The external Keycloak sync program synchronizes a single subject
through the UUID-keyed idempotent upsert
PUT /api/rbac/subjects/{subjectUuid}. The UUID in the path
is the same UUID as in Keycloak. Creating a new subject returns
201 Created, updating an existing subject’s name returns
200 OK. Only a global-admin may synchronize subjects
(others are rejected with 403), and only realm-prefixed
names are accepted (others are rejected with 400).
| name | value |
|---|---|
| subjectUuid | 238a0004-0000-0000-0000-000000000004 |
| subjectName | sync-eve |
| subjectType | USER |
HTTP PUT "/api/rbac/subjects/238a0004-0000-0000-0000-000000000004" \
-H "Authorization: Bearer $HSADMINNG_JWT_BEARER" \
`# {` \
`# "comment" : "an authenticated user without the global-admin role",` \
`# "sub" : "uuid<tst-customer_admin_xxx>"` \
`# }` \
-H 'Content-Type: application/json' \
--data-binary @- <<EOF
{
"name" : "sync-eve",
"type" : "USER"
}
EOF
=> status: 403 FORBIDDEN
{
"timestamp" : "2026-07-17 01:44:28",
"path" : "",
"statusCode" : 403,
"statusPhrase" : "Forbidden",
"message" : "ERROR: [403] only a global-admin may upsert subjects"
}
generated on 2026-07-17 01:44:28 for branch