NAME

WWW::Keycloak::Auth - Get and keep a valid admin token for the Keycloak Admin API

VERSION

version 0.001

SYNOPSIS

my $auth = WWW::Keycloak::Auth->new(
  token_endpoint => 'https://id.example.org/realms/master/protocol/openid-connect/token',
  username       => 'admin',
  password       => $password,
  ua             => $lwp,
);
my $bearer = $auth->token;

DESCRIPTION

Keycloak has no long-lived admin tokens. This class logs in when a token is first needed, keeps it, renews it shortly before it runs out (with the refresh token while that is valid, otherwise by logging in again), and forgets it when told the token was refused. Three ways to log in: a username and password through the admin-cli client, a service-account client with its secret, or a fixed token that is used as it is and never renewed.

Passwords and secrets never appear in an exception.

ua

Required. The LWP::UserAgent to use.

token_endpoint

The token endpoint of the realm the admin logs in to. Required unless token is given.

username

password

Log in with the password grant through admin-cli, or through client_id when that is given too.

client_id

client_secret

Log in with the client credentials grant of a service-account client.

token

A ready token. Used as it is; when it runs out, requests fail.

margin

Seconds before expiry at which a token is renewed. Default 30.

now

Coderef returning the current epoch. For tests.

renewable

False for a fixed token, which this class cannot replace.

token

my $bearer = $auth->token;

A token that is valid for at least margin more seconds.

invalidate

$auth->invalidate;

Forgets the current token, so the next "token" logs in afresh. Called when Keycloak refused a token, for example after a restart.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-www-keycloak/issues.

IRC

Join #kubernetes on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.