K

keycloak.org

4 integrations · REST

Keycloak exposes a tenant-hosted Admin REST API, OIDC/OAuth2 endpoint set, and Client Registration Service plus bundled `kcreg` CLI; authentication is primarily bearer access tokens, with client registration also accepting initial access tokens, registration access tokens, or HTTP Basic client credentials, while the public-client installation endpoint can be unauthenticated.

discovered 2mo ago
REST · OpenAPI4
Credentials
Keycloak bearer access token for admin or client-registration APIsbearer

Create a confidential client or use a user/service account in your Keycloak realm, then obtain an access token from the realm token endpoint described in the OpenID Connect endpoints guide. For admin or client-registration access, grant the needed realm-management roles as described in Using the client registration service and Automating client registration with the CLI.

Keycloak initial access tokenbearerGet token ↗

In the Admin Console for a realm, open Clients → Initial access token, click Create, optionally set expiration and client count limits, then copy the token value immediately; Keycloak only shows it once. Use it as Authorization: bearer ... for the client registration service as documented in Using the client registration service.

Keycloak confidential client ID and client secretbasicGet credentials ↗

In your realm, create or open a confidential client and enable client authentication, then use the client ID and its secret from the client's Credentials tab. The client registration docs show this can be used with HTTP Basic auth for the installation provider, and the CLI guide shows passing the secret with kcreg config credentials --secret. See Using the client registration service and Automating client registration with the CLI.

conventions · 0/7 published

Publish these signals → /publishing