Skip to content

Keycloak Verification

pbcs.ghaustein edited this page Jun 26, 2026 · 5 revisions

Verifying Keycloak Access

This page describes how to verify that your system can successfully request an access token from the Ministry of Health Keycloak server. Use the PowerShell example below to test connectivity, client credentials, and the Keycloak token endpoint for both sandbox and production environments.

Prerequisite Keycloak Required Certificates

Review the document Do-you-have-a-certificate-problem.docx to insure your system has the necessary root and intermediate certificates in place.

Instructions:

  • save the content below as a .ps1 file on the system to be tested (e.g. keycloak-test.ps1)
  • edit the script to meet your requirements, e.g. enter your credentials
  • open Powershell and cd to the folder where you saved the .ps1 file
  • execute the file, for example type ./keycloak-test.ps1 and hit the Enter key
  • Review the contents of the script in full before running.
# KeyCloak verification Powershell script (.ps1)

# Setting these values is optional. If invalid values are provided, Keycloak will return an "Unauthorized" response.
$clientid = "A99AA9AA-9AA996A4A99"
$clientSecret = "a99aa999-a9aa-9a9a-999a-9a9aa999a999"

# test/sandbox
$keycloak = "https://common-logon-test.hlth.gov.bc.ca/auth/realms/moh_applications/protocol/openid-connect/token"

# production
# $keycloak = "https://common-logon.hlth.gov.bc.ca/auth/realms/moh_applications/protocol/openid-connect/token"

# get a token from keycloak; if this times-out then your system was unable to reach the Keycloak server, 
# which likely means your system and/or network are not setup correctly
$response = curl.exe -X POST $keycloak `
   -H "Content-Type: application/x-www-form-urlencoded" `
   -d "grant_type=client_credentials&client_id=$clientid&client_secret=$clientsecret"

if ([string]::IsNullOrEmpty($accessToken)) {
    echo "Token has not been received from Keycloak"
    echo $response
    exit 1
}

# parse/display the token from the response
$accessToken = ($response | ConvertFrom-Json).access_token
echo $accessToken

Clone this wiki locally