Anyway as I said if I remove the groups from the access token it works, so I think this proves the error is not from Keycloak...
In XWiki I add the scope "microprofile-jwt", login fails. I remove the scope, login works, I add the scope, login fails... No change in Keycloak... so something breaks on the XWiki side...
This message was sent by Atlassian Jira (v9.3.0#930000-sha1:287aeb6)
If image attachments aren't displayed, see this article.