OAuth 2.0 in Spring Boot Applications


OAuth = Open Authorization

OAuth 2.0 is an Authorization framework

OAuth is a delegated authorization framework

Client Type

We can have different types of clients that need to contact Authorization Server. First of all, they need to be registered in the AS, so they are recognized and they can send their client_id and client_secret to the AS. But not all clients are secure to hold their credentials.

  • Confidential [can keep client_secret safe]
    • Secure app running on server
  • Public [can not keep the client_id & client_secret safe]
    • Native apps on user's device
    • Single page browser-based app

Access Token

  • Identifier Type
    • Base-64 encoded
    • In the Authorization Server's DB:
access_token user_id scope expires
BYL5v5a4s984wF7 JWeFS12s profile, documents 159354110
  • Self-contain the authorization information
    • decodable in JWT.io
    • header . payload . signature
    • eyJhbGciOiJSUzI1NiIsImtpZCI6IjFlOWdkazcifQ.ewogImlzcyI6ICJodHRwOi8vc2VydmVyLmV4YW1wbGUuY29tIiwKICJzdWIiOiAiMjQ4Mjg5NzYxMDAxIiwKICJhdWQiOiAiczZCaGRSa3F0MyIsCiAibm9uY2UiOiAibi0wUzZfV3pBMk1qIiwKICJleHAiOiAxMzExMjgxOTcwLAogImlhdCI6IDEzMTEyODA5NzAKfQ.ggW8hZ1EuVLuxNuuIJKX_V8a_OMXzR0EHR9R6jgdqrOOF4daGU96Sr_P6qJp6IcmD3HP99Obi1PRs-cwh3LO-p146waJ8IhehcwL7F09JdijmBqkvPeB2T9CJNqeGpe-gccMg4vfKjkM8FcGvnzZUN4_KSP0aAp1tOJ1zZwgjxqGByKHiOtX7TpdQyHE5lcMiKPXfEIQILVq0pc_E2DzL7emopWoaoZTF_m0_N0YzFC6g6EJbOEoRoSK5hoDalrcvRYLSrQAZZKflyuVCyixEoV9GfNQC3_osjzw2PAithfubEEBLuVVk4XUVrWOLrLl0nx7RkKU8NXNHq-rvKMzqg

OpenID Connect

OAuth 2 Grant Types and Authorization Flows

Is a way an application gets and access_token

  • Server side web app
    • Authorization Code
    • Password grant [deprecated]
  • Server side script with no UI
    • Client Credential
  • Javascript single page app
    • PKCE Enhanced Authorization Code
    • Implicit Flow [deprecated]
    • Password grant [deprecated]
  • Mobile native app
    • Authorization Code
    • PKCE Enhanced Authorization Code
    • Implicit Flow [deprecated]
    • Password grant [deprecated]
  • Device
    • Device Code

Refresh Token Grant Type is used to exchange a refresh_token for an access_token


Proof Key for Code Exchange Java PKCE generator example

  • Code Challenge
  • Code Verifier

Machine to Machine

grant_type = client_credentials

Password Grant

Must be only used when the application doesn't support redirect_uri

Refresh Access Token

grant_type = refresh_token

Keycloak. The Standalone Authorization Server


  • Open source Identity and Access Management solution
  • Supports Single-Sign On (SSO)
  • Social Login
  • User Federation



Each client has some default scopes, so even if they are not provided in the request, AS will use by default. They can be modified

openid profile email ...

OAuth Resource Server

The Spring's dependency spring-boot-starter-oauth2-resource-server included Spring Security and makes the endpoints secure by default.

RS needs to contact the AS to get the needed tokens. In application.properties add one of these:



To access the resources on the RS, the token is passed via Authorization: Bearer XXX format. This Authentication Principal (JWT token) contains the data that can be decrypted by:

public class TokenController {

	public Jwt getToken(@AuthenticationPrincipal Jwt jwt) {
		return jwt;

Resource Server - Scope Based Access Control

Scope is a mechanism in OAuth 2.0 to limit an application's access to a user's account. An application can request one or more scopes, this information is then presented to the user in the consent screen, and the access token issued to the application will be limited to the scopes granted.

  • The client should have that scope?
  • In RS, define the scope-base rule. It must be "SCOPE_xxx", since later Spring Security will add SCOPE_underline at the begining of the "scope"
public class WebSecurity extends WebSecurityConfigurerAdapter{

	protected void configure(HttpSecurity http) throws Exception {
				.antMatchers(HttpMethod.GET, "/users/status/check").hasAuthority("SCOPE_profile")

Role Based Access Control with Keycloak

Role is a collection of authorities

ROLE User Admin Super Admin
Privileges /
View Profile
View other users
Edit own profile
Edit profile of other users
Delete other users
Edit/Delete other admins

In Spring Security:

  • Authoriry name = Role name = ROLE_ADMIN
  • hasRole("Admin")
  • hasAuthority("ROLE_ADMIN")

In Keycloak different roles can be assigned to users. The user's roles are included in the JWT token:

"realm_access": {
    "roles": [

To let the Spring Security obtain the list of assigned roles, a Converter is needed to parse the roles from JWT and put them in SimpleGrantedAuthority

public class KeycloakRoleConverter implements Converter<Jwt, Collection<GrantedAuthority>>{

	public Collection<GrantedAuthority> convert(Jwt jwt) {
		Map<String, Object> realmAccess = (Map<String, Object>) jwt.getClaims().get("realm_access");
		if(realmAccess == null || realmAccess.isEmpty()) {
			return new ArrayList<GrantedAuthority>();
		Collection<GrantedAuthority> returnValue = ((List<String>) realmAccess.get("roles"))
			.stream().map(roleName -> "ROLE_" + roleName)
		return returnValue;

This class is injected in the security configuration

JwtAuthenticationConverter jwtAuthenticationConverter = new JwtAuthenticationConverter();
jwtAuthenticationConverter.setJwtGrantedAuthoritiesConverter(new KeycloakRoleConverter());
			.antMatchers(HttpMethod.GET, "/users/status/check")
			//.hasAuthority("ROLE_developer") //in case of using this cmd
			//.hasAnyRole("developer", "user") //for multiple roles

Resource Server: Method Level Security

Methods can be secured solely by using "@Secured("ROLE_xxx")" annotation. To activate this feature, in the WebSecurity class, should be activated first. Also "@PreAuthorize("...")" and "@PostAuthorize("...")" can be activated here.

@EnableGlobalMethodSecurity(securedEnabled = true, prePostEnabled = true)
public class WebSecurity extends WebSecurityConfigurerAdapter{
public String deleteUser(@PathVariable String id) {
	return "Deleted user with id: " + id;

With "@PreAuthorize" it is possible to set logic using the values sent via the request. For example, only the users with role "developer" or the owner of the logged in user, can invoke this method:

@PreAuthorize("hasAuthority('ROLE_developer') or #id == #jwt.subject")
public String deleteUser(@PathVariable String id, @AuthenticationPrincipal Jwt jwt) {
	return "Deleted user with id: " + id + " / JWT subject: " + jwt.getSubject();

"@PostAuthorize" will evaluate after method invocation.

@PostAuthorize("returnObject.id == #jwt.subject")
@GetMapping(path = "/{id}")
public UserRest getUser(@PathVariable String id, @AuthenticationPrincipal Jwt jwt) {
	return new UserRest("6203892e-e66e-42fd-b8b5-ca720ed5045c", "Name", "Lastname");

Resource Servers Behind API Gateway

Instead of hitting each microservice, an API Gateway can take the responsibility of detecting the requested resource and transfer it to the appropriate service for us.

Spring Cloud Gateway features:

  • Built on Spring Framework 5, Project Reactor and Spring Boot 2.0
  • Able to match routes on any request attribute.
  • Predicates and filters are specific to routes.
  • Circuit Breaker integration.
  • Spring Cloud DiscoveryClient integration
  • Easy to write Predicates and Filters
  • Request Rate Limiting
  • Path Rewriting

Add each MS and endpoint, in the application.properties file:

spring.cloud.gateway.routes[0].id = user-status-check
spring.cloud.gateway.routes[0].uri = http://localhost:8081
spring.cloud.gateway.routes[0].predicates[0] = Path=/users/status/check
spring.cloud.gateway.routes[0].predicates[1] = Method=GET
spring.cloud.gateway.routes[0].filters[0] = RemoveRequestHeader=Cookie

Eureka (Spring Cloud Netflix) Discovery Service

A Discovery Service is needed to let the clients to register themselves in it and all the requests are then transfered via this service.

The Eureka service will run as server

public class DiscoveryServiceApplication { ... }

While other clients, register themselves as register and point to the Discovery Service

public class ResourceServerApplication { ... }

In "application.properties":

eureka.client.serviceUrl.defaultZone = http://localhost:8010/eureka
Service Address
Eureka Discovery Service http://localhost:8010
API Gateway http://localhost:8082
Authorization Server http://localhost:8080
Resource Server http://localhost:8081
Photos Server http://localhost:8090
Albums Server http://localhost:8091

Load Balancing

Applications need to obtain the port dynamically


But with only the line above, Eureka will replace the new_instance:new_port with the old one. The solution is to have different instanceId for each instance


Or provide as a CLI parameter:

mvn spring-boot:run -Dspring-boot.run.arguments=--instanceId=javad

In API Gateway the endpoints are provided. When a client requests for a resource, the API Gateway recieves and will parse the resource's path and send the parsed request to Eureka (for load balancing between running Resource Servers). Order of running applications will be:

  1. Eureka Discovery (Discovery server)
  2. API Gateway (registers itself on Eureka)
  3. Any other Resource Server

OAuth 2.0 in MVC Web App

The client needs dependencay spring-boot-starter-oauth2-client and the configuration:

spring.security.oauth2.client.registration.mywebclient.scope=openid, profile, roles

#needed to contact the Authiorization Provider

Opening the resource in the browser, will relocate to Keycloak's login page. On successful login, the OidcUser can be access in the backend:

Name: [javad], 
Granted Authorities: [[ROLE_USER, SCOPE_email, SCOPE_openid, SCOPE_profile]], 
User Attributes: 
	name=Javad Alizadeh, 

Id Token:

To get the JWT Access Token and use it for later accesses:

OAuth2AuthorizedClientService  oauth2ClientService;
RestTemplate restTemplate;
public String getAlbums(Model model, @AuthenticationPrincipal OidcUser principal) {
	Authentication authentication = SecurityContextHolder.getContext().getAuthentication();
	OAuth2AuthenticationToken oauthToken = (OAuth2AuthenticationToken) authentication;
	OAuth2AuthorizedClient oauth2Client = oauth2ClientService.loadAuthorizedClient(oauthToken.getAuthorizedClientRegistrationId(), oauthToken.getName());
	String jwtAccesstoken = oauth2Client.getAccessToken().getTokenValue();

Using the WebClient from Spring Web Reactive library, it is easier to send requests while the OAuth2 header is already included in the request's header. First define the bean that will inject the OAuth2 configuration.

Note: Never use this config to send request to third party services that can compromise the token.

public WebClient webClient(ClientRegistrationRepository crr, OAuth2AuthorizedClientRepository ocr) {
	ServletOAuth2AuthorizedClientExchangeFilterFunction oauth2 = 
		new ServletOAuth2AuthorizedClientExchangeFilterFunction(crr, ocr);

	return WebClient.builder().apply(oauth2.oauth2Configuration()).build();

And the controller will be:

public String getAlbums(Model model, @AuthenticationPrincipal OidcUser principal) {
	//this address points to API Gateway and then, Albums service
	String url = "http://localhost:8082/albums";
	List<AlbumRest> albums = webClient.get()
		.bodyToMono(new ParameterizedTypeReference<List<AlbumRest>>() {})
	return "albums";

OAuth 2.0 - Social Login

There are also other Authentication Services that can handle the user authentication, like: Google, Facebook, Okta, Github and etc.. Spring Security by default, has the configuration of them and only needs the credential of the client on those services.

For using different service providers, after creating the app in those services, fill up the needed data:





Not that, the application needs also to let the user to logout. This can be added using Spring Security native "/logout" page. But not all services expire the token/session quickly after the user logs out.

public class WebSecurity extends WebSecurityConfigurerAdapter{

	ClientRegistrationRepository clientRegistrationRepository;
	protected void configure(HttpSecurity http) throws Exception{
	private OidcClientInitiatedLogoutSuccessHandler oidcLogoutSuccessHandler() {
		OidcClientInitiatedLogoutSuccessHandler successHandler = 
				new OidcClientInitiatedLogoutSuccessHandler(clientRegistrationRepository);
		return successHandler;



