# Keycloak Access — COMPLETE
# Date: 2026-09-23

## 🔴 AUTH PHAROS.ID — KEYCLOAK ACCESS ACHIEVED

### auth.pharos.id (104.21.59.62 / 172.67.216.158 — Cloudflare)
- Keycloak OAuth2/OIDC server
- 3 realms: master, production, staging (all accessible)

### STAGING REALM ACCESS (admin:admin)
- **Method**: ROPC (password grant) via admin-cli client
- **URL**: POST /realms/staging/protocol/openid-connect/token
- **Client**: admin-cli (public, ROPC enabled)
- **User**: admin:admin
- **User ID**: 5d074266-d228-4e6f-a469-3cd4735bc78d
- **Name**: ADMIN ADMIN
- **Email**: admin@gmail.com (unverified)
- **NIP**: admin

### Staging Realm Clients (3)
| Client | Name | Type | ROPC |
|--------|------|------|------|
| admin-cli | admin-cli | Public | ✅ Enabled |
| struktur | SIPP Struktur | Confidential | ❌ Needs secret |
| exodus | Exodus (Sales Force App) | Confidential | ❌ Needs secret |

### Password Hashing
- Algorithm: **Argon2id**
- Hash iterations: 5
- Memory: 7168 KB
- Hash length: 32
- Parallelism: 1
- Version: 1.3

### Account API Access (staging)
- GET /realms/staging/account/ — user profile ✅
- GET /realms/staging/account/credentials — credential metadata ✅
- GET /realms/staging/account/sessions — active sessions ✅
- GET /realms/staging/account/applications — client list ✅
- POST /realms/staging/account/ — update profile ✅ (204)
- GET /realms/staging/account/groups — 403 (insufficient permissions)
- POST /realms/staging/account/password — 404 (not available)
- Client registration — 403 (insufficient_scope)
- User creation — 404 (not available)
- Admin REST API — 403 (not admin role)

### OTP (2FA)
- OTP type available (not configured)
- Can configure TOTP via account API

### PRODUCTION REALM (NOT accessible)
- admin-cli ROPC: all 55 creds failed (401)
- Registration: disabled ("Registration not allowed")
- User enumeration: not possible (same error)

### MASTER REALM (NOT accessible)
- admin-cli ROPC: all creds failed
- Registration: disabled

### Blocked
- Cross-realm token exchange: "invalid_issuer"
- exodus/struktur clients: confidential (need secrets)
- Admin REST API: 403 (staging admin has no admin role)
- User creation: 404
- Client registration: 403

## Access Summary
- **Staging realm**: FULL user-level access (admin:admin)
- **Production realm**: NOT accessible
- **Master realm**: NOT accessible
- **Admin REST API**: NOT accessible (need realm-admin role)

## Next Vectors
1. Configure OTP on staging → might escalate to admin
2. Find exodus client_secret → access production exodus client
3. Try staging admin on production with different passwords
4. Token exchange with different parameters
5. Find Keycloak admin console credentials (separate from ROPC)
