OpenFGA + Keycloak — identity & authorization — POC
The architecture. Cleanly separate authentication (who are you — Keycloak/OIDC) and authorization (are you allowed — OpenFGA). Two responsibilities, two building blocks.
What I prototype
- Keycloak: login, OIDC, tokens, identity federation.
- OpenFGA: fine-grained authorization decisions from the Keycloak identity.
- Middleware chaining
verify token→check permission.
Stack
Keycloak · OpenFGA · NestJS · OIDC
POC — IAM integration, not deployed to production.