SSO - keycloak-grafana ( login.OAuthLogin(missing saved state )

Good morning,

so ,

i disabled tls check:

    tls_skip_verify_insecure = true

it does not work… in logs x509 error disappeared but got info :

Error getting email address" logger=oauth.generic_oauth url=https://iam.DOMAIN.net/realms/master/protocol/openid-connect/userinfo/emails error="{\"error\":\"RESTEASY003210: Could not find resource for full path: https://iam.DOMAIN.net/realms/master/protocol/openid-connect/userinfo/emails\"}"

as i already faced, but i search and find:
so i add email address for user in keycloak and I’m able to login inside. O_o

When i enable tls check , I’m getting x509 error again.

so , i was looking and find :

but no idea how to add my cert for the “backend” , don’t ask for solution, just point somewhere …

Thanks