# Federated Authentication with Custom External OAuth 2.0 Identity Provider

**URL:** <https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779>\
**Category:** Questions\
**Created:** [April 5, 2018, 5:47pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779 "2018-04-05T17:47:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![PetrDvorak](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/petrdvorak/32/274_2.png) [@PetrDvorak](https://discuss.konghq.com/u/PetrDvorak)\
**Post date:** [April 5, 2018, 5:47pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/1 "2018-04-05T17:47:16Z")

</div>

Hello guys,

we would like to use an external OAuth 2.0 Identity Provider (IDP) for federated authentication - in principle, a similar feature to this one of WSO2 IS:

- Outbound Authentication Plugin for Facebook (allows WSO2 API application users login via Facebook): [https://github.com/wso2-extensions/identity-outbound-auth-facebook](https://github.com/wso2-extensions/identity-outbound-auth-facebook)
- How to build custom outbound authenticator in WSO2: [https://docs.wso2.com/display/IS541/Writing+a+Custom+Federated+Authenticator](https://docs.wso2.com/display/IS541/Writing+a+Custom+Federated+Authenticator), or

Basically, we would like Kong to be responsible for issuing the actual end-application OAuth 2.0 access token (and doing all associated API management stuff), and only use the external IDP for handling the actual user authentication. The external IDP has own OAuth 2.0 Authorization service (and can issue “internal access token”, not used by end-application, but only internally between Kong and IDP) and provides one secured resource for obtaining more user information (so that Kong knows to which user to issue an actual access token).

Does anyone have some experience with this setup?

With kind regards,

Petr Dvorak

---

<div class="post-metadata">

**Author:** ![bungle](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/bungle/32/13_2.png) [@bungle](https://discuss.konghq.com/u/bungle)\
**Post date:** [April 6, 2018, 9:53pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/2 "2018-04-06T21:53:05Z")

</div>

You can certainly do that as a custom plugin. There are some 3rd party plugins, e.g. this:

> **[foodora/kong-plugin-jwt-crafter](https://github.com/foodora/kong-plugin-jwt-crafter)**
>
> Kong plugin to automatically issue a JWT token if consumer is authenticated and has a JWT credential - foodora/kong-plugin-jwt-crafter

That you could use with, e.g. this (EE only):  
[https://getkong.org/plugins/ee-openid-connect/](https://getkong.org/plugins/ee-openid-connect/)

Or (3rd party, OSS):

> **[nokia/kong-oidc](https://github.com/nokia/kong-oidc)**
>
> OIDC plugin for Kong. Contribute to nokia/kong-oidc development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![PetrDvorak](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/petrdvorak/32/274_2.png) [@PetrDvorak](https://discuss.konghq.com/u/PetrDvorak)\
**Post date:** [April 8, 2018, 2:54pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/3 "2018-04-08T14:54:32Z")

</div>

Excellent - thank you, the plugin by Nokia looks very promising.

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [April 8, 2018, 8:41pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/4 "2018-04-08T20:41:32Z")

</div>

Another Plugin I have used that implements OIDC - it needs a little work for working with the latest versions of Kong (swap out the lua crypto for newer lua ossl), its what we are using internally but we have not released the modified source code publicly but may in the future 🙂 -

```auto
https://github.com/mogui/kong-external-oauth

```

---

<div class="post-metadata">

**Author:** ![PetrDvorak](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/petrdvorak/32/274_2.png) [@PetrDvorak](https://discuss.konghq.com/u/PetrDvorak)\
**Post date:** [April 9, 2018, 5:27pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/5 "2018-04-09T17:27:27Z")

</div>

Also looks nice - I like how minimalis it is. We would have to fix it a little bit so that access tokens are actually issued by Kong, not the 3rd party IDP… but this should not be too hard. Thank you.

---

<div class="post-metadata">

**Author:** ![alya](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/alya/32/967_2.png) [@alya](https://discuss.konghq.com/u/alya)\
**Post date:** [May 6, 2019, 5:08pm UTC](https://discuss.konghq.com/t/federated-authentication-with-custom-external-oauth-2-0-identity-provider/779/6 "2019-05-06T17:08:33Z")

</div>

Hi @PetrDvorak, @bungle, @jeremyjpj0916, @thefosk,

I have a similar use case that you have implemented with custom auth service. Main Idea is that we cannot share the client credentials with external service and cannot share the authenticated JWT with client.

When the client tries to authenticate by presenting the client Id and secret(Basic Auth), I want to route the request to custom authentication service. We have the client information saved in our database and is segregated to different realms(user groups). Implemented an auth-service that validates the client credentials based on the realm and generates a JWT response. JWT has sensitive information so cannot be shared with the client. This auth-service has multiple versions, so we need to route the request to different auth-service endpoints based on the realm(sent in the query parameter) and a custom header.

Once the auth-service returns a JWT response, Kong should be able to generate an oauth token and save the associated JWT in cache. This OAuth token will be shared with the client. When client presents this token in the Authorization header, API Gateway should be able to validate the token and get the JWT that was saved before and inject into to the backend request.

Does Kong support any plugin for this set up, Could you please share the relevant links?
