Open sourceActive

Keycloak Server

Keycloak Server: Documentation - Keycloak Join us at KeyConf Prague 2026 , happening during Open Source Sumit Europe · October 08 · Register Today → Guides Docs Downloads Community Blog Documentation 26.7.2 Guides Release Notes Getting Started How to get started with Keycloak Server Installation and Configuration Installation and offline configuration of the Keycloak server Server Container Image Documentation specific to the server container image Securing Applications and Se

Open source page

Field note

What it does

Sections: Upgrading Guide | Upgrading Keycloak | Migration Changes | Migrating to 26.7.2 | Breaking changes | Migrating to 26.7.1 | Notable changes | Deprecated features | Removed features | Migrating to 26.7.0 | Migrating to 26.6.4 | Migrating to 26.6.3 | Migrating to 26.6.2 | Migrating to 26.6.1 | Manual migration if you migrated to 26.6.0 | Migrating to 26.6.0 | Migrating to 26.5.7 | Migrating to 26.5.5 | Migrating to 26.5.4 | Migrating to 26.5.2 | Migrating to 26.5.1 | Migrating to 26.5.0 | Migrating to 26.4.6 | Migrating to 26.4.3 | Migrating to 26.4.2 | Migrating to 26.4.1 | Migrating to 26.4.0 | Migrating to 26.3.0 | Migrating to 26.2.0 | Migrating to 26.1.3 | Migrating to 26.1.0 | Deprecation notices | Migrating to 26.0.6 | Security improvements for the key resolvers | Migrating to 26.0.0 | Infinispan marshalling changes | Operator no longer defaults to proxy=passthrough | New method in ClusterProvider API | Group-related events no longer fired when removing a realm | Automatic redirect from root to relative path | Operator scheduling defaults | Operator’s default CPU and memory limits/requests | Deprecations in keycloak-common module | Consistent usage of UTF-8 charset for URL encoding | Configuring the LDAP Connection Pool | Custom Footer in Login Theme | Persisting revoked access tokens across restarts | Highly available multi-site deployments | External Infinispan in a single-site setup | Admin Bootstrapping and Recovery | Application Initiated Required Action redirect now contains kc_action Parameter | Deprecations in keycloak-services module | Identity Providers no longer available from the realm representation | CLI import placeholder replacement | New Java API to search realms by name | Keystore and trust store default format change | Improving performance for selection of identity providers | Removal of GELF logging handler | Paths for common theme resources have changed | Additional datasources now require using XA | Hostname v1 feature removed | Proxy option removed | All user sessions are persisted by default | Grace period for idle sessions removed when persistent sessions are enabled | Support for legacy redirect_uri parameter and SPI options has been removed | Additional validations on the --optimized startup option | Adapter and misc BOM files are removed | keycloak-test-helper is removed | JEE admin-client is removed | New generalized event types for credentials | --import-realm option can import the master realm | BouncyCastle FIPS updated | setOrCreateChild() method removed from JavaScript Admin Client | Keycloak JS | Stricter startup behavior for build-time options | Features renamed | Migrating to 25.0.3 | Concurrent login requests are blocked by default when brute force is enabled | Migrating to 25.0.2 | Improving performance for deletion of user consents | Migrating to 25.0.0 | New Hostname options | Persistent user sessions | Metrics for embedded caches enabled by default | Metrics for HTTP endpoints enabled by default | Argon2 password hashing | Limiting memory usage when consuming HTTP responses | Hostname Verification Policy | Addressed 'You are already logged in' for expired authentication sessions | Removed a model module | XA Transaction Changes | Removed offline session preloading | Specify cache options at runtime | kcadm and kcreg changes | Removing custom user attribute indexes | New default client scope basic | Removed session_state claim | sub claim is added to access token via protocol mapper | Nonce claim is only added to the ID token | Changed userId for events related to refresh token | Using older javascript adapter | Default http-pool-max-threads reduced | Management port for metrics and health endpoints | Escaping slashes in group paths | Change to class EnvironmentDependentProviderFactory | Removal of the deprecated LinkedIn provider | Improved performance of findGrantedResources and findGrantedOwnerResources queries | Removing deprecated methods from AccessToken , IDToken , Sections: Server Administration Guide | Keycloak features and concepts | Features | Basic Keycloak operations | Core concepts and terms | Creating the first administrator | Creating the account on the local host | Creating the account remotely | Configuring realms | Using the Admin Console | The master realm | Creating a realm | Configuring SSL for a realm | Configuring email for a realm | XOAUTH2 email configuration with third-party vendors | Configuring themes | Enabling internationalization | User locale selection | Controlling login options | Enabling forgot password | Enabling Remember Me | ACR to Level of Authentication (LoA) Mapping | Update Email Workflow (UpdateEmail) | Configuring realm keys | Rotating keys | Adding a generated key pair | Rotating keys by extracting a certificate | Adding an existing key pair and certificate | Loading keys from a Java Keystore | Making keys passive | Disabling keys | Compromised keys | Using external storage | Adding a provider | Dealing with provider failures | Lightweight Directory Access Protocol (LDAP) and Active Directory | Configuring federated LDAP storage | Storage mode | Edit mode | Other configuration options | Connecting to LDAP over SSL | Connecting to multiple LDAP servers for failover | Synchronizing LDAP users to Keycloak | LDAP mappers | Password hashing | Enabling password change after reset | Configuring the connection pool | Troubleshooting | SSSD and FreeIPA Identity Management integration | FreeIPA/IdM server | SSSD and D-Bus | Enabling the SSSD federation provider | Configuring a federated SSSD store | Custom providers | Managing users | Creating users | Managing user attributes | Understanding the Default Configuration | Understanding the User Profile Contexts | Understanding Managed and Unmanaged Attributes | Managing the User Profile | Managing Attributes | Validating Attributes | Defining UI Annotations | Managing Attribute Groups | Using the JSON configuration | Customizing How UIs are Rendered | Enabling Progressive Profiling | Using Internationalized Messages | Defining user credentials | Setting a password for a user | Requesting a user reset a password | Creating an OTP | Verifying a user’s email address | Allowing users to self-register | Enabling user registration | Registering as a new user | Requiring user to agree to terms and conditions during registration | Defining actions required at login | Setting required actions for one user | Setting required actions for all users | Enabling terms and conditions as a required action | Application initiated actions | Re-authentication during AIA | Parameterized AIA | Available actions | Searching for a user | Default search | Search by fields | Attribute search | Deleting a user | Enabling account deletion by users | Enabling the Delete Account Capability | Giving a user the delete-account role | Deleting your account | Impersonating a user | Enabling reCAPTCHA | Setting up Google reCAPTCHA | Setting up Google reCAPTCHA Enterprise | Personal data collected by Keycloak | Managing user sessions | Administering sessions | Signing out all active sessions | Viewing client sessions | Viewing user sessions | Revoking active sessions | Session and token timeouts | Offline access | Transient sessions | Assigning permissions using roles and groups | Creating a realm role | Client roles | Converting a role to a composite role | Assigning role mappings | Using default roles | Role scope mappings | Groups | Groups compared to roles | Using default groups | Configuring authentication | Password policies | Password policy types | One Time Password (OTP) policies | Time-based or counter-based one time passwords | TOTP configuration options | HOTP configuration options | Authentication flows | Built-in flows | Creating flows | Creating a password-less browser login flow | Using Client Policies to Select an Authentication Flow | Creating a browser login flow with step-up mechanism | Step-up authentication for SAML | Registra

Capabilities

Available capabilities

Tags

Tags

No tags filed yet.

Ways to use it

Ways to use it

No integrations filed yet.

Product features

Product features

Breaking changes

Deprecated features

Migrating to 26.6.3

Migrating to 26.6.4

Migrating to 26.7.0

Migrating to 26.7.1

Migrating to 26.7.2

Migration Changes

Notable changes

Removed features

Upgrading Guide

Upgrading Keycloak