Keycloak website screenshot

Keycloak

Keycloak is an open source identity and access management solution for modern applications and services, providing single sign-on, identity brokering, user federation, and fine-grained authorization using OAuth 2.0 and OpenID Connect.

Keycloak publishes 6 APIs on the APIs.io network, including Clients API, Groups API, Identity Providers API, and 3 more. Tagged areas include Authentication, Authorization, Identity Management, OAuth, and OpenID Connect.

The Keycloak catalog on APIs.io includes 1 Spectral governance ruleset.

Keycloak’s developer surface includes changelog, CLI, authentication, documentation, getting-started guide, engineering blog, and 26 more developer resources.

55.6/100 developing ▬ flat Agent 37/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serve⚡ Free to try
6 APIs
AuthenticationAuthorizationIdentity ManagementOAuthOpenID ConnectSecuritySSO

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 55.6/100 · developing
Contract Quality 14.3 / 25
Developer Ergonomics 8.7 / 20
Commercial Clarity 7.9 / 20
Operational Transparency 6.8 / 13
Governance 9.5 / 12
Discoverability 8.3 / 10
Agent readiness — 37/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 4 / 4
Consent & Bot Identity 3 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/keycloak: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

Keycloak Clients API

Manage OAuth/OIDC clients within a realm

Keycloak Groups API

Manage user groups within a realm

Keycloak Identity Providers API

Manage identity providers for federated authentication

Keycloak Realms API

Manage Keycloak realms

Keycloak Roles API

Manage realm-level and client-level roles

Keycloak Users API

Manage users within a realm

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Keycloak Admin REST API

OPEN COLLECTION

Arazzo Workflows 13

Multi-step API workflows described with the Arazzo specification.

Keycloak Assign a User to a Group

Resolve a user and a group by name, add the membership, and verify it landed.

ARAZZO

Keycloak Audit Group Membership

Resolve a group by name, read its roles and roster, and spot-check the effective roles of a member.

ARAZZO

Keycloak Audit a User's Effective Access

Resolve a user by username and assemble their profile, realm role mappings, and group membership.

ARAZZO

Keycloak Decommission a Client

Snapshot a client registration, disable it, and optionally delete it after a soak period.

ARAZZO

Keycloak Federate an Identity Provider

Upsert an OIDC or SAML identity provider by alias and verify the stored configuration.

ARAZZO

Keycloak Apply a Realm Security Baseline

Capture a realm's current settings, apply brute force protection and session hardening, and verify the result.

ARAZZO

Keycloak Inventory a Realm

Discover available realms and assemble a full read-only inventory of one realm's clients, roles, groups, and identity providers.

ARAZZO

Keycloak Offboard a User

Disable a user, strip realm role mappings and group membership, and optionally delete the account.

ARAZZO

Keycloak Onboard a User

Provision a realm user, set an initial password, and grant a realm-level role.

ARAZZO

Keycloak Provision a Group Hierarchy

Create a top-level group, resolve its id, nest a child group beneath it, and read back the hierarchy.

ARAZZO

Keycloak Register a Confidential OIDC Client

Register an OpenID Connect client in a realm, resolve its internal UUID, and retrieve its generated secret.

ARAZZO

Keycloak Rotate a Client Secret

Resolve a client by clientId, capture the outgoing secret, regenerate it, and verify the new value.

ARAZZO

Keycloak Upsert a Realm Role

Create a realm-level role if it is missing, update it if it already exists, then read it back.

ARAZZO

Scroll for all 13

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Keycloak Rate Limits

5 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

Keycloak API Rules

5 rules · 3 warnings 2 info

SPECTRAL

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Keycloak Authentication

http · 1 scheme

SECURITY

Keycloak Domain Security

TLSv1.3 · DMARC

SECURITY

Keycloak Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Keycloak Agentic Access

40 operations · 24 acting · 1 human-in-the-loop

40 operations · 24 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 1

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 16

Pagination, idempotency, versioning, errors, and events

Scroll for all 16

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Company 2

The organization behind the API

Source (apis.yml)

apis.yml Raw ↑
aid: keycloak
name: Keycloak
description: Keycloak is an open source identity and access management solution for modern applications and services, providing
  single sign-on, identity brokering, user federation, and fine-grained authorization using OAuth 2.0 and OpenID Connect.
type: Index
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/keycloak.png
tags:
- Authentication
- Authorization
- Identity Management
- OAuth
- OpenID Connect
- Security
- SSO
url: https://raw.githubusercontent.com/api-evangelist/keycloak/refs/heads/main/apis.yml
created: '2025-01-01'
modified: '2026-06-20'
specificationVersion: '0.19'
apis:
- aid: keycloak:keycloak-clients-api
  name: Keycloak Clients API
  description: Manage OAuth/OIDC clients within a realm
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Clients
  properties:
  - type: OpenAPI
    url: openapi/keycloak-clients-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
- aid: keycloak:keycloak-groups-api
  name: Keycloak Groups API
  description: Manage user groups within a realm
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Groups
  properties:
  - type: OpenAPI
    url: openapi/keycloak-groups-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
- aid: keycloak:keycloak-identity-providers-api
  name: Keycloak Identity Providers API
  description: Manage identity providers for federated authentication
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Identity Providers
  properties:
  - type: OpenAPI
    url: openapi/keycloak-identity-providers-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
- aid: keycloak:keycloak-realms-api
  name: Keycloak Realms API
  description: Manage Keycloak realms
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Realms
  properties:
  - type: OpenAPI
    url: openapi/keycloak-realms-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
- aid: keycloak:keycloak-roles-api
  name: Keycloak Roles API
  description: Manage realm-level and client-level roles
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Roles
  properties:
  - type: OpenAPI
    url: openapi/keycloak-roles-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
- aid: keycloak:keycloak-users-api
  name: Keycloak Users API
  description: Manage users within a realm
  humanURL: https://www.keycloak.org/docs-api/latest/rest-api/
  tags:
  - Users
  properties:
  - type: OpenAPI
    url: openapi/keycloak-users-api-openapi.yml
  - type: Documentation
    url: https://www.keycloak.org/docs-api/latest/rest-api/
  - type: Reference
    url: https://www.keycloak.org/docs/latest/server_admin/
  - type: JSONSchema
    url: json-schema/realm.yml
  - type: JSONSchema
    url: json-schema/client.yml
  - type: JSONSchema
    url: json-schema/user.yml
  - type: JSONLD
    url: json-ld/keycloak-context.yml
  - type: ErrorCatalog
    url: errors/keycloak-problem-types.yml
  - type: DataModel
    url: data-model/keycloak-data-model.yml
common:
- type: Arazzo
  url: arazzo/keycloak-onboard-user-workflow.yml
  name: Keycloak Onboard a User
- type: Arazzo
  url: arazzo/keycloak-offboard-user-workflow.yml
  name: Keycloak Offboard a User
- type: Arazzo
  url: arazzo/keycloak-audit-user-access-workflow.yml
  name: Keycloak Audit a User's Effective Access
- type: Arazzo
  url: arazzo/keycloak-register-oidc-client-workflow.yml
  name: Keycloak Register a Confidential OIDC Client
- type: Arazzo
  url: arazzo/keycloak-rotate-client-secret-workflow.yml
  name: Keycloak Rotate a Client Secret
- type: Arazzo
  url: arazzo/keycloak-decommission-client-workflow.yml
  name: Keycloak Decommission a Client
- type: Arazzo
  url: arazzo/keycloak-upsert-realm-role-workflow.yml
  name: Keycloak Upsert a Realm Role
- type: Arazzo
  url: arazzo/keycloak-provision-group-hierarchy-workflow.yml
  name: Keycloak Provision a Group Hierarchy
- type: Arazzo
  url: arazzo/keycloak-assign-user-to-group-workflow.yml
  name: Keycloak Assign a User to a Group
- type: Arazzo
  url: arazzo/keycloak-audit-group-membership-workflow.yml
  name: Keycloak Audit Group Membership
- type: Arazzo
  url: arazzo/keycloak-federate-identity-provider-workflow.yml
  name: Keycloak Federate an Identity Provider
- type: Arazzo
  url: arazzo/keycloak-harden-realm-workflow.yml
  name: Keycloak Apply a Realm Security Baseline
- type: Arazzo
  url: arazzo/keycloak-inventory-realm-workflow.yml
  name: Keycloak Inventory a Realm
- type: AgenticAccess
  url: agentic-access/keycloak-agentic-access.yml
- type: Packages
  url: packages/keycloak-packages.yml
- type: WellKnown
  url: well-known/keycloak-well-known.yml
- type: SecurityTxt
  url: well-known/keycloak-security.txt
- type: LLMsTxt
  url: llms/keycloak-llms.txt
- type: Conformance
  url: conformance/keycloak-conformance.yml
- type: Lifecycle
  url: lifecycle/keycloak-lifecycle.yml
- type: Conventions
  url: conventions/keycloak-conventions.yml
- type: ChangeLog
  url: changelog/keycloak-changelog.yml
- type: CLI
  url: cli/keycloak-cli.yml
- type: VulnerabilityDisclosure
  url: security/keycloak-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/keycloak-domain-security.yml
- type: Authentication
  url: authentication/keycloak-authentication.yml
- type: Website
  url: https://www.keycloak.org/
- type: Documentation
  url: https://www.keycloak.org/documentation
- type: GettingStarted
  url: https://www.keycloak.org/getting-started
- type: GitHubOrganization
  url: https://github.com/keycloak/keycloak
- type: Blog
  url: https://www.keycloak.org/blog
- type: Community
  url: https://www.keycloak.org/community
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com