDown() throws Exception {
public void testTokenResponseForOIDC() throws Exception {"Start testing OIDC token response object binding...");
TokenResponse tr = new ObjectMapper().readValue(new File("src/test/resources/oidc-token-response.json"),
logger.debug("OIDC token response:\n{}", ModelUtils.toJSONString(tr, true));
public void testTokenResponseForUMA() throws Exception {"Start testing UMA token response object binding...");
TokenResponse tr = new ObjectMapper().readValue(new File("src/test/resources/uma-token-response.json"),
logger.debug("UMA token response:\n{}", ModelUtils.toJSONString(tr, true));
public void testUMAAccessToken() throws Exception {"Start testing access token object binding...");
AccessToken at = new ObjectMapper().readValue(new File("src/test/resources/uma-access-token.json"),
checkAccessToken(at, null);
public void testUMARefreshToken() throws Exception {"Start testing refresh token object binding...");
RefreshToken rt = new ObjectMapper().readValue(new File("src/test/resources/uma-refresh-token.json"),
public static void checkTokenResponse(TokenResponse tr) throws Exception {
Assert.assertEquals("bearer", tr.getTokenType().toLowerCase());
public static void checkAccessToken(AccessToken at, String preferredUsername) {
logger.debug("Access token:\n{}", ModelUtils.toJSONString(at, true));
if (preferredUsername != null) {
Assert.assertEquals(preferredUsername, at.getPreferredUsername());
public static void checkRefreshToken(RefreshToken rt) {
logger.debug("Refresh token:\n{}", ModelUtils.toJSONString(rt, true));

@ -0,0 +1,10 @@
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJSSklZNEpoNF9qdDdvNmREY0NlUDFfS1l0akcxVExXVW9oMkQ2Tzk1bFNBIn0.eyJleHAiOjE2MjIyMTYxNjEsImlhdCI6MTYyMjIxNTg2MSwianRpIjoiZDM5MWQ4MTQtYTFmNi00YTQwLTlhYTMtM2Y1MWVjNTk5ODhjIiwiaXNzIjoiaHR0cHM6Ly9hY2NvdW50cy5kZXYuZDRzY2llbmNlLm9yZy9hdXRoL3JlYWxtcy9kNHNjaWVuY2UiLCJhdWQiOiJhY2NvdW50Iiwic3ViIjoiMWM4NDEwOGEtMjAxZC00ZTIwLThhZDItZDcyYjA4ZDU4ZjhhIiwidHlwIjoiQmVhcmVyIiwiYXpwIjoibHI2Ml9wb3J0YWwiLCJzZXNzaW9uX3N0YXRlIjoiMWEwNTRiYjctNGQ4Ny00NGE5LWFkMWYtMTc0NmVmMmRkNTIyIiwiYWNyIjoiMSIsImFsbG93ZWQtb3JpZ2lucyI6WyJodHRwczovL2Rldi5kNHNjaWVuY2Uub3JnIl0sInJlYWxtX2FjY2VzcyI6eyJyb2xlcyI6WyJvZmZsaW5lX2FjY2VzcyIsIkluZnJhc3RydWN0dXJlLUNsaWVudCIsInVtYV9hdXRob3JpemF0aW9uIl19LCJyZXNvdXJjZV9hY2Nlc3MiOnsiYWNjb3VudCI6eyJyb2xlcyI6WyJtYW5hZ2UtYWNjb3VudCIsIm1hbmFnZS1hY2NvdW50LWxpbmtzIiwidmlldy1wcm9maWxlIl19fSwic2NvcGUiOiJlbWFpbCBwcm9maWxlIiwiZW1haWxfdmVyaWZpZWQiOnRydWUsIm5hbWUiOiJHaW5vIFN0aWxsYSIsImdyb3VwcyI6W10sInByZWZlcnJlZF91c2VybmFtZSI6Imdpbm8uc3RpbGxhIiwiZ2l2ZW5fbmFtZSI6Ikdpbm8iLCJsb2NhbGUiOiJpdCIsImZhbWlseV9uYW1lIjoiU3RpbGxhIiwiZW1haWwiOiJnaW5vQHN0aWxsYS5jb20ifQ.C43CAMgoHFhRNPACXPKDr_b1ytZeYeB2_AxTOl0jhG5YUpzoigtjwdrYptJbDtlO0fO3Ex9-KgKKBpUROMb0tC7YjuVgK6uGmaBcXGvA2S9mMLVlpl8u0KWJrrvzjPSSBHqH1fKZ6RHhZYkukMAeEeN5nT5SJoftiBNfnQi0wdjsN6fWUDLVQ3kYFQ_8C2RuO-yivSc9TyVpV-1M6ij7PEplWf2UjoygJKchs9R6x_sLHbaQHPTE24PMEY7GcEsgUwBXR3bkcWZ9cVuxAnbcIYITT-qC6V4YXodS2cYew3WoSaMl8LfTmIl7oFiv3lIDYvQ3dd-X8h1QkkbTPlVLOQ",
"expires_in": 300,
"refresh_expires_in": 1800,
"refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJjOTk5YmVjNC1iNDc4LTQ4Y2YtYmI5OS0wMWMxODY5NzcwNGIifQ.eyJleHAiOjE2MjIyMTc2NjEsImlhdCI6MTYyMjIxNTg2MSwianRpIjoiNzA2YzEyZjUtZDk3OS00MjVmLWI1NzctMzgxNWU4ZTdlNWM2IiwiaXNzIjoiaHR0cHM6Ly9hY2NvdW50cy5kZXYuZDRzY2llbmNlLm9yZy9hdXRoL3JlYWxtcy9kNHNjaWVuY2UiLCJhdWQiOiJodHRwczovL2FjY291bnRzLmRldi5kNHNjaWVuY2Uub3JnL2F1dGgvcmVhbG1zL2Q0c2NpZW5jZSIsInN1YiI6IjFjODQxMDhhLTIwMWQtNGUyMC04YWQyLWQ3MmIwOGQ1OGY4YSIsInR5cCI6IlJlZnJlc2giLCJhenAiOiJscjYyX3BvcnRhbCIsInNlc3Npb25fc3RhdGUiOiIxYTA1NGJiNy00ZDg3LTQ0YTktYWQxZi0xNzQ2ZWYyZGQ1MjIiLCJzY29wZSI6ImVtYWlsIHByb2ZpbGUifQ.2nYaWSEIbzr56vKx39AxomfiWoSQweAnepf7p3maZMs",
"token_type": "bearer",
"not-before-policy": 1618317421,
"session_state": "1a054bb7-4d87-44a9-ad1f-1746ef2dd522",
"scope": "email profile"

@ -0,0 +1,63 @@
"exp": 1621960710,
"iat": 1621960410,
"jti": "5a2a2240-8a32-40c9-8cc2-456dd8b089d9",
"iss": "",
"aud": "conductor-server",
"sub": "a47dfe16-b4ed-44ed-a1d9-97ecd504360c",
"typ": "Bearer",
"azp": "keycloak-client",
"session_state": "1550e4ef-5a92-430d-aa0f-242e5f8048de",
"acr": "1",
"realm_access": {
"roles": [
"resource_access": {
"keycloak-client": {
"roles": [
"account": {
"roles": [
"authorization": {
"permissions": [
"scopes": [
"rsid": "249fd469-79c5-4b85-b195-f29b3eb60345",
"rsname": "metadata"
"scopes": [
"rsid": "a6f3eade-7404-4e5d-9070-800adb5aac4e",
"rsname": "workflow"
"rsid": "1b6c00b7-9139-4eaa-aac7-20231fee05a5",
"rsname": "Default Resource"
"scope": "email profile",
"clientId": "keycloak-client",
"clientHost": "",
"email_verified": false,
"preferred_username": "service-account-keycloak-client",
"clientAddress": ""

@ -0,0 +1,36 @@
"exp": 1621962210,
"iat": 1621960410,
"jti": "ca223961-22a2-4171-af3e-f109749e83ea",
"iss": "",
"aud": "",
"sub": "a47dfe16-b4ed-44ed-a1d9-97ecd504360c",
"typ": "Refresh",
"azp": "keycloak-client",
"session_state": "1550e4ef-5a92-430d-aa0f-242e5f8048de",
"authorization": {
"permissions": [
"scopes": [
"rsid": "249fd469-79c5-4b85-b195-f29b3eb60345",
"rsname": "metadata"
"scopes": [
"rsid": "a6f3eade-7404-4e5d-9070-800adb5aac4e",
"rsname": "workflow"
"rsid": "1b6c00b7-9139-4eaa-aac7-20231fee05a5",
"rsname": "Default Resource"
"scope": "email profile"

@ -0,0 +1,9 @@
"upgraded": false,
"access_token": "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJSSklZNEpoNF9qdDdvNmREY0NlUDFfS1l0akcxVExXVW9oMkQ2Tzk1bFNBIn0.eyJleHAiOjE2MjE5NjA3MTAsImlhdCI6MTYyMTk2MDQxMCwianRpIjoiNWEyYTIyNDAtOGEzMi00MGM5LThjYzItNDU2ZGQ4YjA4OWQ5IiwiaXNzIjoiaHR0cHM6Ly9hY2NvdW50cy5kZXYuZDRzY2llbmNlLm9yZy9hdXRoL3JlYWxtcy9kNHNjaWVuY2UiLCJhdWQiOiJjb25kdWN0b3Itc2VydmVyIiwic3ViIjoiYTQ3ZGZlMTYtYjRlZC00NGVkLWExZDktOTdlY2Q1MDQzNjBjIiwidHlwIjoiQmVhcmVyIiwiYXpwIjoia2V5Y2xvYWstY2xpZW50Iiwic2Vzc2lvbl9zdGF0ZSI6IjE1NTBlNGVmLTVhOTItNDMwZC1hYTBmLTI0MmU1ZjgwNDhkZSIsImFjciI6IjEiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJJbmZyYXN0cnVjdHVyZS1DbGllbnQiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImtleWNsb2FrLWNsaWVudCI6eyJyb2xlcyI6WyJ1bWFfcHJvdGVjdGlvbiJdfSwiYWNjb3VudCI6eyJyb2xlcyI6WyJtYW5hZ2UtYWNjb3VudCIsIm1hbmFnZS1hY2NvdW50LWxpbmtzIiwidmlldy1wcm9maWxlIl19fSwiYXV0aG9yaXphdGlvbiI6eyJwZXJtaXNzaW9ucyI6W3sic2NvcGVzIjpbImdldCJdLCJyc2lkIjoiMjQ5ZmQ0NjktNzljNS00Yjg1LWIxOTUtZjI5YjNlYjYwMzQ1IiwicnNuYW1lIjoibWV0YWRhdGEifSx7InNjb3BlcyI6WyJnZXQiLCJzdGFydCIsInRlcm1pbmF0ZSJdLCJyc2lkIjoiYTZmM2VhZGUtNzQwNC00ZTVkLTkwNzAtODAwYWRiNWFhYzRlIiwicnNuYW1lIjoid29ya2Zsb3cifSx7InJzaWQiOiIxYjZjMDBiNy05MTM5LTRlYWEtYWFjNy0yMDIzMWZlZTA1YTUiLCJyc25hbWUiOiJEZWZhdWx0IFJlc291cmNlIn1dfSwic2NvcGUiOiJlbWFpbCBwcm9maWxlIiwiY2xpZW50SWQiOiJrZXljbG9hay1jbGllbnQiLCJjbGllbnRIb3N0IjoiMi4yMzEuMzEuMjQwIiwiZW1haWxfdmVyaWZpZWQiOmZhbHNlLCJwcmVmZXJyZWRfdXNlcm5hbWUiOiJzZXJ2aWNlLWFjY291bnQta2V5Y2xvYWstY2xpZW50IiwiY2xpZW50QWRkcmVzcyI6IjIuMjMxLjMxLjI0MCJ9.UKcREwcaJc9tpfUIsIfqbN-uON1lrtAcVQSoZan29hyQ-t8o6tjWS4-ix8JnWN8YBxU0Gbo1XcGx2NEnX7QCcAt9R46I9jpd5D9LBF-DF1G5zTVc1Cwm9-XcQ9vU_KDJ_qOzhcbPe1ZeAkYV4LpRXuPS7bBSUiNYExHoWBQTUTjNUc7rJRGWk14YKNjEgvri46RZw3ZZQ19JdjktyLz4WNGF8asSAmLXTeJ4q7O1kWttDzxjiz6QMW1378lYCb_GfXWsnAWbm7zpfz2-Fs3NmZO35BUw_jba_l_8Uog35X9qhsgcw2-_sWEB0vGLEHvz2zowpy70zjpoeHZYq6LeBw",
"expires_in": 300,
"refresh_expires_in": 1800,
"refresh_token": "eyJhbGciOiJIUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJjOTk5YmVjNC1iNDc4LTQ4Y2YtYmI5OS0wMWMxODY5NzcwNGIifQ.eyJleHAiOjE2MjE5NjIyMTAsImlhdCI6MTYyMTk2MDQxMCwianRpIjoiY2EyMjM5NjEtMjJhMi00MTcxLWFmM2UtZjEwOTc0OWU4M2VhIiwiaXNzIjoiaHR0cHM6Ly9hY2NvdW50cy5kZXYuZDRzY2llbmNlLm9yZy9hdXRoL3JlYWxtcy9kNHNjaWVuY2UiLCJhdWQiOiJodHRwczovL2FjY291bnRzLmRldi5kNHNjaWVuY2Uub3JnL2F1dGgvcmVhbG1zL2Q0c2NpZW5jZSIsInN1YiI6ImE0N2RmZTE2LWI0ZWQtNDRlZC1hMWQ5LTk3ZWNkNTA0MzYwYyIsInR5cCI6IlJlZnJlc2giLCJhenAiOiJrZXljbG9hay1jbGllbnQiLCJzZXNzaW9uX3N0YXRlIjoiMTU1MGU0ZWYtNWE5Mi00MzBkLWFhMGYtMjQyZTVmODA0OGRlIiwiYXV0aG9yaXphdGlvbiI6eyJwZXJtaXNzaW9ucyI6W3sic2NvcGVzIjpbImdldCJdLCJyc2lkIjoiMjQ5ZmQ0NjktNzljNS00Yjg1LWIxOTUtZjI5YjNlYjYwMzQ1IiwicnNuYW1lIjoibWV0YWRhdGEifSx7InNjb3BlcyI6WyJnZXQiLCJzdGFydCIsInRlcm1pbmF0ZSJdLCJyc2lkIjoiYTZmM2VhZGUtNzQwNC00ZTVkLTkwNzAtODAwYWRiNWFhYzRlIiwicnNuYW1lIjoid29ya2Zsb3cifSx7InJzaWQiOiIxYjZjMDBiNy05MTM5LTRlYWEtYWFjNy0yMDIzMWZlZTA1YTUiLCJyc25hbWUiOiJEZWZhdWx0IFJlc291cmNlIn1dfSwic2NvcGUiOiJlbWFpbCBwcm9maWxlIn0.63dE64hNYpxQRV-M5zOrLLWt9cehJI4DcIbHia977r4",
"token_type": "Bearer",
"not-before-policy": 1618317421