
Open-source identity and access management for self-hosted authentication, federation, authorization, and extensible identity workflows.
Keycloak is an open-source Identity and Access Management project for adding authentication and authorization to applications and services. It supports SSO, MFA, user federation, identity brokering, social identity, and fine-grained authorization through standards including OpenID Connect, OAuth 2.0, and SAML 2.0. Organizations operate the community distribution on infrastructure they control, while Red Hat offers a separately supported commercial distribution called Red Hat build of Keycloak.
Keycloak is an identity server that applications and services can use for authentication, federation, and authorization. Applications integrate through standards such as OpenID Connect, OAuth 2.0, and SAML rather than implementing every identity function independently. The administration model covers realms, clients, users, groups, roles, authentication flows, identity providers, federation, and authorization services.
Realms are isolated identity domains with their own users, clients, roles, and configuration. A Keycloak deployment can host multiple realms, although realm boundaries, tenancy design, operational isolation, and scaling should be planned according to the application architecture rather than assuming one realm per environment or customer.
Realm-based identity domains operated by the deploying organization. Keycloak manages users, groups, roles, clients, service accounts, identity providers, and federated directories. Realms provide administrative and identity boundaries within a Keycloak deployment.
Standards-based SSO with configurable authentication and identity brokering. Keycloak supports OpenID Connect, OAuth 2.0, SAML, MFA, WebAuthn/passkeys, social and external identity providers, LDAP/Active Directory federation, and configurable authentication flows.
Roles, groups, service accounts, and fine-grained authorization services. Keycloak supports realm and client roles plus resource- and scope-based policies. User lifecycle can be administered directly or connected to external directories and identity sources; broader provisioning workflows may require integrations or extensions.
Self-managed community distribution with container, Kubernetes, and server deployment paths. Operators control infrastructure, database, networking, upgrades, extensions, and availability. Commercially supported distributions such as Red Hat build of Keycloak provide a different support and lifecycle model.
Each realm is an isolated identity domain with its own users, clients, roles, identity providers, and authentication configuration. A Keycloak deployment can host multiple realms. SSO operates across participating clients within a realm, while logout behavior depends on client protocol support and configuration.
Server Admin Guide →User federation can connect Keycloak to LDAP and Active Directory so existing directory identities can participate in Keycloak authentication flows. Kerberos integration is also available for supported environments, while synchronization, credential validation, and attribute behavior depend on federation configuration.
User Federation docs →Authorization Services provide resource-, scope-, permission-, and policy-based authorization beyond basic role checks, including UMA-related capabilities. Applications can query authorization decisions or use supported policy-enforcement integrations; implementation depends on the application stack and authorization model.
Authorization Services →Service Provider Interfaces and extension points support custom authentication components, protocol mappers, user-storage providers, event listeners, themes, and other integrations. Extensions become part of the operator’s compatibility and upgrade surface and should be tested against the deployed Keycloak version.
Extensions directory →