---
title: "Control Model Access with OIDC (Azure AD/Keycloak/etc.)"
url: "/docs/proxy/jwt_auth_arch"
canonical_url: "https://docs.litellm.ai/docs/proxy/jwt_auth_arch"
type: "docs"
last_updated: "2026-10-09"
related:
  - "/docs/proxy/oauth2"
  - "/docs/oidc"
---
# Control Model Access with OIDC (Azure AD/Keycloak/etc.)

> Index of all LiteLLM docs: https://docs.litellm.ai/llms.txt


> **LiteLLM Enterprise feature: JWT Auth.** Requires an Enterprise license (`LITELLM_LICENSE`). Talk to sales: https://www.litellm.ai/enterprise#talk-to-sales

## Example Token 

**Azure AD**

```bash
{
  "sub": "1234567890",
  "name": "John Doe",
  "email": "john.doe@example.com",
  "roles": ["basic_user"] # 👈 ROLE
}
```
**Keycloak**

```bash
{
  "sub": "1234567890",
  "name": "John Doe",
  "email": "john.doe@example.com",
  "resource_access": {
    "litellm-test-client-id": {
      "roles": ["basic_user"] # 👈 ROLE
    }
  }
}
```

## Proxy Configuration

**Azure AD**

```yaml
general_settings:
  enable_jwt_auth: True 
  litellm_jwtauth:
    user_roles_jwt_field: "roles" # the field in the JWT that contains the roles 
    user_allowed_roles: ["basic_user"] # roles that map to an 'internal_user' role on LiteLLM 
    enforce_rbac: true # if true, will check if the user has the correct role to access the model
  
  role_permissions: # control what models are allowed for each role
    - role: internal_user
      models: ["anthropic-claude"]

model_list:
    - model_name: anthropic-claude
      litellm_params:
        model: claude-sonnet-5
    - model_name: openai-gpt-4o
      litellm_params:
        model: gpt-5.6-terra
```

**Keycloak**

```yaml
general_settings:
  enable_jwt_auth: True 
  litellm_jwtauth:
    user_roles_jwt_field: "resource_access.litellm-test-client-id.roles" # the field in the JWT that contains the roles
    user_allowed_roles: ["basic_user"] # roles that map to an 'internal_user' role on LiteLLM 
    enforce_rbac: true # if true, will check if the user has the correct role to access the model
  
  role_permissions: # control what models are allowed for each role
    - role: internal_user
      models: ["anthropic-claude"]

model_list:
    - model_name: anthropic-claude
      litellm_params:
        model: claude-sonnet-5
    - model_name: openai-gpt-4o
      litellm_params:
        model: gpt-5.6-terra
```

## How it works

1. Specify JWT_PUBLIC_KEY_URL - This is the public keys endpoint of your OpenID provider. For Azure AD it's `https://login.microsoftonline.com/{tenant_id}/discovery/v2.0/keys`. For Keycloak it's `{keycloak_base_url}/realms/{your-realm}/protocol/openid-connect/certs`.

1. Map JWT roles to LiteLLM roles - Done via `user_roles_jwt_field` and `user_allowed_roles`
    -  Currently just `internal_user` is supported for role mapping. 
2. Specify model access: 
    - `role_permissions`: control what models are allowed for each role. 
        - `role`: the LiteLLM role to control access for. Allowed roles = ["internal_user", "proxy_admin", "team"]
        - `models`: list of models that the role is allowed to access. 
    - `model_list`: parent list of models on the proxy. [Learn more](./configs.md#llm-configs-model_list)

3. Model Checks: The proxy will run validation checks on the received JWT. [Code](https://github.com/BerriAI/litellm/blob/3a4f5b23b5025b87b6d969f2485cc9bc741f9ba6/litellm/proxy/auth/user_api_key_auth.py#L284)

## Related pages

- [OAuth 2.0 Authentication](https://docs.litellm.ai/docs/proxy/oauth2.md)
- [[BETA] OpenID Connect (OIDC)](https://docs.litellm.ai/docs/oidc.md)
