Skip to main content

6 posts tagged with "security"

View All Tags

Keycloak "Invalid parameter: redirect_uri" — Every Cause and Fix

· 7 min read
GR Patil
Phase Two

You clicked "Log in", Keycloak showed you "We are sorry… Invalid parameter: redirect_uri", and no amount of staring at the admin console explains why.

The short answer: the redirect_uri your application sent does not match, character for character after wildcard expansion, any entry in that client's Valid redirect URIs. The long answer is that Keycloak's matching rules are stricter and stranger than almost everyone assumes — in particular, it will reject any redirect_uri containing a query string, no matter what you registered.

Everything below was tested against Keycloak 26.7.3.

Phase Two Achieves ISO/IEC 27001 Certification

· 3 min read
Jeff Patzer
Phase Two

Phase Two is excited to announce that we are now ISO/IEC 27001 certified.

This milestone reflects how seriously we take security and compliance across our platform, operations, and internal processes. We completed this as a fast follow to our September 17, 2025 SOC 2 Type II compliance milestone, reaching full ISO/IEC 27001 certification just over six months later as part of our commitment to building a mature, enterprise-ready security program.

Learn more at our Trust Center: trust.phasetwo.io.

Web Application Security with Your Keycloak Deployment

· 5 min read
Jeff Patzer
Phase Two

As more companies adopt Keycloak for enterprise identity and access management, security is no longer just a back-end concern. One of the most frequent questions we hear at Phase Two is:

"Should I put a Web Application Firewall (WAF) in front of Keycloak?"

The short answer? It depends—but it's a smart question to ask.

In this post, we'll break down what Keycloak provides out of the box, explore common attack vectors (especially around authentication endpoints), and help you evaluate whether you need to add an external firewall or WAF to your deployment.