Manage Keycloak Identity and Access
Python MCP server for Keycloak's REST API - manage users, clients, roles, groups, realms, and auth flows via natural language.
1.2.2Add to Favorites
Why it matters
Automate the management of users, clients, roles, and realms within Keycloak using natural language commands. This asset enables AI agents to perform comprehensive identity and access control operations programmatically.
Outcomes
What it gets done
Manage user lifecycle (creation, deletion, password resets, session control).
Configure OAuth2/OIDC clients and manage client secrets.
Define and assign realm and client-specific roles for fine-grained access control.
Administer realm settings, event configurations, and default groups.
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/vb-keycloak | bash Capabilities
Tools your agent gets
List users with pagination and filtering
Create a new user
Update an existing user
Delete a user
Reset a user's password
Get user sessions
Logout a user
Count total users
Overview
Keycloak MCP Server
mcp-keycloak gives an AI assistant natural-language access to Keycloak's REST API for user, client, role, group, realm, and authentication-flow management. Use it for conversational Keycloak administration; requires valid admin credentials (SERVER_URL/USERNAME/PASSWORD/REALM_NAME) for every operation.
What it does
Keycloak MCP Server (mcp-keycloak) bridges AI applications and Keycloak's identity and access management REST API, letting an assistant manage user lifecycle (creation to deletion, password resets, sessions), OAuth2/OIDC client configuration (including client secrets and service accounts), role-based access control (realm and client-specific roles), realm-wide administration (settings, default groups, event config), authentication flows (creating/updating/copying flows, managing executions and authenticators), and group hierarchies with membership management.
It authenticates to Keycloak using admin username/password plus a target realm, with optional OAuth2 client credentials, and supports both stdio (default, for local CLI tools) and HTTP transport.
When to use - and when NOT to
Use this connector when you want an assistant to administer Keycloak conversationally - creating users, assigning roles, configuring OAuth2 clients, managing group hierarchies, or building custom authentication flows.
Do not use it without valid Keycloak admin credentials (SERVER_URL, USERNAME, PASSWORD, REALM_NAME) configured - every tool operates against your Keycloak instance's admin API and requires these to authenticate.
Inputs and outputs
Tools take user/client/role/group/realm identifiers and configuration payloads (e.g. user attributes, client settings, role names, flow definitions). Outputs are the corresponding Keycloak objects or lists - user records, client secrets, role/group assignments, realm settings, or authentication flow/execution details.
Capabilities
- User management:
list_users,create_user/update_user/delete_user,reset_user_password,get_user_sessions/logout_user,count_users - Client management:
list_clients/get_client/create_client/update_client/delete_client,get_client_secret/regenerate_client_secret,get_client_service_account - Role management:
list_realm_roles/create_realm_role,list_client_roles/create_client_role,assign_realm_role_to_user/remove_realm_role_from_user,assign_client_role_to_user - Group management:
list_groups/create_group/update_group,get_group_members/add_user_to_group/remove_user_from_group - Realm administration:
get_accessible_realms,get_realm_info/update_realm_settings,get_realm_events_config/update_realm_events_config,add_realm_default_group/remove_realm_default_group - Authentication management:
list_authentication_flows/create_authentication_flow/update_authentication_flow/delete_authentication_flow/copy_authentication_flow,get_flow_executions/update_flow_executions,create_execution/delete_execution,get_authenticator_config/create_authenticator_config,get_required_actions/update_required_action
How to install
Via Smithery: npx -y @smithery/cli install mcp-keycloak --client claude. Or via pip: pip install mcp-keycloak. Configure:
SERVER_URL=https://your-keycloak-server.com
USERNAME=admin-username
PASSWORD=admin-password
REALM_NAME=your-realm
Run with python -m src.main (stdio, default) or TRANSPORT=http python -m src.main for HTTP mode. Requirements are Python 3.8 or higher, a Keycloak server (tested with Keycloak 18+), and admin access to the target realm.
HTTP mode is offered for network accessibility, concurrent connections from multiple AI clients, easier integration with web applications, and deployment behind a load-balancing reverse proxy - all communication goes through a single /mcp/ endpoint using JSON-RPC 2.0 over POST, with FastMCP automatically choosing between a single JSON response or an SSE stream. Its security implementation follows the MCP specification: Origin header validation blocks cross-origin requests to prevent DNS rebinding attacks, the server binds to 127.0.0.1 only by default, and no authentication is required for local/trusted-environment use - production deployments are expected to add HTTPS, a reverse proxy, firewall rules, and authentication at the proxy layer themselves. Four example use cases are documented: AI-powered identity management (user onboarding, permissions, access control via natural language), automated user provisioning workflows driven by business rules, identity analytics (querying user data, sessions, and access patterns for insight), and DevOps integration into CI/CD pipelines for automated identity-service configuration.
Who it's for
Identity teams and developers who want an AI assistant to manage Keycloak users, clients, roles, groups, and authentication flows via natural language.
Source README
Keycloak MCP Server
A Model Context Protocol (MCP) server that provides a natural language interface for managing Keycloak identity and access management through its REST API. This server enables AI agents to perform user management, client configuration, realm administration, and role-based access control operations seamlessly.
Overview
The Keycloak MCP Server bridges the gap between AI applications and Keycloak's powerful identity management capabilities. Whether you're building an AI assistant that needs to manage users, configure clients, or handle complex authorization scenarios, this server provides the tools you need through simple, natural language commands.
Features
๐ Comprehensive User Management
Manage users lifecycle from creation to deletion, including password resets, session management, and user attribute updates.
๐ข Client Configuration
Create and configure OAuth2/OIDC clients, manage client secrets, and handle service accounts programmatically.
๐ฅ Role-Based Access Control
Define and assign realm and client-specific roles, manage user permissions, and implement fine-grained access control.
๐๏ธ Realm Administration
Configure realm settings, manage default groups, handle event configurations, and control realm-wide policies.
๐ Authentication Management
Comprehensive authentication flow management including creating, updating, and deleting flows, managing executions, and configuring authenticators.
๐ Group Management
Organize users into groups, manage group hierarchies, and handle group-based permissions efficiently.
Installation
Installing via Smithery
To install mcp-keycloak for Claude Desktop automatically via Smithery:
npx -y @smithery/cli install mcp-keycloak --client claude
Quick Start
Install using pip:
pip install mcp-keycloak
Development Installation
Clone the repository and install dependencies:
git clone https://github.com/idoyudha/mcp-keycloak.git
cd mcp-keycloak
pip install -e .
Configuration
The server can be configured using environment variables or a .env file:
# Required configuration
SERVER_URL=https://your-keycloak-server.com
USERNAME=admin-username
PASSWORD=admin-password
REALM_NAME=your-realm
# Optional OAuth2 client configuration
CLIENT_ID=optional-client-id
CLIENT_SECRET=optional-client-secret
Tools
The Keycloak MCP Server provides a comprehensive set of tools organized by functionality:
User Management
Complete user lifecycle management including:
list_users- List users with pagination and filteringcreate_user/update_user/delete_user- Full CRUD operationsreset_user_password- Password managementget_user_sessions/logout_user- Session controlcount_users- User statistics
Client Management
OAuth2/OIDC client configuration:
list_clients/get_client/create_client- Client operationsget_client_secret/regenerate_client_secret- Secret managementget_client_service_account- Service account accessupdate_client/delete_client- Client modifications
Role Management
Fine-grained permission control:
list_realm_roles/create_realm_role- Realm role operationslist_client_roles/create_client_role- Client-specific rolesassign_realm_role_to_user/remove_realm_role_from_user- Role assignmentsget_user_realm_roles/assign_client_role_to_user- User role queries
Group Management
Hierarchical user organization:
list_groups/create_group/update_group- Group operationsget_group_members/add_user_to_group- Membership managementget_user_groups/remove_user_from_group- User group associations
Realm Administration
System-wide configuration:
get_accessible_realms- List of accessible realmsget_realm_info/update_realm_settings- Realm configurationget_realm_events_config/update_realm_events_config- Event managementadd_realm_default_group/remove_realm_default_group- Default settings
Authentication Management
Complete authentication flow control:
list_authentication_flows/get_authentication_flow- Flow managementcreate_authentication_flow/update_authentication_flow- Flow CRUD operationsdelete_authentication_flow/copy_authentication_flow- Flow modificationsget_flow_executions/update_flow_executions- Execution managementcreate_execution/delete_execution- Execution lifecycleget_authenticator_config/create_authenticator_config- Configuration managementget_required_actions/update_required_action- Required actions control
Usage
Running the Server
The server supports both stdio (default) and HTTP transports. The smithery.yaml configuration file enables deployment on the Smithery platform and automatic installation via Smithery CLI:
# Run in stdio mode (default, for local CLI tools)
python -m src.main
# Run in HTTP mode with streamable HTTP transport
TRANSPORT=http python -m src.main
# Run HTTP mode on a custom port
TRANSPORT=http PORT=8080 python -m src.main
# Or use the convenience script:
./scripts/run_server.sh # stdio mode (default)
./scripts/run_server.sh http # HTTP mode
PORT=8080 ./scripts/run_server.sh http # HTTP mode on custom port
When using HTTP transport, the server will be accessible at http://127.0.0.1:8000/mcp/ (or your custom PORT).
HTTP Transport
The Keycloak MCP Server supports HTTP transport mode, which offers several advantages:
- Network Accessibility: Access the server from any machine on your network
- Multiple Clients: Support concurrent connections from multiple AI clients
- Integration Flexibility: Easy integration with web applications and APIs
- Load Balancing: Deploy behind a reverse proxy for scalability
HTTP Protocol Details
The HTTP transport follows the MCP specification for Streamable HTTP. FastMCP automatically handles all protocol requirements:
- Endpoint: All communication happens through
/mcp/endpoint - Request Method: POST requests with JSON-RPC 2.0 messages
- Content Types:
- Server returns
Content-Type: application/jsonfor single responses - Server returns
Content-Type: text/event-streamfor streaming responses
- Server returns
- Accept Headers: Clients must include
Accept: application/json, text/event-stream - Message Format: All messages use JSON-RPC 2.0 format, UTF-8 encoded
FastMCP automatically determines whether to return a single JSON response or an SSE stream based on the request type and whether the response needs streaming capabilities.
Connecting to HTTP Server
When running in HTTP mode, clients can connect to:
http://127.0.0.1:8000/mcp/
Example client request:
curl -X POST http://localhost:8000/mcp/ \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc": "2.0", "method": "list_tools", "id": 1}'
Security Implementation
The HTTP transport implements all MCP specification security requirements:
โ Origin Header Validation (REQUIRED)
- Automatically validates Origin headers to prevent DNS rebinding attacks
- Only allows connections from
localhostand127.0.0.1origins - Blocks unauthorized cross-origin requests
โ Localhost Binding (RECOMMENDED)
- Binds to
127.0.0.1only to prevent network-based attacks - Follows MCP specification security recommendations
โ No Authentication Required
- The server runs without authentication requirements for simplified local development
- Suitable for localhost usage and trusted environments
For production deployments, additional considerations:
- Use HTTPS with proper certificates
- Deploy behind a reverse proxy (nginx, Apache)
- Set appropriate firewall rules
- Implement authentication at the reverse proxy level if needed
Integration Examples
Prerequisites
Before integrating the Keycloak MCP Server, ensure you have one of the following installed:
- uvx (recommended): Install via
pip install uvxorpipx install uvx - uv: Follow installation instructions
- npm/npx: For Smithery installation (comes with Node.js)
Option 1: Using Smithery CLI (Recommended)
The easiest way - automatically configures everything for Claude Desktop:
npx @smithery/cli install @idoyudha/mcp-keycloak --client claude
This command will prompt you for the required configuration values and set up the server automatically.
Option 2: Using uvx (Manual Setup)
No cloning required! Add to your claude_desktop_config.json:
{
"mcpServers": {
"keycloak": {
"command": "uvx",
"args": ["mcp-keycloak"],
"env": {
"SERVER_URL": "https://your-keycloak.com",
"USERNAME": "admin",
"PASSWORD": "admin-password",
"REALM_NAME": "your-realm"
}
}
}
}
Option 3: Local Development Setup
For development or customization:
- Clone the repository:
git clone https://github.com/idoyudha/mcp-keycloak.git
cd mcp-keycloak
- Add to your
claude_desktop_config.json:
{
"mcpServers": {
"keycloak": {
"command": "uv",
"args": [
"--directory",
"/path/to/mcp-keycloak",
"run",
"python",
"-m",
"src"
],
"env": {
"SERVER_URL": "https://your-keycloak.com",
"USERNAME": "admin",
"PASSWORD": "admin-password",
"REALM_NAME": "your-realm"
}
}
}
}
๐ก Quick Tips:
- Replace
/path/to/mcp-keycloakwith the actual path where you cloned the repository - Ensure your Keycloak server URL includes the protocol (
https://orhttp://) - The
REALM_NAMEshould match an existing realm in your Keycloak instance
Example Use Cases
๐ค AI-Powered Identity Management
Build AI assistants that can handle user onboarding, permission management, and access control through natural language commands.
๐ Automated User Provisioning
Create workflows that automatically provision users, assign roles, and configure client applications based on business rules.
๐ Identity Analytics
Query and analyze user data, session information, and access patterns to gain insights into your identity infrastructure.
๐ DevOps Integration
Integrate Keycloak management into your CI/CD pipelines, allowing automated configuration of identity services.
Requirements
- Python 3.8 or higher
- Keycloak server (tested with Keycloak 18+)
- Admin access to Keycloak realm
FAQ
Common questions
Trust
How it checks out
Discussion
Questions & comments ยท 0
Sign In Sign in to leave a comment.