Keycloak
Keycloak is an open source identity and access management solution for modern applications and services, providing single sign-on, identity brokering, user federation, and fine-grained authorization using OAuth 2.0 and OpenID Connect.
Keycloak publishes 6 APIs on the APIs.io network, including Clients API, Groups API, Identity Providers API, and 3 more. Tagged areas include Authentication, Authorization, Identity Management, OpenID Connect, and Security.
The Keycloak catalog on APIs.io includes 1 Spectral governance ruleset.
Keycloak’s developer surface includes changelog, CLI, authentication, documentation, getting-started guide, engineering blog, and 29 more developer resources.
Kin Score
What adopting Keycloak moves on the Kin Score 6
Keycloak is an area vendor: providers adopt it to run part of their developer surface. This is the Kin Score checks its features can move for a provider that adopts it, what each one really earns, and what it earns nothing for.
Keycloak is self-hosted, so its discovery document already sits on the provider’s own domain, and it advertises authorization_code and a registration endpoint. But the document lives under the realm path, and the harvest probes only the host root, so the served tiers of auth clarity, delegated identity and dynamic client registration are reached only if the provider also answers the root well-known paths (a reverse-proxy rewrite). Keycloak says outright that protected-resource metadata is the MCP server’s job, and it does not yet support RFC 8707 resource indicators.
| Check | Earns | Through |
|---|---|---|
| Machine-Readable Authpartial Agent ReadinessThe served tier needs the document at the host root; Keycloak serves it under /realms/ |
7.5 of 10 | Realm-scoped OIDC discovery |
| Delegated User Identitypartial Agent ReadinessServed tier needs the root document; documented reads an authorizationCode flow in the provider’s OpenAPI. |
3.0 of 6 | Realm-scoped OIDC discovery |
| Self-service sign-up Access ClarityEnable realm self-registration and declare the login/registration URL as a Login or SignUp pointer. |
5.0 of 5 | Login and self-registration pages |
| Enumerates OAuth scopessaturated Contract QualityOnly if the provider’s own OpenAPI declares oauth2 and enumerates its client scopes. |
4.0 of 4 | MCP authorization server support |
| Registration Without a Humanconditional Agent ReadinessOnly if the provider serves the realm’s discovery document at the host’s root /.well-known/openid-configuration or oauth-authorization-server (reverse-proxy rewrite) on a host on its record; the realm-path document is not probed. |
6.0 of 6 | Client Registration service (RFC 7591/7592) |
| FAPI / hardened authorization profileconditional RegulatoryBanking/open-finance regime, FAPI client policies switched on, and the provider’s own auth documentation stating FAPI, PAR, private_key_jwt or mTLS-bound tokens. |
6.0 of 6 | Certified specifications incl. FAPI |
What Keycloak ships that earns nothing (2)
- Certified specifications incl. FAPI — The OpenID/FAPI certifications are Keycloak’s; the check reads a certification the provider holds.
- Realm-scoped OIDC discovery — openid-configuration is not one of the well-known documents that check reads, at any path.
A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. The rating is not for sale → · Full vendor facets artifact
APIs 6
Individual APIs this provider publishes, each with its own machine-readable definition.
Keycloak Clients API
Manage OAuth/OIDC clients within a realm
Keycloak Groups API
Manage user groups within a realm
Keycloak Identity Providers API
Manage identity providers for federated authentication
Keycloak Realms API
Manage Keycloak realms
Keycloak Roles API
Manage realm-level and client-level roles
Keycloak Users API
Manage users within a realm
Open Collections 8
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONKeycloak Admin REST API
OPEN COLLECTIONKeycloak Admin REST Clients API
OPEN COLLECTIONKeycloak Admin REST Clients Groups API
OPEN COLLECTIONKeycloak Admin REST Clients Identity Providers API
OPEN COLLECTIONKeycloak Admin REST Clients Realms API
OPEN COLLECTIONKeycloak Admin REST Clients Roles API
OPEN COLLECTIONKeycloak Admin REST Clients Users API
OPEN COLLECTIONScroll for all 8
Arazzo Workflows 13
Multi-step API workflows described with the Arazzo specification.
Keycloak Assign a User to a Group
Resolve a user and a group by name, add the membership, and verify it landed.
ARAZZOKeycloak Audit Group Membership
Resolve a group by name, read its roles and roster, and spot-check the effective roles of a member.
ARAZZOKeycloak Audit a User's Effective Access
Resolve a user by username and assemble their profile, realm role mappings, and group membership.
ARAZZOKeycloak Decommission a Client
Snapshot a client registration, disable it, and optionally delete it after a soak period.
ARAZZOKeycloak Federate an Identity Provider
Upsert an OIDC or SAML identity provider by alias and verify the stored configuration.
ARAZZOKeycloak Apply a Realm Security Baseline
Capture a realm's current settings, apply brute force protection and session hardening, and verify the result.
ARAZZOKeycloak Inventory a Realm
Discover available realms and assemble a full read-only inventory of one realm's clients, roles, groups, and identity providers.
ARAZZOKeycloak Offboard a User
Disable a user, strip realm role mappings and group membership, and optionally delete the account.
ARAZZOKeycloak Onboard a User
Provision a realm user, set an initial password, and grant a realm-level role.
ARAZZOKeycloak Provision a Group Hierarchy
Create a top-level group, resolve its id, nest a child group beneath it, and read back the hierarchy.
ARAZZOKeycloak Register a Confidential OIDC Client
Register an OpenID Connect client in a realm, resolve its internal UUID, and retrieve its generated secret.
ARAZZOKeycloak Rotate a Client Secret
Resolve a client by clientId, capture the outgoing secret, regenerate it, and verify the new value.
ARAZZOKeycloak Upsert a Realm Role
Create a realm-level role if it is missing, update it if it already exists, then read it back.
ARAZZOScroll for all 13
Pricing Plans 1
Published pricing tiers and plan structures.
Rate Limits 1
Documented rate limits and quota policies.
Keycloak Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals for API financial operations.
Keycloak Finops
FINOPSSpectral Rules 1
Spectral governance rulesets for linting and validating these APIs.
Keycloak API Rules
SPECTRALSecurity Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
Recommended x-agentic-access execution contracts for AI agents.
Resources
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 4
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 16
Pagination, idempotency, versioning, errors, and events
Scroll for all 16
Build 3
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Operate 2
Status, limits, changes, and where to get help
Company 2
The organization behind the API
Other 2
Properties that don't map to a standard resource type
Source (apis.yml)
Work with this as data
Every provider here is available over the APIs.io API and to AI agents over MCP.