Consumer Group authorizationv3.12+

Configure Consumer Group mapping with the OpenID Connect plugin.

This example uses password authentication, but you can use any supported authentication type with Consumer Groups.

For a full example that shows you how to set up the OpenID Connect plugin to map Consumers to IdP users, see Configure OpenID Connect with Consumer Group authorization.

Prerequisites

  • A configured identity provider (IdP)

  • At least one Consumer Group with a name matching the value defined in config.consumer_group_claim

Environment variables

  • ISSUER: The issuer authentication URL for your IdP. For example, if you’re using Keycloak as your IdP, the issuer URL looks like this: http://localhost:8080/realms/example-realm

Set up the plugin

Something wrong?

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!