{"id":6043,"date":"2026-09-23T13:56:47","date_gmt":"2026-09-23T13:56:47","guid":{"rendered":"https:\/\/itservicenet.net\/nextcloud-migrazione-identity-provider-ldap-oidc-entra-keycloak\/"},"modified":"2026-09-23T14:59:13","modified_gmt":"2026-09-23T14:59:13","slug":"migrate-nextcloud-from-ldap-to-openid-connect-entra-id-or-keycloak","status":"publish","type":"post","link":"https:\/\/itservicenet.net\/en\/migrate-nextcloud-from-ldap-to-openid-connect-entra-id-or-keycloak\/","title":{"rendered":"Nextcloud Identity Provider Migration: Strategies for LDAP, OpenID Connect, Entra ID and Keycloak"},"content":{"rendered":"<h2><strong>Index<\/strong><\/h2>\n<p><a href=\"#intro\"><u>Intro<\/u><\/a><\/p>\n<p class=\"p1\"><a href=\"#why\">Why User Identity Matters in Nextcloud<\/a><\/p>\n<p><a href=\"#preserve\">The Main Objective: Preserve Identity Continuity<\/a><\/p>\n<p class=\"p1\"><a href=\"#remapping\">Advantages of Identity Remapping<\/a><\/p>\n<p><a href=\"#migrating\">Migrating from LDAP to OpenID Connect<\/a><\/p>\n<p class=\"p1\"><a href=\"#ipm\">Identity Provider Migration as an Enterprise Architecture Project<\/a><\/p>\n<p><a href=\"#conclusion\"><u>Conclusion<\/u><\/a><\/p>\n\n\n<h2 id=\"intro\" class=\"wp-block-heading\"><strong>Intro<\/strong><\/h2>\n\n\n<div id=\"brxe-36ef46\" class=\"brxe-text\">\n<p>Migrating a Nextcloud environment is not simply a matter of moving files from one system to another. In enterprise environments, one of the most critical aspects of any migration project is <strong>preserving user identities and their relationships with existing data, permissions, groups, and applications<\/strong>.<\/p>\n<p>This becomes particularly important when changing the authentication architecture, for example when migrating from LDAP or Active Directory to a modern Identity Provider based on <strong>OpenID Connect (OIDC)<\/strong>, Microsoft Entra ID, Keycloak, or another centralized identity platform.<\/p>\n<p>If the migration is not carefully designed, Nextcloud may interpret the new authentication identity as a completely new user. This can break the relationship between the user and existing files, shares, permissions, group memberships, application settings, and metadata.<\/p>\n<p>For this reason, an Identity Provider migration should be treated as an <strong>identity continuity project<\/strong>, not simply as a login configuration change.<\/p>\n<\/div>\n\n\n<h2 id=\"why\" class=\"wp-block-heading\"><strong><strong><strong><strong><strong><strong>Why User Identity Matters in Nextcloud<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/h2>\n\n\n<p>Within Nextcloud, a user is much more than a username or an email address.<\/p>\n<p>Over time, Nextcloud creates multiple relationships between each user and the platform, including:<\/p>\n<ul>\n<li>personal files and folders;<\/li>\n<li>files and folders shared with other users;<\/li>\n<li>incoming shares;<\/li>\n<li>group memberships;<\/li>\n<li>Team Folder permissions;<\/li>\n<li>application preferences;<\/li>\n<li>activity history;<\/li>\n<li>metadata;<\/li>\n<li>ownership information;<\/li>\n<li>collaboration relationships;<\/li>\n<li>application-specific references.<\/li>\n<\/ul>\n<p>The key challenge during an authentication migration is therefore to <strong>preserve the connection between the existing Nextcloud identity and the identity provided by the new Identity Provider<\/strong>.<\/p>\n<p>Consider a user currently authenticated through LDAP.<\/p>\n<p>The user may appear as:<\/p>\n<p>mario.rossi<\/p>\n<p>The same person may also exist in Microsoft Entra ID or Keycloak using the same username and email address.<\/p>\n<p>However, this does not necessarily mean that Nextcloud will automatically recognize both identities as belonging to the same user.<\/p>\n<p>Behind the visible username, authentication systems may use different unique identifiers.<\/p>\n<p>LDAP environments may rely on attributes such as:<\/p>\n<ul>\n<li>uid;<\/li>\n<li>entryUUID;<\/li>\n<li>objectGUID;<\/li>\n<li>sAMAccountName;<\/li>\n<li>userPrincipalName.<\/li>\n<\/ul>\n<p>An OpenID Connect Identity Provider may instead provide identifiers through claims such as:<\/p>\n<ul>\n<li>sub;<\/li>\n<li>preferred_username;<\/li>\n<li>email;<\/li>\n<li>upn.<\/li>\n<\/ul>\n<p>If these identifiers are not mapped correctly, Nextcloud may create a new account instead of associating the new authentication identity with the existing user.<\/p>\n\n\n<h2 id=\"preserve\" class=\"wp-block-heading\"><strong><br><strong><strong>The Main Objective: Preserve Identity Continuity<\/strong><\/strong><\/strong><\/h2>\n\n\n<div id=\"brxe-73e8bb\" class=\"brxe-text\">\n<p>The goal of a successful Nextcloud Identity Provider migration is straightforward:<\/p>\n<p><strong>the authentication system may change, but the user&#8217;s identity inside Nextcloud should remain consistent whenever possible.<\/strong><\/p>\n<p>From the user&#8217;s perspective, the transition should ideally be transparent.<\/p>\n<p>After logging in through the new Identity Provider, users should continue to find:<\/p>\n<ul>\n<li>their files;<\/li>\n<li>their shares;<\/li>\n<li>their group memberships;<\/li>\n<li>Team Folder access;<\/li>\n<li>application settings;<\/li>\n<li>collaboration history;<\/li>\n<li>permissions and access rights.<\/li>\n<\/ul>\n<p>Achieving this continuity requires a clear understanding of how identities are represented in both the current and future authentication systems.<\/p>\n<h3><strong>Strategy 1: Create New Accounts and Transfer Data<\/strong><\/h3>\n<p>The first migration strategy is to create new accounts using the target Identity Provider and transfer data from the old accounts to the new ones.<\/p>\n<p>This approach can be appropriate when:<\/p>\n<ul>\n<li>the number of users is relatively small;<\/li>\n<li>the sharing structure is simple;<\/li>\n<li>the environment does not contain a large number of complex permissions;<\/li>\n<li>the organization wants to reorganize its user structure;<\/li>\n<li>legacy accounts need to be consolidated or cleaned up;<\/li>\n<li>the migration is being used as an opportunity to redesign the environment.<\/li>\n<\/ul>\n<p>The process typically involves several phases.<\/p>\n<p>First, new user accounts are created using the target authentication system.<\/p>\n<p>The existing accounts should remain available during the migration period so that administrators can verify that all required information has been transferred correctly.<\/p>\n<p>Depending on the environment, the migration may involve:<\/p>\n<ul>\n<li>file ownership transfer;<\/li>\n<li>recreation of shares;<\/li>\n<li>validation of group membership;<\/li>\n<li>reconstruction of permissions;<\/li>\n<li>Team Folder access verification;<\/li>\n<li>application configuration checks.<\/li>\n<\/ul>\n<p>It is important to understand that transferring user data does not automatically guarantee that every relationship associated with that user will also be migrated.<\/p>\n<p>Different components inside Nextcloud may reference users in different ways.<\/p>\n<p>As a result, files, shares, metadata, application settings, and other user-related information must be validated individually according to the specific environment.<\/p>\n<p>Only after the migration has been tested and verified should the legacy accounts be disabled or removed.<\/p>\n<h4><strong>When This Strategy Works Best<\/strong><\/h4>\n<p>Creating new accounts and transferring data is generally more practical for smaller environments where administrators can manually validate the migration.<\/p>\n<p>For larger enterprise environments, however, this approach can become operationally complex because of the number of user relationships that need to be recreated.<\/p>\n<h3><strong>Strategy 2: Identity Remapping<\/strong><\/h3>\n<p>For larger Nextcloud environments, identity remapping is often a more suitable strategy.<\/p>\n<p>Instead of creating a completely new user, the objective is to ensure that the identity provided by the new authentication system is associated with the user that already exists inside Nextcloud.<\/p>\n<p>For example:<\/p>\n<p><strong>Existing identity<\/strong><\/p>\n<p>mario.rossi<\/p>\n<p><strong>New Identity Provider<\/strong><\/p>\n<p>mario.rossi<\/p>\n<p>At first sight, these accounts appear identical.<\/p>\n<p>However, matching usernames alone is not sufficient.<\/p>\n<p>The migration must determine which identifiers Nextcloud currently uses internally and which attributes or claims will be provided by the new Identity Provider.<\/p>\n<p>A mapping strategy must then be created between these identifiers.<\/p>\n<p>When identity mapping is correctly implemented, the user can authenticate through the new Identity Provider while continuing to access the resources associated with the existing Nextcloud identity.<\/p>\n<p>This may allow the organization to preserve:<\/p>\n<ul>\n<li>personal files;<\/li>\n<li>existing shares;<\/li>\n<li>group memberships;<\/li>\n<li>Team Folder permissions;<\/li>\n<li>application references;<\/li>\n<li>user preferences;<\/li>\n<li>collaboration history.<\/li>\n<\/ul>\n<\/div>\n\n\n<h2 id=\"remapping\" class=\"wp-block-heading\"><strong><strong><br><strong>Advantages of Identity Remapping<\/strong><\/strong><\/strong><\/h2>\n\n\n<div id=\"brxe-73e8bb\" class=\"brxe-text\">\n<p>The main advantage of this approach is continuity.<\/p>\n<p>Instead of migrating the user&#8217;s data to a new identity, the authentication mechanism is changed while the existing Nextcloud user relationship is preserved.<\/p>\n<p>This can significantly reduce the migration impact in environments with:<\/p>\n<ul>\n<li>hundreds or thousands of users;<\/li>\n<li>complex group structures;<\/li>\n<li>many shared folders;<\/li>\n<li>extensive Team Folder usage;<\/li>\n<li>long-established collaboration workflows;<\/li>\n<li>multiple integrated applications.<\/li>\n<\/ul>\n<p>However, identity remapping requires careful planning and testing.<\/p>\n<p>Incorrect mappings can result in duplicate accounts, inaccessible resources, or permissions being assigned to the wrong user.<\/p>\n<\/div>\n\n\n<h2 id=\"migrating\" class=\"wp-block-heading\"><strong><strong><strong>Migrating from LDAP to OpenID Connect<\/strong><\/strong><\/strong><\/h2>\n\n\n<div id=\"brxe-73e8bb\" class=\"brxe-text\">\n<p>One increasingly common scenario is the migration from LDAP-based authentication to an Identity Provider that supports OpenID Connect.<\/p>\n<p>LDAP has traditionally been widely used for centralized directory services.<\/p>\n<p>Modern identity architectures increasingly rely on protocols such as:<\/p>\n<ul>\n<li>OpenID Connect;<\/li>\n<li>OAuth 2.0;<\/li>\n<li>SAML.<\/li>\n<\/ul>\n<p>OpenID Connect allows applications such as Nextcloud to delegate authentication to a centralized Identity Provider.<\/p>\n<p>Instead of Nextcloud validating credentials directly against LDAP, the authentication process can be handled by platforms such as:<\/p>\n<ul>\n<li>Microsoft Entra ID;<\/li>\n<li>Keycloak;<\/li>\n<li>other enterprise Identity Providers supporting OIDC.<\/li>\n<\/ul>\n<p>This architecture can simplify identity management and enable broader Single Sign-On strategies across multiple applications.<\/p>\n<h3><strong>Nextcloud with Microsoft Entra ID<\/strong><\/h3>\n<p>Microsoft Entra ID is frequently used as a centralized Identity Provider in organizations that already rely on Microsoft cloud services.<\/p>\n<p>Integrating Nextcloud with Entra ID can allow organizations to include Nextcloud within their existing identity architecture.<\/p>\n<p>Depending on the configuration, this can enable capabilities such as:<\/p>\n<ul>\n<li>Single Sign-On;<\/li>\n<li>Multi-Factor Authentication;<\/li>\n<li>Conditional Access;<\/li>\n<li>centralized account management;<\/li>\n<li>enterprise authentication policies;<\/li>\n<li>integration with existing Microsoft identity environments.<\/li>\n<\/ul>\n<p>The key point during a migration is determining which Entra ID claims should be used to identify Nextcloud users.<\/p>\n<p>Using the wrong identifier can result in Nextcloud treating existing users as new accounts.<\/p>\n<p>For this reason, attributes such as email addresses or usernames should not automatically be assumed to represent stable user identifiers.<\/p>\n<p>A proper migration assessment should determine which identity attributes remain consistent throughout the user lifecycle.<\/p>\n<h3><strong>Nextcloud with Keycloak<\/strong><\/h3>\n<p>Keycloak is another common Identity Provider used to centralize authentication across applications.<\/p>\n<p>It supports protocols such as:<\/p>\n<ul>\n<li>OpenID Connect;<\/li>\n<li>OAuth 2.0;<\/li>\n<li>SAML.<\/li>\n<\/ul>\n<p>Organizations can use Keycloak as an identity layer between Nextcloud and multiple identity sources.<\/p>\n<p>For example, Keycloak can integrate with:<\/p>\n<ul>\n<li>LDAP;<\/li>\n<li>Active Directory;<\/li>\n<li>external Identity Providers;<\/li>\n<li>enterprise directories;<\/li>\n<li>custom authentication systems.<\/li>\n<\/ul>\n<p>This architecture can provide organizations with greater control over authentication policies while allowing Nextcloud to rely on a standardized identity interface.<\/p>\n<p>Again, the critical aspect is ensuring that the identity delivered by Keycloak is mapped correctly to the existing Nextcloud user.<\/p>\n<\/div>\n\n\n<h2 id=\"ipm\" class=\"wp-block-heading\"><strong><strong><strong><strong>Identity Provider Migration as an Enterprise Architecture Project<\/strong><\/strong><\/strong><\/strong><\/h2>\n\n\n<div id=\"brxe-73e8bb\" class=\"brxe-text\">\n<p>Migrating authentication systems should not be viewed only as a technical configuration task.<\/p>\n<p>A modern Identity Provider can become the foundation of a broader <strong>Identity and Access Management (IAM)<\/strong> strategy.<\/p>\n<p>Centralizing identity management can make it possible to introduce or improve:<\/p>\n<ul>\n<li>Single Sign-On;<\/li>\n<li>Multi-Factor Authentication;<\/li>\n<li>centralized access policies;<\/li>\n<li>account lifecycle management;<\/li>\n<li>user provisioning;<\/li>\n<li>identity federation;<\/li>\n<li>security policies;<\/li>\n<li>application integration.<\/li>\n<\/ul>\n<p>Nextcloud therefore becomes one component of a larger enterprise identity ecosystem.<\/p>\n<p>Instead of independently managing authentication for every application, organizations can define centralized authentication policies and apply them consistently across multiple services.<\/p>\n<h3><strong>What to Assess Before Migrating<\/strong><\/h3>\n<p>Before starting the migration, the existing Nextcloud environment should be carefully analyzed.<\/p>\n<p>The assessment should include at least:<\/p>\n<ul>\n<li>number of users;<\/li>\n<li>current authentication backend;<\/li>\n<li>current user identifiers;<\/li>\n<li>LDAP attributes currently used;<\/li>\n<li>group structures;<\/li>\n<li>personal shares;<\/li>\n<li>group shares;<\/li>\n<li>Team Folder configuration;<\/li>\n<li>external storage configurations;<\/li>\n<li>application integrations;<\/li>\n<li>user provisioning methods;<\/li>\n<li>Single Sign-On configuration;<\/li>\n<li>application-specific user references;<\/li>\n<li>future Identity Provider architecture.<\/li>\n<\/ul>\n<p>It is also important to identify which user attributes are stable and unique.<\/p>\n<p>Email addresses, for example, may appear convenient as identity keys but can change over time.<\/p>\n<p>A dedicated immutable identifier may provide a more reliable mapping strategy.<\/p>\n<h3><strong>Testing the Migration<\/strong><\/h3>\n<p>Identity migrations should always be tested before being applied to production environments.<\/p>\n<p>A dedicated test environment can be used to simulate the migration process and verify how Nextcloud behaves when users authenticate through the new Identity Provider.<\/p>\n<p>Testing should verify at least:<\/p>\n<ul>\n<li>successful authentication;<\/li>\n<li>correct user identification;<\/li>\n<li>access to personal files;<\/li>\n<li>existing shares;<\/li>\n<li>group membership;<\/li>\n<li>Team Folder access;<\/li>\n<li>permissions;<\/li>\n<li>application functionality;<\/li>\n<li>account duplication;<\/li>\n<li>user provisioning behavior.<\/li>\n<\/ul>\n<p>A representative group of users should be selected for testing, including users with different permission structures and collaboration patterns.<\/p>\n<h3><strong>Avoiding Duplicate Accounts<\/strong><\/h3>\n<p>One of the most common risks during Identity Provider migration is accidental account duplication.<\/p>\n<p>For example, an existing LDAP account may appear in Nextcloud as:<\/p>\n<p>mario.rossi<\/p>\n<p>After enabling OpenID Connect authentication, the Identity Provider may create:<\/p>\n<p>mario.rossi@example.com<\/p>\n<p>From an administrator&#8217;s perspective, both accounts clearly belong to the same person.<\/p>\n<p>From Nextcloud&#8217;s perspective, however, they may represent two separate identities.<\/p>\n<p>The result may be that the user logs in successfully but sees an empty account without access to previous files and shares.<\/p>\n<p>This is why user mapping must be validated before enabling the new authentication system for the entire organization.<\/p>\n<h3><strong>Small Environment vs Enterprise Environment<\/strong><\/h3>\n<p>There is no single migration strategy that applies to every Nextcloud deployment.<\/p>\n<p>In a small environment, creating new accounts and transferring the required data may be the simplest approach.<\/p>\n<p>In larger enterprise environments, however, preserving the existing identity structure is often more important.<\/p>\n<p>An identity mapping strategy may therefore be preferable when:<\/p>\n<ul>\n<li>many users are involved;<\/li>\n<li>complex sharing relationships exist;<\/li>\n<li>Team Folders are widely used;<\/li>\n<li>the platform contains years of collaboration data;<\/li>\n<li>multiple applications depend on existing identities.<\/li>\n<\/ul>\n<p>The more relationships users have inside Nextcloud, the more important identity continuity becomes.<\/p>\n<h3><strong>From Authentication Migration to Business Continuity<\/strong><\/h3>\n<p>A Nextcloud Identity Provider migration should ultimately be considered a <strong>business continuity project<\/strong>.<\/p>\n<p>Changing the authentication backend without considering user relationships can disrupt access to data and collaboration workflows.<\/p>\n<p>A properly designed migration should aim to preserve the relationship between:<\/p>\n<p><strong>Users \u2192 Data \u2192 Shares \u2192 Groups \u2192 Permissions \u2192 Applications<\/strong><\/p>\n<p>The authentication system may change, but these relationships should remain stable whenever technically possible.<\/p>\n<p>This approach reduces user disruption and allows organizations to modernize their identity architecture without unnecessarily rebuilding their Nextcloud environment.<\/p>\n<\/div>\n\n\n<h2 id=\"conclusion\" class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n<div id=\"brxe-73e8bb\" class=\"brxe-text\">\n<p>Migrating Nextcloud from LDAP or another authentication backend to Microsoft Entra ID, Keycloak, or an OpenID Connect Identity Provider requires more than simply enabling a new login method.<\/p>\n<p>The central challenge is <strong>preserving the identity of existing users<\/strong>.<\/p>\n<p>Two main strategies can be considered:<\/p>\n<ol>\n<li>creating new accounts and transferring the required data and permissions;<\/li>\n<li>remapping the new authentication identity to the existing Nextcloud user.<\/li>\n<\/ol>\n<p>The appropriate strategy depends on the size and complexity of the environment.<\/p>\n<p>Small deployments may benefit from a controlled account migration, while larger enterprise infrastructures often require a carefully designed identity mapping strategy.<\/p>\n<p>In both cases, the migration should begin with a detailed assessment of user identifiers, group structures, permissions, shares, Team Folders, and integrated applications.<\/p>\n<p>A successful Identity Provider migration does not simply move users to a new login system.<\/p>\n<p>It preserves their digital identity and ensures continuity across <strong>data, permissions, collaboration workflows, and enterprise applications<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<p><u><a href=\"https:\/\/www.linkedin.com\/in\/emilio-veronesi\/\" target=\"_blank\" rel=\"noopener\"><strong><em>Emilio Veronesi<\/em><\/strong><\/a><\/u><\/p>\n<\/div>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"mailto:marketing@itservicenet.net\">Write to ITServicenet<\/a><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>How to migrate Nextcloud from LDAP to OpenID Connect, Microsoft Entra ID, or Keycloak while preserving users, files, shares, groups, and permissions. Strategies, risks, and best practices.<\/p>\n","protected":false},"author":2,"featured_media":6038,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":7,"footnotes":""},"categories":[{"term_id":24,"name":"Article","slug":"article","term_group":0,"term_taxonomy_id":24,"taxonomy":"category","description":"","parent":0,"count":44,"filter":"raw","cat_ID":24,"category_count":44,"category_description":"","cat_name":"Article","category_nicename":"article","category_parent":0},{"term_id":27,"name":"Nextcloud","slug":"nextcloud","term_group":0,"term_taxonomy_id":27,"taxonomy":"category","description":"","parent":0,"count":15,"filter":"raw","cat_ID":27,"category_count":15,"category_description":"","cat_name":"Nextcloud","category_nicename":"nextcloud","category_parent":0}],"tags":[33],"class_list":["post-6043","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-article","category-nextcloud","tag-nextcloud"],"images":{"thumbnail":"https:\/\/itservicenet.net\/wp-content\/uploads\/2026\/09\/Migrazione-Nextcloud-Identity-Provider-150x150.png","medium":"https:\/\/itservicenet.net\/wp-content\/uploads\/2026\/09\/Migrazione-Nextcloud-Identity-Provider-300x169.png","medium_large":"https:\/\/itservicenet.net\/wp-content\/uploads\/2026\/09\/Migrazione-Nextcloud-Identity-Provider-768x432.png","large":"https:\/\/itservicenet.net\/wp-content\/uploads\/2026\/09\/Migrazione-Nextcloud-Identity-Provider-1024x576.png","full":"https:\/\/itservicenet.net\/wp-content\/uploads\/2026\/09\/Migrazione-Nextcloud-Identity-Provider.png"},"_links":{"self":[{"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/posts\/6043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/comments?post=6043"}],"version-history":[{"count":4,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/posts\/6043\/revisions"}],"predecessor-version":[{"id":6049,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/posts\/6043\/revisions\/6049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/media\/6038"}],"wp:attachment":[{"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/media?parent=6043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/categories?post=6043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itservicenet.net\/en\/wp-json\/wp\/v2\/tags?post=6043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}