keycloak.org
Keycloak exposes a tenant-hosted Admin REST API, OIDC/OAuth2 endpoint set, and Client Registration Service plus bundled `kcreg` CLI; authentication is primarily bearer access tokens, with client registration also accepting initial access tokens, registration access tokens, or HTTP Basic client credentials, while the public-client installation endpoint can be unauthenticated.
- Keycloak Admin REST APIdiscovered
- Keycloak OpenID Connect endpointsdiscovered
- Keycloak Client Registration Servicediscovered
Create a confidential client or use a user/service account in your Keycloak realm, then obtain an access token from the realm token endpoint described in the OpenID Connect endpoints guide. For admin or client-registration access, grant the needed realm-management roles as described in Using the client registration service and Automating client registration with the CLI.
In the Admin Console for a realm, open Clients → Initial access token, click Create, optionally set expiration and client count limits, then copy the token value immediately; Keycloak only shows it once. Use it as Authorization: bearer ... for the client registration service as documented in Using the client registration service.
In your realm, create or open a confidential client and enable client authentication, then use the client ID and its secret from the client's Credentials tab. The client registration docs show this can be used with HTTP Basic auth for the installation provider, and the CLI guide shows passing the secret with kcreg config credentials --secret. See Using the client registration service and Automating client registration with the CLI.
conventions · 0/7 published
- integrations.json——
- llms.txt✗
/llms.txt - API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing