# Managing modalities using the REST-API and KeyCloak

**URL:** https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137
**Category:** General
**Tags:** rest-api
**Created:** [August 20, 2025, 12:47pm UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137 "2025-08-20T12:47:43Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![kenmunyao](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/kenmunyao/32/2511_2.png) [@kenmunyao](https://discourse.orthanc-server.org/u/kenmunyao)
#### Post date: [August 20, 2025, 12:47pm UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/1 "2025-08-20T12:47:43Z")

</div>

Hello,

Amazing product first off, extremely grateful for the releases and uptades so far. I have Orthanc (version 1.12.9) with the authorization-plugin (version 0.10.1) and KeyCloak (version 26.2.5) setup and working wonderfully so thank you very much OrthancTeam!

On modalities; I am aware these can be added to the config, but I would want to use the REST-API to view, add, update and delete modalities dynamically. I had a custom python plugin that sends API requests to the REST-API to do this, but on upgrading to use the authorization plugin and KeyCloak, I get a 403 when I send PUT/DELETE requests to the REST-API.

To remedey, I have given all permissions to my admin user in the permissions.json file, and generated an api-key for the user on KeyCloak as a user attribute. I was now able to do REST-API requests against study, series and instance resources, including PUT/POST, but for modalities I can only do GET requests, PUT/Delete requests still get a 403 error.

Now my query; is the api-key attribute supposed to be used for the modality resource or this is limited to study/series/instance/patient resources? If it is not meant for managing modalities, what may I use instead?

Here is a snippet of my config file for reference: [Orthanc\_Json\_File — Codefile](https://codefile.io/f/CYbCWl8Z3g)  
And the curl response:

 ![image](https://discourse.orthanc-server.org/uploads/default/original/2X/2/256e7ea1f99e0f5332341268a747d4dffc1dfe1d.png)

---

<div class="post-metadata">

### Author: ![alainmazy](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/alainmazy/32/1576_2.png) [@alainmazy](https://discourse.orthanc-server.org/u/alainmazy)
#### Post date: [August 25, 2025, 2:51pm UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/2 "2025-08-25T14:51:26Z")

</div>

Hi @kenmunyao

Actually, I think the problem is that there are no default permissions defined for the PUT and DELETE requests on the `/modalities` route.

You should probably just add something like:

```auto
        "ExtraPermissions" : [
             ["put", "^/modalities/(.*)$", "admin-permissions"],
             ["delete", "^/modalities/(.*)$", "admin-permissions"],
        ]

```

Please tell me if that works and I’ll add them in the defaults for the next release.

HTH,

Alain

---

<div class="post-metadata">

### Author: ![kenmunyao](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/kenmunyao/32/2511_2.png) [@kenmunyao](https://discourse.orthanc-server.org/u/kenmunyao)
#### Post date: [August 26, 2025, 5:04am UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/3 "2025-08-26T05:04:57Z")

</div>

Hello @alainmazy,

Yes this works! Terrific!

Adding this config to the default config is a splendid idea.

Thank you very much 😃

---

<div class="post-metadata">

### Author: ![alainmazy](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/alainmazy/32/1576_2.png) [@alainmazy](https://discourse.orthanc-server.org/u/alainmazy)
#### Post date: [August 26, 2025, 10:11am UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/4 "2025-08-26T10:11:33Z")

</div>

> [@kenmunyao](#):
>
> Adding this config to the default config is a splendid idea.

Done in [this commit](https://orthanc.uclouvain.be/hg/orthanc-authorization/rev/a9af7e0fa172).

---

<div class="post-metadata">

### Author: ![kenmunyao](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/kenmunyao/32/2511_2.png) [@kenmunyao](https://discourse.orthanc-server.org/u/kenmunyao)
#### Post date: [August 27, 2025, 5:38am UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/5 "2025-08-27T05:38:08Z")

</div>

@alainmazy I also noticed while get requests on /modalities works, APIs like /modalities/{id}/configuration don’t with the api-key unless extra permissions for get are explicitly added.

You may consider adding in the default config as below:

```yaml
// add-delete modalities through the Rest API

```

```yaml
[“get”, “^/modalities/(.*)$”, “admin-permissions”],

```

```yaml
[“put”, “^/modalities/(.*)$”, “admin-permissions”],

```

```yaml
[“delete”, “^/modalities/(.*)$”, “admin-permissions”]

```

---

<div class="post-metadata">

### Author: ![alainmazy](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/alainmazy/32/1576_2.png) [@alainmazy](https://discourse.orthanc-server.org/u/alainmazy)
#### Post date: [August 28, 2025, 7:49am UTC](https://discourse.orthanc-server.org/t/managing-modalities-using-the-rest-api-and-keycloak/6137/6 "2025-08-28T07:49:21Z")

</div>

I have updated the default permissions to grant access to GET `/modalities/../configuration` to all users that are allowed to query or send to a modality: [orthanc-authorization: 0b0222d3a7f9](https://orthanc.uclouvain.be/hg/orthanc-authorization/rev/0b0222d3a7f9)
