Try not to implement your own integration
OAuth2 and OpenID Connect are simple protocols, and their simplicity is, in part, due to the effort that’s been made to make the protocol easier to use by client applications, but not necessarily to implement them from scratch. You may feel tempted to write your own code to integrate with Keycloak, but this is usually a bad choice.
You should rely on well-known and widely used libraries, frameworks, or capabilities provided by the platform where your application is deployed.
By doing that, you can focus on your business and, most importantly, delegate to people who are specialized and focused on these standards to keep their implementations always up to date with the latest versions of the specifications, as well as with any fixes for security vulnerabilities and security best practices.
Also, remember that the more people there are using an implementation, the less likely it is that you will face bugs and security vulnerabilities...