{"_id":"@clemax/nest-keycloak-connect","_rev":"3-ad44139a85a609cd80ee95b955bfda9b","name":"@clemax/nest-keycloak-connect","dist-tags":{"latest":"2.1.1"},"versions":{"2.0.0":{"name":"@clemax/nest-keycloak-connect","version":"2.0.0","keywords":["nestjs","keycloak","typescript"],"author":{"name":"John Joshua Ferrer","email":"johnjoshuaferrer@disroot.org"},"license":"MIT","_id":"@clemax/nest-keycloak-connect@2.0.0","maintainers":[{"name":"clemax","email":"clementhamada@protonmail.com"}],"homepage":"https://github.com/ferrerojosh/nest-keycloak-connect#readme","bugs":{"url":"https://github.com/ferrerojosh/nest-keycloak-connect/issues"},"dist":{"shasum":"38c9c63fff272c9f0c878fed52f1d969c288050a","tarball":"https://registry.npmjs.org/@clemax/nest-keycloak-connect/-/nest-keycloak-connect-2.0.0.tgz","fileCount":43,"integrity":"sha512-kjM8K+/PQSJzMWH4Xplwdf0RaR3GuZmrVl04h8iHPMtCk/EtvofE8viybHgNkqK7p0f2jAXU8cghG/GbKlSyHg==","signatures":[{"sig":"MEYCIQDpsADh4kx8KLMZqdCBKq24eob3UVhad9L2zTc597rsIgIhAJJ2I+gL5jqFk3qNE9FomdxIAxIabp7lY7jAZKcfooFa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86183},"main":"./dist/index.js","_from":"file:clemax-nest-keycloak-connect-2.0.0.tgz","types":"./dist/index.d.ts","volta":{"node":"21.7.1"},"exports":{".":"./dist/index.js","./*":"./dist/*"},"funding":[{"url":"https://www.paypal.me/ferrerojosh/","type":"individual"},{"url":"https://github.com/sponsors/ferrerojosh","type":"github"}],"scripts":{"lint":"eslint src","build":"tsc","clean":"rimraf dist","format":"prettier src --write","release":"release-it","start:dev":"tsc -w","release:alpha":"release-it --preReleaseId=alpha --npm.tag=next --github.preRelease"},"_npmUser":{"name":"clemax","email":"clementhamada@protonmail.com"},"_resolved":"/tmp/a53b502054fd1a902e8c12545e24fd0e/clemax-nest-keycloak-connect-2.0.0.tgz","_integrity":"sha512-kjM8K+/PQSJzMWH4Xplwdf0RaR3GuZmrVl04h8iHPMtCk/EtvofE8viybHgNkqK7p0f2jAXU8cghG/GbKlSyHg==","repository":{"url":"git+https://github.com/ferrerojosh/nest-keycloak-connect.git","type":"git"},"_npmVersion":"11.10.1","description":"keycloak-nodejs-connect module for Nest","directories":{},"lint-staged":{"**/*.ts":["prettier --write","eslint"]},"_nodeVersion":"22.22.0","typesVersions":{"*":{"*":["dist/*"],"dist/index.d.ts":["dist/index.d.ts"]}},"_hasShrinkwrap":false,"devDependencies":{"cpr":"3.0.1","rxjs":"7.8.1","husky":"^9.0.11","eslint":"8.57.0","rimraf":"3.0.2","graphql":"^16.10.0","ts-node":"10.8.2","prettier":"3.2.5","release-it":"17.1.1","typescript":"5.4.2","@types/node":"^18.19.23","lint-staged":"^15.2.2","@nestjs/core":"^11.0.6","@nestjs/common":"^11.0.6","@types/express":"^4.17.21","@nestjs/graphql":"^13.0.2","class-validator":"0.14.1","keycloak-connect":"npm:@clemax/keycloak-connect@26.1.2","reflect-metadata":"0.2.1","class-transformer":"0.5.1","typescript-eslint":"^7.2.0","eslint-config-prettier":"9.1.0","eslint-plugin-prettier":"5.1.3"},"peerDependencies":{"@nestjs/core":">=6.0.0 <12.0.0","@nestjs/common":">=6.0.0 <12.0.0","@nestjs/graphql":">=6","keycloak-connect":"npm:@clemax/keycloak-connect@>=10.0.0"},"peerDependenciesMeta":{"@nestjs/graphql":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/nest-keycloak-connect_2.0.0_1772816241911_0.8329101311373861","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"@clemax/nest-keycloak-connect","version":"2.1.0","keywords":["nestjs","keycloak","typescript"],"author":{"name":"John Joshua Ferrer","email":"johnjoshuaferrer@disroot.org"},"license":"MIT","_id":"@clemax/nest-keycloak-connect@2.1.0","maintainers":[{"name":"clemax","email":"clementhamada@protonmail.com"}],"homepage":"https://github.com/ferrerojosh/nest-keycloak-connect#readme","bugs":{"url":"https://github.com/ferrerojosh/nest-keycloak-connect/issues"},"dist":{"shasum":"e155a97ed37efcf65613d0f0351d32a69e0fd4f1","tarball":"https://registry.npmjs.org/@clemax/nest-keycloak-connect/-/nest-keycloak-connect-2.1.0.tgz","fileCount":3,"integrity":"sha512-M464MKdvtEtBMEZXdgng6AnXBAZY8TfXmmIzwaXvent68+2kRTA2FJUipl9hT+OA9OlvSQ2xAiTS7fJbwcy4QQ==","signatures":[{"sig":"MEUCIQDmdPSpsZyZHeSS1kBJLUOC02lS2yyThqgpoiqZJxu1aQIgMy3COS/vaxgL4MeTHrEcFY9tmPAEOHWaRmP9nfMm0m8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15112},"main":"./dist/index.js","_from":"file:clemax-nest-keycloak-connect-2.1.0.tgz","types":"./dist/index.d.ts","volta":{"node":"21.7.1"},"exports":{".":"./dist/index.js","./*":"./dist/*"},"funding":[{"url":"https://www.paypal.me/ferrerojosh/","type":"individual"},{"url":"https://github.com/sponsors/ferrerojosh","type":"github"}],"scripts":{"lint":"eslint src","build":"tsc","clean":"rimraf dist","format":"prettier src --write","release":"release-it","start:dev":"tsc -w","release:alpha":"release-it --preReleaseId=alpha --npm.tag=next --github.preRelease"},"_npmUser":{"name":"clemax","email":"clementhamada@protonmail.com"},"_resolved":"/tmp/f78cea1dc76976498229a75a0714b7eb/clemax-nest-keycloak-connect-2.1.0.tgz","_integrity":"sha512-M464MKdvtEtBMEZXdgng6AnXBAZY8TfXmmIzwaXvent68+2kRTA2FJUipl9hT+OA9OlvSQ2xAiTS7fJbwcy4QQ==","repository":{"url":"git+https://github.com/ferrerojosh/nest-keycloak-connect.git","type":"git"},"_npmVersion":"11.14.1","description":"keycloak-nodejs-connect module for Nest","directories":{},"lint-staged":{"**/*.ts":["prettier --write","eslint"]},"_nodeVersion":"22.22.2","typesVersions":{"*":{"*":["dist/*"],"dist/index.d.ts":["dist/index.d.ts"]}},"_hasShrinkwrap":false,"devDependencies":{"cpr":"3.0.1","rxjs":"7.8.1","husky":"^9.0.11","eslint":"8.57.0","rimraf":"3.0.2","graphql":"^16.10.0","ts-node":"10.8.2","prettier":"3.2.5","release-it":"17.1.1","typescript":"5.4.2","@types/node":"^18.19.23","lint-staged":"^15.2.2","@nestjs/core":"^11.0.6","@nestjs/common":"^11.0.6","@types/express":"^4.17.21","@nestjs/graphql":"^13.0.2","class-validator":"0.14.1","keycloak-connect":"npm:@clemax/keycloak-connect@26.2.0","reflect-metadata":"0.2.1","class-transformer":"0.5.1","typescript-eslint":"^7.2.0","eslint-config-prettier":"9.1.0","eslint-plugin-prettier":"5.1.3"},"peerDependencies":{"@nestjs/core":">=6.0.0 <12.0.0","@nestjs/common":">=6.0.0 <12.0.0","@nestjs/graphql":">=6","keycloak-connect":"npm:@clemax/keycloak-connect@>=10.0.0"},"peerDependenciesMeta":{"@nestjs/graphql":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/nest-keycloak-connect_2.1.0_1784407845341_0.8673830362393185","host":"s3://npm-registry-packages-npm-production"}},"2.1.1":{"name":"@clemax/nest-keycloak-connect","version":"2.1.1","description":"keycloak-nodejs-connect module for Nest","author":{"name":"John Joshua Ferrer","email":"johnjoshuaferrer@disroot.org"},"license":"MIT","scripts":{"start:dev":"tsc -w","clean":"rimraf dist","build":"tsc","release":"release-it","release:alpha":"release-it --preReleaseId=alpha --npm.tag=next --github.preRelease","format":"prettier src --write","lint":"eslint src","prepare":"husky"},"keywords":["nestjs","keycloak","typescript"],"repository":{"type":"git","url":"git+https://github.com/ferrerojosh/nest-keycloak-connect.git"},"bugs":{"url":"https://github.com/ferrerojosh/nest-keycloak-connect/issues"},"main":"./dist/index.js","types":"./dist/index.d.ts","typesVersions":{"*":{"dist/index.d.ts":["dist/index.d.ts"],"*":["dist/*"]}},"exports":{".":"./dist/index.js","./*":"./dist/*"},"peerDependencies":{"@nestjs/common":">=6.0.0 <12.0.0","@nestjs/core":">=6.0.0 <12.0.0","@nestjs/graphql":">=6","keycloak-connect":"npm:@clemax/keycloak-connect@>=10.0.0"},"devDependencies":{"@nestjs/common":"^11.0.6","@nestjs/core":"^11.0.6","@nestjs/graphql":"^13.0.2","@types/express":"^4.17.21","@types/node":"^18.19.23","class-transformer":"0.5.1","class-validator":"0.14.1","cpr":"3.0.1","eslint":"8.57.0","eslint-config-prettier":"9.1.0","eslint-plugin-prettier":"5.1.3","graphql":"^16.10.0","husky":"^9.0.11","keycloak-connect":"npm:@clemax/keycloak-connect@26.2.0","lint-staged":"^15.2.2","prettier":"3.2.5","reflect-metadata":"0.2.1","release-it":"17.1.1","rimraf":"3.0.2","rxjs":"7.8.1","ts-node":"10.8.2","typescript":"5.4.2","typescript-eslint":"^7.2.0"},"peerDependenciesMeta":{"@nestjs/graphql":{"optional":true}},"funding":[{"type":"individual","url":"https://www.paypal.me/ferrerojosh/"},{"type":"github","url":"https://github.com/sponsors/ferrerojosh"}],"volta":{"node":"21.7.1"},"lint-staged":{"**/*.ts":["prettier --write","eslint"]},"packageManager":"pnpm@9.1.0-0+sha512.568e95e38592215a03fa2cb02a58b67c6452e51b176d9941d546a59a471c42e2b4c2428bf286addcbe4e2dec98e682e2df0fa93a5082cf3493afc496affd8ffb","gitHead":"ee4895284b87faafe734783985ea49c84991a8d3","_id":"@clemax/nest-keycloak-connect@2.1.1","homepage":"https://github.com/ferrerojosh/nest-keycloak-connect#readme","_nodeVersion":"22.22.2","_npmVersion":"11.14.1","dist":{"integrity":"sha512-djcDuCZun3+JvcQDC2NmGi3ltKFZPeR0eC9fnYh53+155GiTWW6PY87vTCvEoLY5bXDmIigg86Wn+5oD7+mHNA==","shasum":"fe099164b4a254b46bc00ce76034ba3ed53e4a42","tarball":"https://registry.npmjs.org/@clemax/nest-keycloak-connect/-/nest-keycloak-connect-2.1.1.tgz","fileCount":43,"unpackedSize":86463,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC3uSmLB0Jd56+odl5yU/ADAqgjJPf8PvHt+QXlzVe6UAIhAOt6Rc/qvxu8+sn3mEnV5rEyfVDNWl2yekHGY4IVkVhj"}]},"_npmUser":{"name":"clemax","email":"clementhamada@protonmail.com"},"directories":{},"maintainers":[{"name":"clemax","email":"clementhamada@protonmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nest-keycloak-connect_2.1.1_1784408045225_0.6987657035865829"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-06T16:57:21.857Z","modified":"2026-07-18T20:54:05.499Z","2.0.0":"2026-03-06T16:57:22.062Z","2.1.0":"2026-07-18T20:50:45.473Z","2.1.1":"2026-07-18T20:54:05.347Z"},"bugs":{"url":"https://github.com/ferrerojosh/nest-keycloak-connect/issues"},"author":{"name":"John Joshua Ferrer","email":"johnjoshuaferrer@disroot.org"},"license":"MIT","homepage":"https://github.com/ferrerojosh/nest-keycloak-connect#readme","keywords":["nestjs","keycloak","typescript"],"repository":{"type":"git","url":"git+https://github.com/ferrerojosh/nest-keycloak-connect.git"},"description":"keycloak-nodejs-connect module for Nest","maintainers":[{"name":"clemax","email":"clementhamada@protonmail.com"}],"readme":"<div align=\"center\">\r\n  \r\n# Nest Keycloak Connect\r\n\r\n### You are currently viewing the pre-release documentation for version 2.0. \r\n## Click [here](https://github.com/ferrerojosh/nest-keycloak-connect/tree/v1.0) for the 1.0 stable release documentation.\r\n\r\n  \r\n![GitHub Issues or Pull Requests](https://img.shields.io/github/issues/ferrerojosh/nest-keycloak-connect?style=for-the-badge)\r\n![GitHub License](https://img.shields.io/github/license/ferrerojosh/nest-keycloak-connect?style=for-the-badge)\r\n  \r\n![NPM Version](https://img.shields.io/npm/v/nest-keycloak-connect?style=for-the-badge)\r\n![NPM dev or peer Dependency Version](https://img.shields.io/npm/dependency-version/nest-keycloak-connect/peer/%40nestjs%2Fcommon?style=for-the-badge)\r\n![NPM dev or peer Dependency Version](https://img.shields.io/npm/dependency-version/nest-keycloak-connect/peer/keycloak-connect?style=for-the-badge)\r\n\r\n![GitHub Actions Workflow Status](https://img.shields.io/github/actions/workflow/status/ferrerojosh/nest-keycloak-connect/build.yml?style=for-the-badge)\r\n![NPM Weekly Downloads](https://img.shields.io/npm/dw/nest-keycloak-connect?style=for-the-badge)\r\n![NPM Total Downloads](https://img.shields.io/npm/dt/nest-keycloak-connect?style=for-the-badge)\r\n\r\nAn adapter for [keycloak-nodejs-connect](https://github.com/keycloak/keycloak-nodejs-connect)\r\n\r\n</div>\r\n\r\n## Features\r\n\r\n- Protect your resources using [Keycloak's Authorization Services](https://www.keycloak.org/docs/latest/authorization_services/).\r\n- Simply add `@Resource`, `@Scopes`, or `@Roles` in your controllers and you're good to go.\r\n- Compatible with [Fastify](https://github.com/fastify/fastify) platform.\r\n\r\n## Installation\r\n\r\n### Yarn\r\n\r\n```bash\r\nyarn add nest-keycloak-connect keycloak-connect\r\n```\r\n\r\n### NPM\r\n\r\n```bash\r\nnpm install nest-keycloak-connect keycloak-connect --save\r\n```\r\n\r\n## Getting Started\r\n\r\n### Module registration\r\n\r\nRegistering the module:\r\n\r\n```typescript\r\nKeycloakConnectModule.register({\r\n  authServerUrl: 'http://localhost:8080', // might be http://localhost:8080/auth for older keycloak versions\r\n  realm: 'master',\r\n  clientId: 'my-nestjs-app',\r\n  secret: 'secret',\r\n  policyEnforcement: PolicyEnforcementMode.PERMISSIVE, // optional\r\n  tokenValidation: TokenValidation.ONLINE, // optional\r\n});\r\n```\r\n\r\nAsync registration is also available:\r\n\r\n```typescript\r\nKeycloakConnectModule.registerAsync({\r\n  useExisting: KeycloakConfigService,\r\n  imports: [ConfigModule],\r\n});\r\n```\r\n\r\n#### KeycloakConfigService\r\n\r\n```typescript\r\nimport { Injectable } from '@nestjs/common';\r\nimport {\r\n  KeycloakConnectOptions,\r\n  KeycloakConnectOptionsFactory,\r\n  PolicyEnforcementMode,\r\n  TokenValidation,\r\n} from 'nest-keycloak-connect';\r\n\r\n@Injectable()\r\nexport class KeycloakConfigService implements KeycloakConnectOptionsFactory {\r\n  createKeycloakConnectOptions(): KeycloakConnectOptions {\r\n    return {\r\n      // http://localhost:8080/auth for older keycloak versions\r\n      authServerUrl: 'http://localhost:8080',\r\n      realm: 'master',\r\n      clientId: 'my-nestjs-app',\r\n      secret: 'secret',\r\n      policyEnforcement: PolicyEnforcementMode.PERMISSIVE,\r\n      tokenValidation: TokenValidation.ONLINE,\r\n    };\r\n  }\r\n}\r\n```\r\n\r\nYou can also register by just providing the `keycloak.json` path and an optional module configuration:\r\n\r\n```typescript\r\nKeycloakConnectModule.register(`./keycloak.json`, {\r\n  policyEnforcement: PolicyEnforcementMode.PERMISSIVE,\r\n  tokenValidation: TokenValidation.ONLINE,\r\n});\r\n```\r\n\r\n### Guards\r\n\r\nRegister any of the guards either globally, or scoped in your controller.\r\n\r\n#### Global registration using APP_GUARD token\r\n\r\n**_NOTE: These are in order, see https://docs.nestjs.com/guards#binding-guards for more information._**\r\n\r\n```typescript\r\nproviders: [\r\n  {\r\n    provide: APP_GUARD,\r\n    useClass: AuthGuard,\r\n  },\r\n  {\r\n    provide: APP_GUARD,\r\n    useClass: ResourceGuard,\r\n  },\r\n  {\r\n    provide: APP_GUARD,\r\n    useClass: RoleGuard,\r\n  },\r\n];\r\n```\r\n\r\n#### Scoped registration\r\n\r\n```typescript\r\n@Controller('cats')\r\n@UseGuards(AuthGuard, ResourceGuard)\r\nexport class CatsController {}\r\n```\r\n\r\n## What does these providers do ?\r\n\r\n### AuthGuard\r\n\r\nAdds an authentication guard, you can also have it scoped if you like (using regular `@UseGuards(AuthGuard)` in your controllers). By default, it will throw a 401 unauthorized when it is unable to verify the JWT token or `Bearer` header is missing.\r\n\r\n### ResourceGuard\r\n\r\nAdds a resource guard, which is permissive by default (can be configured see [options](#nest-keycloak-options)). Only controllers annotated with `@Resource` and methods with `@Scopes` are handled by this guard.\r\n\r\n**_NOTE: This guard is not necessary if you are using role-based authorization exclusively. You can use role guard exclusively for that._**\r\n\r\n### RoleGuard\r\n\r\nAdds a role guard, **can only be used in conjunction with resource guard when enforcement policy is PERMISSIVE**, unless you only use role guard exclusively.\r\nPermissive by default. Used by controller methods annotated with `@Roles` (matching can be configured)\r\n\r\n## Configuring controllers\r\n\r\nIn your controllers, simply do:\r\n\r\n```typescript\r\nimport {\r\n  Resource,\r\n  Roles,\r\n  Scopes,\r\n  Public,\r\n  RoleMatchingMode,\r\n} from 'nest-keycloak-connect';\r\nimport { Controller, Get, Delete, Put, Post, Param } from '@nestjs/common';\r\nimport { Product } from './product';\r\nimport { ProductService } from './product.service';\r\n\r\n@Controller()\r\n@Resource(Product.name)\r\nexport class ProductController {\r\n  constructor(private service: ProductService) {}\r\n\r\n  @Get()\r\n  @Public()\r\n  async findAll() {\r\n    return await this.service.findAll();\r\n  }\r\n\r\n  @Get()\r\n  @Roles({ roles: ['admin', 'other'] })\r\n  async findAllBarcodes() {\r\n    return await this.service.findAllBarcodes();\r\n  }\r\n\r\n  @Get(':code')\r\n  @Scopes('View')\r\n  async findByCode(@Param('code') code: string) {\r\n    return await this.service.findByCode(code);\r\n  }\r\n\r\n  @Post()\r\n  @Scopes('Create')\r\n  @ConditionalScopes((request, token) => {\r\n    if (token.hasRealmRole('sysadmin')) {\r\n      return ['Overwrite'];\r\n    }\r\n    return [];\r\n  })\r\n  async create(@Body() product: Product) {\r\n    return await this.service.create(product);\r\n  }\r\n\r\n  @Delete(':code')\r\n  @Scopes('Delete')\r\n  @Roles({ roles: ['admin', 'realm:sysadmin'], mode: RoleMatchingMode.ALL })\r\n  async deleteByCode(@Param('code') code: string) {\r\n    return await this.service.deleteByCode(code);\r\n  }\r\n\r\n  @Put(':code')\r\n  @Scopes('Edit')\r\n  async update(@Param('code') code: string, @Body() product: Product) {\r\n    return await this.service.update(code, product);\r\n  }\r\n}\r\n```\r\n\r\n## Decorators\r\n\r\nHere is the decorators you can use in your controllers.\r\n\r\n| Decorator          | Description                                                                                               |\r\n| ------------------ | --------------------------------------------------------------------------------------------------------- |\r\n| @KeycloakUser      | Retrieves the current Keycloak logged-in user. (must be per method, unless controller is request scoped.) |\r\n| @AccessToken       | Retrieves the access token used in the request                                                            |\r\n| @ResolvedScopes    | Retrieves the resolved scopes (used in @ConditionalScopes)                                                |\r\n| @EnforcerOptions   | Keycloak enforcer options.                                                                                |\r\n| @Public            | Allow any user to use the route.                                                                          |\r\n| @Resource          | Keycloak application resource name.                                                                       |\r\n| @Scopes            | Keycloak application scopes.                                                                              |\r\n| @ConditionalScopes | Conditional keycloak application scopes.                                                                  |\r\n| @Roles             | Keycloak realm/application roles.                                                                         |\r\n\r\n## Multi tenant configuration\r\n\r\nSetting up for multi-tenant is configured as an option in your configuration:\r\n\r\n```typescript\r\n{\r\n  // Add /auth for older keycloak versions\r\n  authServerUrl: 'http://localhost:8180/', // will be used as fallback\r\n  clientId: 'nest-api', // will be used as fallback\r\n  secret: 'fallback', // will be used as fallback\r\n  multiTenant: {\r\n    resolveAlways: true,\r\n    realmResolver: (request) => {\r\n      return request.get('host').split('.')[0];\r\n    },\r\n    realmSecretResolver: (realm, request) => {\r\n      const secrets = { master: 'secret', slave: 'password' };\r\n      return secrets[realm];\r\n    },\r\n    realmClientIdResolver: (realm, request) => {\r\n      const clientIds = { master: 'angular-app', slave: 'vue-app' };\r\n      return clientIds[realm];\r\n    },\r\n    // note to add /auth for older keycloak versions\r\n    realmAuthServerUrlResolver: (realm, request) => {\r\n      const authServerUrls = { master: 'https://master.local/', slave: 'https://slave.local/' };\r\n      return authServerUrls[realm];\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n## Configuration options\r\n\r\n### Keycloak Options\r\n\r\nFor Keycloak options, refer to the official [keycloak-connect](https://github.com/keycloak/keycloak-nodejs-connect/blob/main/middleware/auth-utils/config.js) library.\r\n\r\n### Nest Keycloak Options\r\n\r\n| Option            | Description                                                              | Required | Default      |\r\n| ----------------- | ------------------------------------------------------------------------ | -------- | ------------ |\r\n| cookieKey         | Cookie Key                                                               | no       | KEYCLOAK_JWT |\r\n| policyEnforcement | Sets the policy enforcement mode                                         | no       | PERMISSIVE   |\r\n| tokenValidation   | Sets the token validation method                                         | no       | ONLINE       |\r\n| multiTenant       | Sets the options for [multi-tenant configuration](#multi-tenant-options) | no       | -            |\r\n| roleMerge         | Sets the merge mode for @Role decorator                                  | no       | OVERRIDE     |\r\n\r\n### Multi Tenant Options\r\n\r\n| Option                     | Description                                                                                             | Required | Default |\r\n| -------------------------- | ------------------------------------------------------------------------------------------------------- | -------- | ------- |\r\n| resolveAlways              | Option to always resolve the realm and secret. Disabled by default.                                     | no       | false   |\r\n| realmResolver              | A function that passes a request (from respective platform i.e express or fastify) and returns a string | yes      | -       |\r\n| realmSecretResolver        | A function that passes the realm string, and an optional request and returns the secret string          | no       | -       |\r\n| realmAuthServerUrlResolver | A function that passes the realm string, and an optional request and returns the auth server url string | no       | -       |\r\n| realmClientIdResolver      | A function that passes the realm string, and an optional request and returns the client-id string       | no       | -       |\r\n\r\n## Example app\r\n\r\nAn [example application](example) is provided in the source code with both Keycloak Realm and Postman requests for you to experiment with.\r\n","readmeFilename":"README.md"}