Keycloak
Keycloak is an open source identity and access management solution for modern applications and services, providing single sign-on, identity brokering, user federation, and fine-grained authorization using OAuth 2.0 and OpenID Connect.
Keycloak publishes 6 APIs on the APIs.io network, including Clients API, Groups API, Identity Providers API, and 3 more. Tagged areas include Authentication, Authorization, Identity Management, OAuth, and OpenID Connect.
The Keycloak catalog on APIs.io includes 1 Spectral governance ruleset.
Keycloak’s developer surface includes changelog, CLI, authentication, documentation, getting-started guide, engineering blog, and 26 more developer resources.
Kin Score
APIs 6
Individual APIs this provider publishes, each with its own machine-readable definition.
Keycloak Clients API
Manage OAuth/OIDC clients within a realm
Keycloak Groups API
Manage user groups within a realm
Keycloak Identity Providers API
Manage identity providers for federated authentication
Keycloak Realms API
Manage Keycloak realms
Keycloak Roles API
Manage realm-level and client-level roles
Keycloak Users API
Manage users within a realm
Open Collections 1
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Keycloak Admin REST API
OPEN COLLECTIONArazzo Workflows 13
Multi-step API workflows described with the Arazzo specification.
Keycloak Assign a User to a Group
Resolve a user and a group by name, add the membership, and verify it landed.
ARAZZOKeycloak Audit Group Membership
Resolve a group by name, read its roles and roster, and spot-check the effective roles of a member.
ARAZZOKeycloak Audit a User's Effective Access
Resolve a user by username and assemble their profile, realm role mappings, and group membership.
ARAZZOKeycloak Decommission a Client
Snapshot a client registration, disable it, and optionally delete it after a soak period.
ARAZZOKeycloak Federate an Identity Provider
Upsert an OIDC or SAML identity provider by alias and verify the stored configuration.
ARAZZOKeycloak Apply a Realm Security Baseline
Capture a realm's current settings, apply brute force protection and session hardening, and verify the result.
ARAZZOKeycloak Inventory a Realm
Discover available realms and assemble a full read-only inventory of one realm's clients, roles, groups, and identity providers.
ARAZZOKeycloak Offboard a User
Disable a user, strip realm role mappings and group membership, and optionally delete the account.
ARAZZOKeycloak Onboard a User
Provision a realm user, set an initial password, and grant a realm-level role.
ARAZZOKeycloak Provision a Group Hierarchy
Create a top-level group, resolve its id, nest a child group beneath it, and read back the hierarchy.
ARAZZOKeycloak Register a Confidential OIDC Client
Register an OpenID Connect client in a realm, resolve its internal UUID, and retrieve its generated secret.
ARAZZOKeycloak Rotate a Client Secret
Resolve a client by clientId, capture the outgoing secret, regenerate it, and verify the new value.
ARAZZOKeycloak Upsert a Realm Role
Create a realm-level role if it is missing, update it if it already exists, then read it back.
ARAZZOScroll for all 13
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Keycloak Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Keycloak Finops
FINOPSSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
Keycloak API Rules
SPECTRALSecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 3
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 16
Pagination, idempotency, versioning, errors, and events
Scroll for all 16
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Company 2
The organization behind the API