Rank #5 of 5 in Auth & Identity
Access
Install
docker run -p 127.0.0.1:8080:8080 -e KC_BOOTSTRAP_ADMIN_USERNAME=admin -e KC_BOOTSTRAP_ADMIN_PASSWORD=admin quay.io/keycloak/keycloak:26.7.3 start-devShowcase


Verified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agent auth — stories about agent auth in this arenaAgent authevidence →
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment controlevidence →
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise ssoevidence →
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooksevidence →
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integrationevidence →
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordlessevidence →
Stories about mfa passwordless in this arena
Oauth oidc — stories about oauth oidc in this arenaOauth oidcevidence →
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenantevidence →
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissionsevidence →
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession managementevidence →
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migrationevidence →
Stories about user migration in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Keycloak stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agent auth — stories about agent auth in this arenaAgent auth
Stories about agent auth in this arena
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Webhooks · Official SDKs · MCP server · Versioning policy · API sandbox · Headless / CI · Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction · Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM · Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync · Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
Subscribe to events via webhooks
—–
Build against official SDKs
—0/10
Issue scoped/least-privilege API credentials for an agent
~7/10
unlocks → Headless / CI
Connect an agent via an official MCP server
—0/10
Download a machine-readable API spec (OpenAPI or equivalent)
~4/10
unlocks → Interactive API docs · Official SDKs · MCP server
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
!4/10
Explore an interactive API reference with runnable examples
—0/10
CLI & headless
Use an official CLI
✓7/10
unlocks → Headless / CI
Run the product headlessly / in CI for automation
!4/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
—–
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
n/an/a
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment control — stories about deployment control in this arenaDeployment control
Stories about deployment control in this arena
Enterprise sso — stories about enterprise sso in this arenaEnterprise sso
Stories about enterprise sso in this arena
Events webhooks — stories about events webhooks in this arenaEvents webhooks
Stories about events webhooks in this arena
Framework integration — stories about framework integration in this arenaFramework integration
Stories about framework integration in this arena
Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless
Stories about mfa passwordless in this arena
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
✓8/10
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
~4/10
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
~6/10
Oauth oidc — stories about oauth oidc in this arenaOauth oidc
Stories about oauth oidc in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant
Stories about orgs multitenant in this arena
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Rbac permissions — stories about rbac permissions in this arenaRbac permissions
Stories about rbac permissions in this arena
Session management — stories about session management in this arenaSession management
Stories about session management in this arena
User migration — stories about user migration in this arenaUser migration
Stories about user migration in this arena
Sorted by importance (agentic first) (high → low) · 56/56 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Xcommunity | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 7/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 4/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | disputed | 4/10 | Dcontradicted | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | disputed | 4/10 | Dcontradicted | |
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details C Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 3 | full | 9/10 | Xcommunity | |
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | full | 9/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 9/10 | Xcommunity | |
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks G Rbac | developer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 3 | full | 8/10 | Cclaimed | |
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 3 | full | 7/10 | Xcommunity | |
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session C Sessions | developer | Session management — stories about session management in this arenaSession management | 3 | full | 7/10 | Cclaimed | |
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials C Machine identity | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 6/10 | Cclaimed | |
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box C Orgs | developer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 3 | partial | 6/10 | Cclaimed | |
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens C Mcp | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 6/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 5/10 | Cclaimed | |
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 3 | partial | 4/10 | Cclaimed | |
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed G Mfa | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 3 | partial | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 3/10 | Cclaimed | |
Protect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets C Device flow | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | full | 9/10 | Cclaimed | |
Control where the auth system and its user data run — self-managed deployment, private instance, or my own database C Deployment | security-engineer | Deployment control — stories about deployment control in this arenaDeployment control | 2 | full | 9/10 | Xcommunity | |
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code G Flows | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | full | 8/10 | Xcommunity | |
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app") C Provider | developer | Oauth oidc — stories about oauth oidc in this arenaOauth oidc | 2 | full | 8/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 7/10 | Tprobed | |
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages C Frameworks | developer | Framework integration — stories about framework integration in this arenaFramework integration | 2 | full | 7/10 | Cclaimed | |
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods G Passwordless | developer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 2 | partial | 6/10 | Cclaimed | |
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access G Sso | security-engineer | Enterprise sso — stories about enterprise sso in this arenaEnterprise sso | 2 | partial | 6/10 | Cclaimed | |
Bulk-import existing users — including password hashes — and export them again, so I am never locked in C Migration | developer | User migration — stories about user migration in this arenaUser migration | 2 | partial | 5/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Xcommunity | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 4/10 | Cclaimed | |
Give each customer organization its own SSO connection with verified domains and just-in-time provisioning G Orgs | security-engineer | Orgs multitenant — stories about orgs multitenant in this arenaOrgs multitenant | 2 | partial | 4/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 3/10 | Cclaimed | |
Require asynchronous human approval (e.g. CIBA-style confirmation) before an autonomous agent completes a sensitive transaction C Delegation | ai-native user | Agent auth — stories about agent auth in this arenaAgent auth | 2 | none | 0/10 | ||
Capture tamper-evident audit logs of authentication and admin activity and stream or export them to my SIEM G Audit | security-engineer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | n/a | untested | none yet | |
Subscribe to webhooks or event streams for auth events (sign-ups, sign-ins, user changes) to keep my systems in sync C Webhooks | developer | Events webhooks — stories about events webhooks in this arenaEvents webhooks | 2 | none | untested | none yet | |
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles C Rbac | security-engineer | Rbac permissions — stories about rbac permissions in this arenaRbac permissions | 1 | full | 9/10 | Cclaimed | |
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows C Hardening | security-engineer | Mfa passwordless — stories about mfa passwordless in this arenaMfa passwordless | 1 | full | 8/10 | Xcommunity | |
Let users and admins see active sessions and devices and revoke them individually or all at once C Sessions | security-engineer | Session management — stories about session management in this arenaSession management | 1 | full | 7/10 | Cclaimed | |
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets C Migration | founder | User migration — stories about user migration in this arenaUser migration | 1 | partial | 4/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 31 stories with headroom
What would move Keycloak’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDelegate tasks to a built-in AI assistant inside the product
nonemoves Built-in AIimpact 45
The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server
nonemoves agent-readyimpact 45
Keycloak is an identity/access management server; no evidence of an official MCP server for connecting AI agents, and probes for llms.txt/openapi endpoints returned 404.
Framework integration — stories about framework integration in this arenaProtect routes with first-party framework SDKs and middleware (Next.js and peers) that verify sessions at the edge
nonemoves PA Scoreimpact 30
Evidence shows only generic OIDC/SAML protocol support and endpoints (well-known config, introspection, revocation) but no mention of a first-party Next.js SDK, edge middleware, or session verification at the edge; Keycloak's client adapters for specific frameworks are not referenced anywhere in the pack.
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
Direct probes show no llms.txt (404), no markdown docs endpoint, and no OpenAPI/agent-oriented docs endpoint; only standard human-facing documentation exists.
Agenticness — how well agents can access and operate the productBuild against official SDKs
nonemoves agent-readyimpact 30
Missing: any mention of official SDKs (Java, Node, Python, etc.), agent/AI-specific integration libraries, or programmatic SDK documentation.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Missing: any documentation of webhook config, event listener SPI exposed as webhooks, or third-party corroboration of webhook support.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Evidence shows only a link to 'Documentation for the Administration RESTful API' (keycloak-docs-6) with no mention of an interactive, runnable API explorer; probes for OpenAPI/Swagger specs and machine-readable docs all returned 404s, indicating no interactive API reference is exposed.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: any documentation of API version numbers, backward-compatibility guarantees, or a formal deprecation/sunset policy.
Showing the top 8 of 31 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map8 surfaces · 36 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs24 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app access
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Control data retention and deletion
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
keycloak.org19 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Issue scoped/least-privilege API credentials for an agent
- Define rules that trigger actions automatically on events
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Export all of my data in open formats and leave
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Control data retention and deletion
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Let users and admins see active sessions and devices and revoke them individually or all at once
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
- Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets
Getting started docs14 stories
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Run the product headlessly / in CI for automation
- Test against a sandbox environment without touching production data
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where needed
- Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methods
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
- Self-host the core product
- Give each customer organization its own SSO connection with verified domains and just-in-time provisioning
- Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the box
- Choose where my data is stored (region/residency)
- Let users and admins see active sessions and devices and revoke them individually or all at once
Securing apps docs12 stories
- Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authority
- Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secrets
- Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loop
- Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentials
- Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokens
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Download a machine-readable API spec (OpenAPI or equivalent)
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")
- Define roles and permissions and have them enforced and surfaced in session tokens for authorization checks
- Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised session
Hacker News11 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Test against a sandbox environment without touching production data
- Perform bulk operations across many items at once
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-in
- Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flows
- Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol details
- Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom code
- Do everything through the API that I can do in the UI
- Self-host the core product
Guides docs9 stories
- Run the product headlessly / in CI for automation
- Test against a sandbox environment without touching production data
- Perform bulk operations across many items at once
- Control where the auth system and its user data run — self-managed deployment, private instance, or my own database
- Export all of my data in open formats and leave
- Self-host the core product
- Choose where my data is stored (region/residency)
- Bulk-import existing users — including password hashes — and export them again, so I am never locked in
- Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resets
Documentation docs8 stories
- Use an official CLI
- Drive the product through a documented public API
- Download a machine-readable API spec (OpenAPI or equivalent)
- Perform bulk operations across many items at once
- Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pages
- Do everything through the API that I can do in the UI
- Control data retention and deletion
- Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple roles
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
7 of 20 testable claims verified · 0 contradicted → integrity 35/100
39 distinct capability claims found in Keycloak’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
7
Verified
13
Unverified
0
Contradicted
14
Undersold
Verified (13)
“Supports standard protocols OpenID Connect, OAuth 2.0, and SAML”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailsfullproof ↗
“Can be started instantly via a single Docker command with an initial admin user”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
“Can be started instantly via a single Docker command with an initial admin user”
“Exposes OpenID Connect discovery document at a well-known endpoint per realm”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailsfullproof ↗
“Publishes a documented Admin REST API”
Drive the product through a documented public APIfullproof ↗
“Built-in federation with existing LDAP or Active Directory servers, and custom user store providers”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
“Can authenticate users via existing external OpenID Connect or SAML 2.0 identity providers (brokering)”
Connect enterprise identity providers over SAML and OIDC (Okta, Entra, Google Workspace) for workforce sign-infullproof ↗
“Social login can be enabled purely via admin console configuration, no app code changes”
Offer sign-in with a broad set of social and OAuth identity providers through configuration, not custom codefullproof ↗
“Can be configured to run behind a reverse proxy, API gateway, or load balancer”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
“Provides a token introspection endpoint to validate access or refresh tokens”
Implement standard OAuth 2.0 / OIDC flows (authorization code with PKCE, refresh tokens) without hand-rolling protocol detailsfullproof ↗
“Kubernetes Operator can manage OIDC and SAML clients declaratively”
Control where the auth system and its user data run — self-managed deployment, private instance, or my own databasefullproof ↗
“Can be run as a self-hosted container image or installed via the Operator”
“Built-in brute-force protection that temporarily or permanently locks accounts after repeated failed logins”
Rely on built-in protection against bots, credential stuffing, and brute-force attacks on the auth flowsfullproof ↗
Unverified (18)
“Supports custom themes to change login/UI look and feel”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Realms (including users/config) can be imported and exported as JSON files”
Bulk-import existing users — including password hashes — and export them again, so I am never locked inpartialproof ↗
“Fine-grained, resource-level authorization services with custom policies beyond basic roles”
Express fine-grained, resource-level authorization (relationship- or policy-based) beyond simple rolesfullproof ↗
“Account console lets users self-manage profile, password, and two-factor authentication”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Account console lets users self-manage profile, password, and two-factor authentication”
Require multi-factor authentication with TOTP authenticator apps and backup codes, with step-up enforcement where neededpartialproof ↗
“Single sign-out logs a user out of all applications at once”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessionfullproof ↗
“Realms act as isolated multi-tenant boundaries for users and applications”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxpartialproof ↗
“Admins can centrally manage users, their permissions, and active sessions”
Let users and admins see active sessions and devices and revoke them individually or all at oncefullproof ↗
“Supports allowing users to self-register accounts”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Supports a built-in forgot-password flow”
Ship production sign-in, sign-up, and profile management with prebuilt, customizable UI components or hosted pagesfullproof ↗
“Provides a dynamic client registration endpoint for programmatically registering OAuth clients”
Turn my own application into an OAuth provider that issues tokens to third-party clients ("Sign in with my app")fullproof ↗
“Provides a token revocation endpoint for both access and refresh tokens”
Manage session lifecycle — expiry, refresh, and immediate server-side revocation of a compromised sessionfullproof ↗
“Admins can create and manage organizations within a realm, each with settings like a unique name”
Model multi-tenant B2B apps with organizations, memberships, and invitation flows out of the boxpartialproof ↗
“Supports WebAuthn and Passkeys (including passwordless/conditional UI login) as sign-in methods”
Offer passkeys/WebAuthn and passwordless options like magic links or email OTP as first-class sign-in methodspartialproof ↗
“Provides built-in SCIM endpoints per realm to sync users and groups with external directories”
Sync users and groups from customer directories via SCIM so deprovisioning in the IdP revokes app accesspartialproof ↗
“Supports the OAuth device authorization grant for input-constrained or browserless clients”
Authenticate CLIs and headless agents via the OAuth device authorization flow instead of pasting long-lived secretsfullproof ↗
“Supports OAuth client credentials flow for service accounts to authenticate machine-to-machine”
Issue machine-to-machine credentials (client-credentials flow) so backend services and agents authenticate without a human in the loopfullproof ↗
“Ships an Admin CLI (kcadm.sh) for scripted administration of realms, users, roles, and clients”
Undersold (14)
Have an agent obtain short-lived, user-consented tokens for third-party APIs (token vault/exchange) so tool calls run under the user's delegated authoritypartialproof ↗
Give each agent its own least-privilege machine identity with narrowly scoped permissions and instant revocation, instead of sharing a human's credentialspartialproof ↗
Put a spec-compliant OAuth authorization flow in front of my MCP server so remote agents connect with scoped, verifiable tokenspartialproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Download a machine-readable API spec (OpenAPI or equivalent)partialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Give each customer organization its own SSO connection with verified domains and just-in-time provisioningpartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Define roles and permissions and have them enforced and surfaced in session tokens for authorization checksfullproof ↗
Follow vendor-maintained migration guides or tooling for moving off a competing auth provider without forcing password resetspartialproof ↗
Claims outside our story set (10)
Real capability claims found in Keycloak’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Extensible through custom code (providers/SPI)”
source ↗“Central admin console for managing all aspects of the server”
source ↗“Single sign-on: log in once to access multiple registered applications”
source ↗“Exposes health REST endpoints to check startup/readiness status”
source ↗“Users can link their account to multiple identity providers for alternate sign-in”
source ↗“Supports key rotation for signing/encryption keys”
source ↗“Integrates with SSSD and FreeIPA identity management”
source ↗“Can be configured for FIPS compliance”
source ↗“Exposes metrics for monitoring a running Keycloak instance”
source ↗“Supports managing custom user attributes”
source ↗
Business model
Open-source (Apache-2.0) identity server under the CNCF; free to self-host with no usage pricing, with commercial support available via Red Hat build of Keycloak subscriptions.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
