Replies: 1 comment
-
|
Just a small comment regarding point 1 :
It's possible by adding a specific scope : |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I was thrilled to see that the Keycloak team has introduced the concept of organizations. However, after exploring it further, I realized it’s more of an MVP than a fully usable feature (especially in scenarios where a single user belongs to multiple organizations).
Here are some critical gaps I’ve encountered:
No clear way to log in with a specific active (or default) organization
Currently, there are only two primitive options:
NOTE: The second option raises a serious security concern: anyone with a user's email address can enumerate all their organizations.
No ability to switch organizations without logging out and back in
This makes multi-organization workflows cumbersome and impractical.
No standard way to specify the active organization via REST API authentication
I was surprised to find that the only viable method involves:
This feels overly complex for such a basic requirement.
Switching between organizations via REST APIs follows the same convoluted path
There’s no clean or documented way to handle this.
I understand the team may have approached this feature with a different perspective, but for many of us, the term organization suggested a more advanced level of multi-tenancy. I’m hopeful that future iterations will bring more robust and intuitive flows.
Beta Was this translation helpful? Give feedback.
All reactions