Latest AI and tech news
Before upgrading refer to the migration guide for a complete list of changes....
The KEYCONF26 speaker line-up is taking shape, and this year’s agenda is now live!...
Before upgrading refer to the migration guide for a complete list of changes....
Before upgrading refer to the migration guide for a complete list of changes....
Before upgrading refer to the migration guide for a complete list of changes....
The Keycloak project has always relied on open, searchable, community-owned discussion. Over the years, the Keycloak Discourse forum has been an important part of that: a place where users could ask configuration questions, share migration experience...
Starting with Keycloak 26.7, the stateless feature is available as a preview. It fundamentally simplifies how Keycloak handles volatile data — authentication sessions, action tokens, and brute-force counters move from embedded or external Infinispan ...
Before upgrading refer to the migration guide for a complete list of changes....
This release features new capabilities for users and administrators of Keycloak. The highlights of this release are:...
We are excited to announce that Keycloak now provides experimental support for the
OpenID Shared Signals Framework 1.0 specification,
available from today in the nightly release.
This allows Keycloak to act as a Shared Signals Transmitter, pushing si...
Before upgrading refer to the migration guide for a complete list of changes....
‼️ Mark your calendars! Keycloak DevDay 2027 is coming back to Darmstadt, Germany, on April 8–9, 2027 ‼️...
Before upgrading refer to the migration guide for a complete list of changes....
The Keycloak project is back at KubeCon Japan Yokohama with all highlights: Talks, our kiosk in the Project Table, and this time also with KeycloakCon, our very-own co-located event!
If you are new to Keycloak, or already a user, join us for this exc...
Before upgrading refer to the migration guide for a complete list of changes....
This year’s KubeCon India is coming to Mumbai, and Keycloak will be part of this year’s edition on June 18-19!...
We are excited to announce that from 26.7.0, Keycloak will include experimental support for the
OpenID AuthZEN Authorization API 1.0 specification. This allows
Keycloak to act as a Policy Decision Point (PDP), exposing its authorization capabilities...
Before upgrading refer to the migration guide for a complete list of changes....
Ricardo joined the Keycloak IBM team at the beginning of 2023 and became one of the top Keycloak contributors since then....
In Keycloak 26.7.0, Fine-Grained Admin Permissions (FGAP) will support Organizations as a resource type. This means you can grant an administrator permission to manage Org A while only allowing them to view Org B — or restrict their access to a singl...
Our annual conference dedicated to the Keycloak user community returns, with even more content and networking opportunities than last year. It’s the perfect place to interact, learn, share, and exchange insights and real-world use cases, network with...
Introduced in Keycloak 26.6.0, Organization Groups bring hierarchical group management to the Organizations feature. While Organizations already let you model Business-to-Business (B2B) relationships where external companies, partners, or departments...
This release of Keycloak JS addresses two regressions in the Cordova adapter that were introduced in version 26.2.1....
Before upgrading refer to the migration guide for a complete list of changes....
Before upgrading refer to the migration guide for a complete list of changes....
If you have been following the latest blog posts, you may have noticed that we have been working on implementing the
System for Cross-domain Identity Management (SCIM) protocol in Keycloak.
We are excited to announce that the SCIM Realm API is now av...
This release features new capabilities for users and administrators of Keycloak. The highlights of this release are:...
Before upgrading refer to the migration guide for a complete list of changes....
Before upgrading refer to the migration guide for a complete list of changes....
Earlier this year, we conducted a survey to better understand how the community deploys and manages Keycloak in the real world....
The call for papers and the registration for KeycloakCon Japan 2026 is now open! Submit your talks to KeycloakCon in Japan....
Before upgrading refer to the migration guide for a complete list of changes....
First of all, we want to thank everyone who took the time to fill out our survey on SCIM support in Keycloak.
Your feedback is invaluable to us as we work on implementing this feature. We are currently in the early stages of
development, and we are u...
The testsuite module, with all related dependents, like Arquillian testsuite, is now officially deprecated....
Before upgrading refer to the migration guide for a complete list of changes....
Keycloak is the open-source IAM backbone for countless applications, and provides single sign-on, strong authentication and user federation across organizations....
Before upgrading refer to the migration guide for a complete list of changes....
The Keycloak project is back at KubeCon EU Amsterdam with all highlights: Talks, our kiosk in the Project Pavilion, and this time also with KeycloakCon, our very-own co-located event!
If you are new to Keycloak, or already a user, join us for this ex...
This release of Keycloak JS addresses a regression that was introduced in version 26.2.2 affecting applications that use hash-based routing in combination with the fragment response mode....
FOSDEM is a free event for software developers to meet, share ideas and collaborate.
Every year, thousands of developers of free and open source software from all over the world gather at the event....
Keycloak has from day one supported identity brokering, allowing users to authenticate via an
external OpenID Connect or SAML 2.0 identity provider. With federated client authentication it is
now possible to authenticate OpenID Connect clients throug...
Modern applications and AI agents increasingly operate across distributed trust domains, where each domain is protected by its own OAuth 2.0 Authorization Server. A single request may also traverse multiple resource servers to complete a task....