Recent Blog Posts
Keycloak Workflows - Identity Governance & Administration (IGA)
Disabling stale accounts, onboarding new users into the right groups, offboarding leavers — until now that meant scripts against the Admin REST API or a separate IGA product. Keycloak Workflows brings this into the server itself: an automation engine for realm administrative tasks, and Keycloak’s first real step into Identity Governance and Administration.
Read more »Fine Grained Admin Permissions (FGAP) in Keycloak
Delegating admin rights in Keycloak has always been coarse-grained: hand someone manage-users and they can manage every user in the realm. Fine Grained Admin Permissions change that — you can now define exactly who may manage which users, groups, clients and roles, and what they’re allowed to do with them.
Keycloak DevDay 2027 - Save the date!
‼️ Mark your calendars! Keycloak DevDay 2027 is coming back to Darmstadt, Germany, on April 8–9, 2027 ‼️
Read more »Use Custom Infinispan Caches in Keycloak
When implementing custom Keycloak extensions (aka SPI implementations), the requirement to cache some data may arise from time to time. For example, you might want to cache the results of calls to external systems to reduce dependencies on those systems and speed up things during runtime.
Read more »Keycloak Account REST API OpenAPI Specification
Finally..! 🙏
Finally I created an OpenAPI Specification file (OAS) for the Keycloak Account REST API.
This API is available since Keycloak version… 12? 14?
I don’t remember anymore exactly.
At least for several years!
But it has never been documented, neither as OAS, nor in any other format.
Unfortunately.
All Blog Posts / Archive
Read all of my blog posts, find them either by tag or chronological: