Skip to content

Organization-scoped token exchange #196

@NikiforovAll

Description

@NikiforovAll

Status: Not relevant yet

Keycloak does not currently have an organization-specific token exchange flow. The standard token exchange (urn:ietf:params:oauth:grant-type:token-exchange) works as before — organization context is carried via session notes and resolved from requested scopes (e.g., scope=organization:acme-corp).

This issue is a placeholder to track when Keycloak implements dedicated organization-scoped token exchange.

Related

When to revisit

When Keycloak ships organization-scoped roles or dedicated org token exchange endpoints.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Renovation20262026 renovation and modernization tasks

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions