X509 Authentication Nokia/Oidc Plugin

I am using the nokia/oidc plugin. I am using this with keycloak. I have issued some developers certificates to access my api. I would like the devs to be authenticated using their certificates. The issue that I am running into is the current workflow for nokia/oidc plugin.

  1. Dev needs to request a token from keycloak.
  2. Dev needs to apply Bearer token as a header to api request.

Is there a way to consolidate these two steps? Dev just makes request to api and kong / keycloak handle the heavy lifting of requesting token and applying bearer token to api request?

