---
url: >-
  https://flip-chart.ru/developers/en/on-premise/installation/other/keycloak/oidc.md
description: >-
  Set up sign-in to flip on-premise through Keycloak via OpenID Connect: create
  client scopes, create the client and complete its configuration, including the
  Client Secret.
---

# OpenID Connect integration with Keycloak

## Step 1. Creating **Client Scopes**

1. Sign in to the Keycloak admin console.
2. Go to **Client scopes**.

![Go to Client scopes](/on-premise/images/kk/kk-main-to-scopes.png)

3. Click **Create client scope**

![Creating a client scope](/on-premise/images/kk/kk-create-scope-0.png)

4. Fill in the required fields, select the **OpenID Connect** protocol and save.

![Client scope settings](/on-premise/images/kk/kk-create-scope-oidc-1.png)

***

## Step 2. Creating a **Client**

1. Go to **Clients**.

![Go to Clients](/on-premise/images/kk/kk-main-to-clients.png)

2. Click **Create client**.

![Creating a client](/on-premise/images/kk/kk-clients-to-create.png)

3. Fill in **Client type** by selecting the **OpenID Connect** protocol, and fill in **Client ID**.

![Client creation, step 1](/on-premise/images/kk/kk-create-oidc-step-1.png)

4. Turn on **Authorization** and select **Implicit flow**.

![Client creation, step 2](/on-premise/images/kk/kk-create-oidc-step-2.png)

5. Specify **Valid redirect URIs** (multiple values are allowed).

::: tip Note
The redirect URI must contain the domain name on which the **flip** app runs.
:::

![Client creation, step 3](/on-premise/images/kk/kk-create-oidc-step-3.png)

***

## Step 3. Additional client configuration

1. Review the client settings and adjust them if needed.

![Client settings](/on-premise/images/kk/kk-create-oidc-setting.png)

2. Get the **Client Secret** on the **Credentials** tab.

::: tip Important
The Client ID and Client Secret are entered when you configure SSO in the flip interface; they are not added to the backend configuration file.
:::

![Client Secret](/on-premise/images/kk/kk-create-oidc-cred.png)

3. Add the previously created **Client Scope** to this client.

![Adding a client scope](/on-premise/images/kk/kk-create-oidc-scope.png)

::: tip Note
Enter the data you obtained as described in the [SSO](/en/on-premise/installation/other/sso) setup guide.
:::
