diff --git a/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java b/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java
index b17f8d21cbc..90c270164c6 100644
--- a/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java
+++ b/server-spi/src/main/java/org/keycloak/services/clientpolicy/ClientPolicyEvent.java
@@ -30,6 +30,7 @@ public enum ClientPolicyEvent {
UPDATED,
VIEW,
UNREGISTER,
+ PRE_AUTHORIZATION_REQUEST,
AUTHORIZATION_REQUEST,
IMPLICIT_HYBRID_TOKEN_RESPONSE,
TOKEN_REQUEST,
diff --git a/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java b/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java
index 0e5890f5895..7e632d0850f 100755
--- a/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java
+++ b/services/src/main/java/org/keycloak/protocol/oidc/endpoints/AuthorizationEndpoint.java
@@ -45,6 +45,7 @@ import org.keycloak.services.ErrorPageException;
import org.keycloak.services.Urls;
import org.keycloak.services.clientpolicy.ClientPolicyException;
import org.keycloak.services.clientpolicy.context.AuthorizationRequestContext;
+import org.keycloak.services.clientpolicy.context.PreAuthorizationRequestContext;
import org.keycloak.services.messages.Messages;
import org.keycloak.services.resources.LoginActionsService;
import org.keycloak.services.util.CacheControlUtil;
@@ -144,6 +145,12 @@ public class AuthorizationEndpoint extends AuthorizationEndpointBase {
checkSsl();
checkRealm();
+
+ try {
+ session.clientPolicy().triggerOnEvent(new PreAuthorizationRequestContext(clientId, params));
+ } catch (ClientPolicyException cpe) {
+ throw new ErrorPageException(session, authenticationSession, cpe.getErrorStatus(), cpe.getErrorDetail());
+ }
checkClient(clientId);
request = AuthorizationEndpointRequestParserProcessor.parseRequest(event, session, client, params, AuthorizationEndpointRequestParserProcessor.EndpointType.OIDC_AUTH_ENDPOINT);
diff --git a/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java b/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java
new file mode 100644
index 00000000000..41b5ab33c06
--- /dev/null
+++ b/services/src/main/java/org/keycloak/services/clientpolicy/context/PreAuthorizationRequestContext.java
@@ -0,0 +1,51 @@
+/*
+ * Copyright 2023 Red Hat, Inc. and/or its affiliates
+ * and other contributors as indicated by the @author tags.
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+package org.keycloak.services.clientpolicy.context;
+
+import javax.ws.rs.core.MultivaluedMap;
+
+import org.keycloak.services.clientpolicy.ClientPolicyContext;
+import org.keycloak.services.clientpolicy.ClientPolicyEvent;
+
+/**
+ * @author Dmitry Telegin
+ */
+public class PreAuthorizationRequestContext implements ClientPolicyContext {
+
+ private final String clientId;
+ private final MultivaluedMap requestParameters;
+
+ public PreAuthorizationRequestContext(String clientId, MultivaluedMap requestParameters) {
+ this.clientId = clientId;
+ this.requestParameters = requestParameters;
+ }
+
+ @Override
+ public ClientPolicyEvent getEvent() {
+ return ClientPolicyEvent.PRE_AUTHORIZATION_REQUEST;
+ }
+
+ public String getClientId() {
+ return clientId;
+ }
+
+ public MultivaluedMap getRequestParameters() {
+ return requestParameters;
+ }
+
+}
diff --git a/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java b/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java
index f80337b2613..e7b2c6602f0 100644
--- a/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java
+++ b/services/src/main/java/org/keycloak/services/clientpolicy/executor/RejectRequestExecutor.java
@@ -38,6 +38,6 @@ public class RejectRequestExecutor implements ClientPolicyExecutorProvider