---
title: "GET /sources/kerberos/{slug}/"
method: GET
path: "/sources/kerberos/{slug}/"
tags: ["sources"]
---

# GET /sources/kerberos/{slug}/

`GET /sources/kerberos/{slug}/`

Kerberos Source Viewset

## Path parameters

- `slug` string, required — Internal source name, used in URLs.

## Response `200`

- KerberosSource — Kerberos Source Serializer
  - `pk` string, uuid, required
  - `name` string, required — Source's display Name.
  - `slug` string, required — Internal source name, used in URLs.
  - `enabled` boolean
  - `promoted` boolean — When enabled, this source will be displayed as a prominent button on the login page, instead of a small icon.
  - `authentication_flow` string, uuid, nullable — Flow to use when authenticating existing users.
  - `enrollment_flow` string, uuid, nullable — Flow to use when enrolling new users.
  - `user_property_mappings` string[]
  - `group_property_mappings` string[]
  - `component` string, required — Get object component so that we know how to edit the object
  - `verbose_name` string, required — Return object's verbose_name
  - `verbose_name_plural` string, required — Return object's plural verbose_name
  - `meta_model_name` string, required — Return internal model name
  - `policy_engine_mode` 'all' | 'any'
  - `user_matching_mode` 'identifier' | 'email_link' | 'email_deny' | 'username_link' | 'username_deny'
  - `managed` string, nullable, required — Objects that are managed by authentik. These objects are created and updated automatically. This flag only indicates that an object can be overwritten by migrations. You can still modify the objects via the API, but expect changes to be overwritten in a later update.
  - `user_path_template` string
  - `icon` string
  - `icon_url` string, required
  - `icon_themed_urls` ThemedUrls, required — Themed URLs - maps theme names to URLs for light and dark themes
    - `light` string, nullable
    - `dark` string, nullable
  - `group_matching_mode` 'identifier' | 'name_link' | 'name_deny'
  - `realm` string, required — Kerberos realm
  - `krb5_conf` string — Custom krb5.conf to use. Uses the system one by default
  - `kadmin_type` 'MIT' | 'Heimdal'
  - `sync_users` boolean — Sync users from Kerberos into authentik
  - `sync_users_password` boolean — When a user changes their password, sync it back to Kerberos
  - `sync_principal` string — Principal to authenticate to kadmin for sync.
  - `sync_ccache` string — Credentials cache to authenticate to kadmin for sync. Must be in the form TYPE:residual
  - `connectivity` object, nullable, required — Get cached source connectivity
  - `spnego_server_name` string — Force the use of a specific server name for SPNEGO. Must be in the form HTTP@hostname
  - `spnego_ccache` string — Credential cache to use for SPNEGO in form type:residual
  - `password_login_update_internal_password` boolean — If enabled, the authentik-stored password will be updated upon login with the Kerberos password backend
  - `sync_outgoing_trigger_mode` 'none' | 'immediate' | 'deferred_end'

## Other responses

- `400`
- `403`

---

[API](https://skmtc.dev/goauthentik/apis/authentik.md) · [All operations](https://skmtc.dev/goauthentik/apis/authentik/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/goauthentik/authentik/revisions/4e42e86021d7/schema)
