Create the proxy and the Keycloak resource
Step 2 of 4 in Federate wallet sign-in to Keycloak.
Create the hosted proxy with deployment: HOSTED, authenticationMode: FEDERATED_ONLY, a dedicated
slug such as wallet-proxy, and purposes CREDENTIAL_ISSUANCE and WALLET_LOGIN. Then call the same
operation a second time with deployment: EXTERNAL, the Keycloak realm issuer and
usages: ["HOSTED_LOGIN_UPSTREAM"]. An external resource must omit slug; creation runs discovery and
leaves no partial resource when discovery fails.
Register the public wallet client on the hosted proxy: authorization_code, PKCE and the wallet's own
redirect URI. Its clientId is what the wallet sends.
Validate the external resource's discovery snapshot (issuer, grants, scopes, endpoints, client authentication methods), then activate both resources.
Next
Continue with step 3, Create, validate and enable the federation binding.