Keycloak
Unclaimed verified 6 oct 2026Open source identity and access management solution for single sign-on and authentication.
TL;DR
Keycloak is an open-source identity and access management (IAM) platform delivering single sign-on (SSO), user federation, and fine-grained authorization for modern cloud architectures. Built for DevOps engineers, software developers, and security architects, it allows teams to implement enterprise-grade identity controls without vendor lock-in. Its primary differentiator is offering complete feature parity with proprietary identity platforms at zero licensing cost regardless of user volume.
What Users Actually Pay
No user-reported pricing yet.
Our Take
Keycloak stands as the standard open-source identity and access management system in enterprise software, backed by Red Hat and CNCF community ecosystems. It offers an alternative to proprietary identity-as-a-service providers like Auth0, Okta, and Entra ID by supporting industry standards including OpenID Connect, OAuth 2.0, SAML 2.0, and WebAuthn out of the box. The system's core strength is total architectural sovereignty. Organizations retain complete control over identity data storage, encryption configurations, user migration pipelines, and custom authentication workflows through Service Provider Interfaces (SPIs). With no monthly active user (MAU) billing tier, Keycloak offers predictable infrastructure costs for high-scale applications. However, this flexibility introduces notable operational complexity. Managing Keycloak in production demands dedicated engineering resources for high-availability clustering, distributed cache management (Infinispan), database tuning, and zero-downtime upgrades. The administrative UI and configuration workflows are feature-dense but have a steep learning curve compared to modern SaaS CIAM solutions. Keycloak is best suited for organizations with strict data sovereignty mandates, air-gapped deployments, public sector entities, or engineering teams with mature Kubernetes and DevOps capabilities. Teams seeking hands-off maintenance without in-house infrastructure operations may find managed SaaS alternatives more cost-effective when factoring in engineering hours.
Alternatives
Ranked by Revuo score — paid tiers never affect order.Supabase Auth
Built-in user management
Auth0
Secure AI agents, humans, and whatever comes next
Descope
Reduce user friction, prevent account takeover, and get a 360° view of your customer and agentic identities with the Descope External IAM platform.
Okta
Secure Identity for Employees, Customers, and AI
WorkOS
Your app, Enterprise Ready.
Clerk
More than authentication, Complete User Management
Pros
- + Zero software licensing fees with no per-user or per-authentication MAU pricing models
- + Broad protocol and standard support covering OpenID Connect, OAuth 2.0, SAML 2.0, Passkeys/WebAuthn, and SCIM
- + Extensive customizability and extensibility through Service Provider Interfaces (SPIs) and custom themes
- + Full data sovereignty and deployment flexibility across bare metal, Docker, and Kubernetes environments
Cons
- - High operational maintenance burden requiring dedicated DevOps overhead for clustering, caching, and upgrades
- - Steep learning curve and complex administration console navigation for new administrators
- - Upgrades across major versions can introduce breaking changes to custom SPIs, database schemas, and theme templates
Agent Readiness
74/100Keycloak is well prepared for autonomous agent and programmatic integration via its comprehensive Admin and Account REST APIs, full OpenAPI specifications, and OAuth 2.0/OIDC standard bearer token authorization. While it relies on self-hosted infrastructure (requiring internal health monitoring endpoints rather than a central status page) and event listener extensions for webhook dispatches, its deterministic REST interface and official container images make it automated-agent ready.
Last checked Oct 6, 2026
MCP Integrations
5 servers128 toolsOperate managed Keycloak from your AI client. Provision and scale clusters, create realms and applications, wire up SSO and identity providers (Google, GitHub, SAML, LDAP), manage users, roles and groups, set custom domains and branding, configure WAF and geo-blocking, and stream audit events to your SIEM. Signs you in through the browser with OAuth, so there is no API key to paste, and what you can change is bounded by your workspace role.
128 tools
skycloak_add_cluster_captcha_domainRegister a hostname for CAPTCHA protection on a cluster.skycloak_add_realm_user_to_groupAdd a user to a realm group.skycloak_assign_application_roleGrant a role to an application's service account. Provide role_client_id for a client role, or omit it for a realm role.skycloak_assign_realm_user_roleAssign a realm role to a user.skycloak_cancel_cluster_upgradeCancel an in-progress cluster version upgrade. Set confirm=true to proceed.skycloak_create_applicationCreate an OIDC/SAML client (application) in a realm. Returns the client secret for confidential clients (store it; it is not retrievable later).skycloak_create_clusterProvision a new Keycloak cluster. Asynchronous: the returned cluster starts in a provisioning state — poll skycloak_get_cluster until its status is 'available'. Requires --allow-writes.skycloak_create_domainAdd a custom domain to a cluster. Returns the DNS records the customer must create to verify and route the domain.skycloak_create_domain_routeAdd a realm route to a custom domain.skycloak_create_exportStart a database export for a cluster. Asynchronous: poll skycloak_get_export until the status is 'completed' to obtain the download URL. Including credentials requires an encryption_password.skycloak_create_identity_providerCreate an OIDC identity provider (SSO connection) in a realm.skycloak_create_realmCreate a new Keycloak realm in a cluster. Requires the server to be started with --allow-writes and a write-scoped API key.skycloak_create_realm_exportExport a Keycloak realm to an encrypted archive. Asynchronous: poll skycloak_get_realm_export until status is 'completed'. The archive is always encrypted, so encryption_password is required, and the same password is needed to import it again. This is a realm export (one realm's configuration); skycloak_create_export is the separate whole-cluster database export.skycloak_create_realm_groupCreate a realm group, optionally nested under a parent group.skycloak_create_realm_importImport a Keycloak realm into a cluster from an uploaded archive or an existing realm export. Asynchronous: poll skycloak_get_realm_import. Creates a new realm: preflight refuses a name collision rather than overwriting, so an existing realm of the same name fails with 409. It does import users and their credentials, so set confirm=true to proceed.skycloak_create_realm_import_upload_urlGet a presigned URL to upload a realm archive to. PUT the archive to upload_url, then pass the returned s3_key to skycloak_create_realm_import as upload_s3_key. Not needed when importing an existing export: pass that export's ID as source_export_id instead.skycloak_create_realm_roleCreate a realm-scoped role.skycloak_create_realm_userCreate a realm user with an initial temporary password.skycloak_create_siem_destinationCreate a SIEM destination. Credentials are write-only and are not returned.skycloak_create_webhook_subscriptionCreate a webhook subscription. Signing secrets and authorization headers are write-only.skycloak_delete_applicationDelete an application (OIDC/SAML client) from a realm. Set confirm=true to proceed.skycloak_delete_clusterPermanently delete a Keycloak cluster and all of its realms and data. Irreversible. Set confirm=true to proceed.skycloak_delete_cluster_maintenance_windowDelete a cluster-specific maintenance window so the cluster follows the workspace default. Set confirm=true to proceed.skycloak_delete_domainRemove a custom domain from a cluster. Set confirm=true to proceed.skycloak_delete_domain_routeRemove a realm route from a custom domain. Set confirm=true to proceed.skycloak_delete_email_brandingRevert email branding to defaults. Set confirm=true to proceed.skycloak_delete_exportDelete a database export archive. Set confirm=true to proceed.skycloak_delete_extensionDelete a custom extension from the workspace catalog. Set confirm=true to proceed.skycloak_delete_identity_providerDelete an identity provider from a realm. Set confirm=true to proceed.skycloak_delete_login_brandingRevert login branding to defaults. Set confirm=true to proceed.skycloak_delete_realmPermanently delete a realm and all of its users, clients and configuration. This is irreversible. Set confirm=true to proceed.skycloak_delete_realm_groupDelete a realm group. Set confirm=true to proceed.skycloak_delete_realm_roleDelete a realm role. Set confirm=true to proceed.skycloak_delete_realm_userDelete a realm user. Set confirm=true to proceed.skycloak_delete_siem_destinationDelete a SIEM destination. Set confirm=true to proceed.skycloak_delete_smtpRemove a realm's SMTP configuration. Set confirm=true to proceed.skycloak_delete_themeDelete a custom theme. Set confirm=true to proceed.skycloak_delete_webhook_subscriptionDelete a webhook subscription. Set confirm=true to proceed.skycloak_discover_oidcResolve an OIDC issuer's discovery document to obtain its authorization, token, and userinfo endpoints. Use the result when creating an identity provider.skycloak_download_theme_contentDownload a custom theme's content archive. Returns size and SHA-256 always, and the archive itself only when it is small enough to inline.skycloak_export_cluster_eventsExport a cluster's events as a document and return its contents.skycloak_get_applicationGet an application (OIDC/SAML client) by client ID.skycloak_get_client_theme_assignmentGet a client's login-theme override (empty means the realm default).skycloak_get_clusterGet full details for a single Keycloak cluster by its ID.skycloak_get_cluster_insightsGet cluster analytics as a JSON document. type is one of: overview, authentication, events, performance, security.skycloak_get_cluster_maintenance_windowGet a cluster-specific maintenance window. A 404 means the cluster follows the workspace default.skycloak_get_cluster_securityGet a cluster's edge-security configuration: IP allow-listing, rate limiting, WAF, geo-blocking, and bot management.skycloak_get_cluster_upgrade_pathGet the recommended version-upgrade path for a cluster.skycloak_get_domainGet a custom domain by ID, including its DNS records and verification/SSL status.skycloak_get_domain_routeGet a single realm route on a custom domain.skycloak_get_email_brandingGet the email-template branding (colors, logo, footer) for a realm.skycloak_get_exportGet a database export job by ID, including its status, progress, and (once completed) the time-limited download URL.skycloak_get_identity_providerGet an identity provider by provider ID.skycloak_get_login_brandingGet the login-page branding (colors, logo, toggles) for a realm.skycloak_get_logsRead recent Keycloak server logs for a cluster, optionally filtered by level and a search string.skycloak_get_realmGet a realm by name.skycloak_get_realm_exportGet a realm export job by ID. Poll this after skycloak_create_realm_export until status is 'completed'; the download URL only appears then and expires 24 hours later.skycloak_get_realm_groupGet a realm group by ID.skycloak_get_realm_importGet a realm import job by ID. Poll this after skycloak_create_realm_import until status is 'completed' or 'failed'.skycloak_get_realm_roleGet a realm role by name.skycloak_get_realm_userGet a realm user by ID.skycloak_get_security_logsRead recent security (WAF) logs for a cluster — blocked requests, attack types, source IPs.skycloak_get_siem_destinationGet a SIEM destination by ID.skycloak_get_smtpGet a realm's SMTP configuration (secret values are never returned).skycloak_get_themeGet a custom theme by ID.skycloak_get_theme_assignmentGet the active custom theme per Keycloak theme type (login, account, admin, email) for a realm.skycloak_get_webhook_subscriptionGet a webhook subscription by ID.skycloak_install_extensionInstall a catalog extension on a cluster. Installation is asynchronous; poll skycloak_list_cluster_extensions until the status settles. Provide required parameters keyed by parameter name.skycloak_list_application_rolesList the roles assigned to an application's service account.skycloak_list_application_sessionsList active user sessions for an application.skycloak_list_applicationsList the OIDC/SAML clients (applications) in a realm.skycloak_list_cluster_captcha_domainsList hostnames registered for CAPTCHA protection on a cluster.skycloak_list_cluster_extensionsList the extensions currently installed on a cluster, with their version and upgrade status.skycloak_list_cluster_featuresList the Keycloak feature flags available to tenant clusters.skycloak_list_cluster_locationsList the deployment regions available to the workspace.skycloak_list_cluster_typesList the cluster types the workspace can provision.skycloak_list_cluster_upgradesList the version-upgrade history for a cluster.skycloak_list_cluster_versionsList the Keycloak versions available for a cluster type.skycloak_list_clustersList the Keycloak clusters in your Skycloak workspace, with their status, type, size, version and location.skycloak_list_domain_routesList the realm routes configured on a custom domain.skycloak_list_domainsList the custom domains configured on a cluster.skycloak_list_exportsList the database export jobs for a cluster, with their status and expiry.skycloak_list_extensionsList the extension catalog available to the workspace (marketplace extensions that can be installed on a cluster).skycloak_list_identity_provider_templatesList the pre-configured identity-provider templates. Use a template id when creating a provider.skycloak_list_identity_providersList the identity providers (SSO connections) in a realm.skycloak_list_realm_group_membersList the users that belong to a realm group.skycloak_list_realm_groupsList the top-level groups in a realm.skycloak_list_realm_rolesList the realm-scoped roles in a realm.skycloak_list_realm_usersList the users in a realm.skycloak_list_realmsList the Keycloak realms in a Skycloak cluster.skycloak_list_siem_destinationsList SIEM destinations configured for the workspace.skycloak_list_themesList the custom themes uploaded to a cluster, with their IDs, status, and theme types.skycloak_list_user_groupsList the groups a user belongs to.skycloak_list_user_rolesList the realm roles assigned to a user.skycloak_list_webhook_event_typesList webhook event types. Optionally filter by source: platform or keycloak.skycloak_list_webhook_subscriptionsList webhook subscriptions. Optionally filter by source, cluster_id, and enabled.skycloak_query_eventsQuery Keycloak user and admin events for a cluster (logins, token grants, admin operations), filterable by category, realm, username and search.skycloak_remove_application_roleRemove a role from an application's service account.skycloak_remove_cluster_captcha_domainRemove a hostname from CAPTCHA protection on a cluster. Set confirm=true to proceed.skycloak_remove_realm_user_from_groupRemove a user from a realm group.skycloak_remove_realm_user_roleRemove a realm role from a user.skycloak_rotate_application_secretRegenerate an application's client secret and return the new value (shown only once).skycloak_set_client_theme_assignmentSet a client's login-theme override. Pass a theme ID, or an empty string to reset to the realm default.skycloak_set_cluster_maintenance_windowCreate or replace a cluster-specific maintenance window.skycloak_set_theme_assignmentAssign custom themes to a realm per Keycloak theme type. Pass a theme ID to activate it, or an empty string to reset that type to Keycloak's built-in default. Only the provided fields are changed.skycloak_test_identity_providerTest connectivity to an identity provider, optionally overriding the client credentials for this test only.skycloak_test_siem_destinationSend a test event to a SIEM destination.skycloak_test_smtpSend a test email through a realm's configured SMTP server to verify delivery.skycloak_test_webhook_subscriptionSend a test event to a webhook subscription.skycloak_uninstall_extensionUninstall an extension from a cluster. Set confirm=true to proceed.skycloak_update_applicationUpdate an application's name, description, or redirect URIs.skycloak_update_clusterUpdate a cluster's version (to trigger an upgrade) or size.skycloak_update_cluster_securityUpdate a cluster's edge-security configuration. Only the sections you provide are changed; CAPTCHA settings are preserved. Supports IP allow-listing, rate limiting, WAF, geo-blocking, and bot management.skycloak_update_domain_routeUpdate a domain route's admin access and CORS origins.skycloak_update_extensionUpdate a custom extension's name or description.skycloak_update_identity_providerUpdate an identity provider's display name and enabled state.skycloak_update_realmUpdate a realm's display name and enabled state.skycloak_update_realm_groupRename a realm group.skycloak_update_realm_roleRename a realm role or change its description.skycloak_update_realm_userUpdate a realm user's profile (email, name, enabled, email_verified).skycloak_update_siem_destinationUpdate a SIEM destination. Only provided fields are changed; credentials remain write-only.skycloak_update_themeUpdate a theme's name, description, or version.skycloak_update_webhook_subscriptionUpdate a webhook subscription. Use clear_authorization_header, clear_cluster_id, or clear_realm_id to remove nullable fields.skycloak_upgrade_extensionUpgrade an installed extension to the latest available version. Asynchronous.skycloak_upsert_email_brandingCreate or update email-template branding (color, logo, footer).skycloak_upsert_login_brandingCreate or update login-page branding (colors, logo, registration toggle).skycloak_upsert_smtpCreate or update a realm's SMTP configuration (basic auth).skycloak_verify_domainTrigger DNS verification for a custom domain and return its updated status.
Keycloak admin for AI agents — realms, users, clients, roles; safe-by-default governance.
This is just a test publish, delete me
Needs a self-provisionable API key
Administer Keycloak via its Admin REST API: users, roles, clients, groups, IdP, events.
MCP server for KeyCloak Admin REST API via Service Account
Last checked Sep 12, 2026
[ features ]
Geostrategic Position
Information on which part of the world this product / vendor belongs to, i.e. the country of their headquarters primarily, but also their hosting options etc.
Find which geostrategic world region the headquarter is located in. Relevant for compliance questions (e.g., CLOUD Act) or risk of cut-off in case of conflicts. For example, some EU companies are worried about the US and would definitely not host their customer with Chinese or Russian companies.
The hosting provider that is used to host this product, if any.
The available hosting locations, if you can choose
Compliance & Security
Security certifications, compliance features, and access control capabilities.
SOC 2 Type I or Type II certification.
ISO 27001 information security certification.
Built-in tools for GDPR compliance (data export, deletion, consent).
Complete audit log of all data changes.
Granular permissions based on user roles.
Single Sign-On integration support.
Developer Experience
Tools and abstractions easing agent development and iteration.
No-code/low-code UI for designing agent workflows.
OpenAI API-compatible endpoints or SDKs.
Available as open-source with community contributions.
Programming languages with official SDK support.
Ready-to-use, customizable UI elements for auth flows.
Self-service admin dashboard for customers to manage users/orgs.
Supported frontend frameworks with dedicated guides/components.
Authentication Methods
Core authentication flows and options supported by the platform.
Supports passwordless authentication via magic links, passkeys, or biometrics.
Supported third-party social login providers.
Supported multi-factor authentication methods.
Built-in protection against bots and automated attacks during auth.
Enterprise Integrations
Protocols and tools for integrating with enterprise identity systems.
Supports SCIM for automated user provisioning and deprovisioning.
Supports syncing users/groups from directories like HRIS or IdPs.
Compatible identity providers for federation.
Just-In-Time user provisioning from SAML/OIDC assertions.
Pricing & Free Tier
Free tier limits and overall pricing structure.
Maximum Monthly Active Users allowed on the free tier.
Key usage metrics that incur costs.
Compare With
Reviews
No reviews yet. Be the first to review Keycloak!