{
  "id": 12815107,
  "title": "How to secure a Spring Security client application with OIDC (using pac4j)",
  "url": "https://urgent.news/2026/10/08/how-to-secure-a-spring-security-client-application-with-oidc-using",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-08T07:22:30.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jleleu/how-to-secure-a-spring-security-client-application-with-oidc-using-pac4j-2one"
  },
  "original_language": "en",
  "account": "To integrate OpenID Connect (OIDC) login into an existing Spring Security application using pac4j, follow these steps:\n\n1. Set up a new Maven project with Java 17 or later and Spring Boot v4.x, which includes Spring Security v7 or Spring Boot v3.x with Spring Security v6. The bridge supports both versions.\n\n2. Create the pom.xml file with Spring Boot parent dependency and specify Java version and project details.\n\n3. Add the necessary Maven dependencies in pom.xml:\n- spring-boot-starter-webmvc for MVC support\n- spring-boot-starter-security for Spring Security\n- org.pac4j:jakartaee-pac4j (version 8.0.4) for the OIDC authentication implementation\n- org.pac4j:pac4j-oidc (version 6.5.9) for OpenID Connect support\n- org.pac4j:spring-security-pac4j (version 10.1.0) as the bridge to integrate pac4j with Spring Security\n\n4. Configure pac4j by creating a Pac4jConfig.java class annotated with @Configuration. Declare an OidcClient bean with OIDC client configuration and an authorization generator to convert trusted profile attributes into application roles.\n\n5. Ensure your Spring Security application is configured with SpringBootApp.java as the main class.\n\nBy following these steps and using the appropriate pac4j artifacts and configuration, you can seamlessly integrate OIDC login into an existing Spring Security application while preserving the existing authorization mechanism.",
  "summary": "If you already have Spring Security in your application, with hasRole rules, @PreAuthorize on services and code reading SecurityContextHolder and you want to add an OpenID Connect login, while keeping that authorization code, you can use pac4j for that. Whatever the provider (Keycloak, Microsoft Entra ID, Okta, a CAS server, etc.), once pac4j has authenticated the user, it can make that user…",
  "key_points": [
    "Set up Maven project with Spring Boot and Spring Security",
    "Add pac4j dependencies for OIDC authentication in pom.xml",
    "Configure Pac4j by creating Pac4jConfig.java with OidcClient bean"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}