The external Keycloak sync program synchronizes a single subject
through the UUID-keyed idempotent
PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path
is the same UUID as in Keycloak. Creating a new subject returns
201 Created, updating an existing subject’s name returns
200 OK. Only a global-admin may synchronize subjects
(others are rejected with 403). Without an explicit
organization, only realm-prefixed names are accepted (others are
rejected with 400) and the organization is derived from the
name prefix. With an explicit organization, USER names are free except
that they must not start with /; GROUP names must start
with / directly followed by the organization, because JWTs
reference groups just by name and thus the organization must stay
derivable from it.
| name | value |
|---|---|
| subjectUuid | 239a0004-0000-0000-0000-000000000004 |
| subjectName | /bob |
| organization | example |
| subjectType | USER |
HTTP PUT "/api/rbac/subjects/239a0004-0000-0000-0000-000000000004" \
-H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
`# {` \
`# "sub" : "uuid<hsh-alex_superuser>"` \
`# }` \
<<EOF
{
"name" : "/bob",
"organization" : "example",
"type" : "USER"
}
EOF
=> status: 400 BAD_REQUEST
{
"timestamp" : "2026-08-10 01:38:10",
"path" : "",
"statusCode" : 400,
"statusPhrase" : "Bad Request",
"message" : "ERROR: [400] [USER subject name '/bob' does not match required pattern]"
}
generated on 2026-08-10 01:38:10 for branch