Field note
What it does
Sections: Upgrading Guide | Upgrading Keycloak | Migration Changes | Migrating to 26.7.2 | Breaking changes | Migrating to 26.7.1 | Notable changes | Deprecated features | Removed features | Migrating to 26.7.0 | Migrating to 26.6.4 | Migrating to 26.6.3 | Migrating to 26.6.2 | Migrating to 26.6.1 | Manual migration if you migrated to 26.6.0 | Migrating to 26.6.0 | Migrating to 26.5.7 | Migrating to 26.5.5 | Migrating to 26.5.4 | Migrating to 26.5.2 | Migrating to 26.5.1 | Migrating to 26.5.0 | Migrating to 26.4.6 | Migrating to 26.4.3 | Migrating to 26.4.2 | Migrating to 26.4.1 | Migrating to 26.4.0 | Migrating to 26.3.0 | Migrating to 26.2.0 | Migrating to 26.1.3 | Migrating to 26.1.0 | Deprecation notices | Migrating to 26.0.6 | Security improvements for the key resolvers | Migrating to 26.0.0 | Infinispan marshalling changes | Operator no longer defaults to proxy=passthrough | New method in ClusterProvider API | Group-related events no longer fired when removing a realm | Automatic redirect from root to relative path | Operator scheduling defaults | Operator’s default CPU and memory limits/requests | Deprecations in keycloak-common module | Consistent usage of UTF-8 charset for URL encoding | Configuring the LDAP Connection Pool | Custom Footer in Login Theme | Persisting revoked access tokens across restarts | Highly available multi-site deployments | External Infinispan in a single-site setup | Admin Bootstrapping and Recovery | Application Initiated Required Action redirect now contains kc_action Parameter | Deprecations in keycloak-services module | Identity Providers no longer available from the realm representation | CLI import placeholder replacement | New Java API to search realms by name | Keystore and trust store default format change | Improving performance for selection of identity providers | Removal of GELF logging handler | Paths for common theme resources have changed | Additional datasources now require using XA | Hostname v1 feature removed | Proxy option removed | All user sessions are persisted by default | Grace period for idle sessions removed when persistent sessions are enabled | Support for legacy redirect_uri parameter and SPI options has been removed | Additional validations on the --optimized startup option | Adapter and misc BOM files are removed | keycloak-test-helper is removed | JEE admin-client is removed | New generalized event types for credentials | --import-realm option can import the master realm | BouncyCastle FIPS updated | setOrCreateChild() method removed from JavaScript Admin Client | Keycloak JS | Stricter startup behavior for build-time options | Features renamed | Migrating to 25.0.3 | Concurrent login requests are blocked by default when brute force is enabled | Migrating to 25.0.2 | Improving performance for deletion of user consents | Migrating to 25.0.0 | New Hostname options | Persistent user sessions | Metrics for embedded caches enabled by default | Metrics for HTTP endpoints enabled by default | Argon2 password hashing | Limiting memory usage when consuming HTTP responses | Hostname Verification Policy | Addressed 'You are already logged in' for expired authentication sessions | Removed a model module | XA Transaction Changes | Removed offline session preloading | Specify cache options at runtime | kcadm and kcreg changes | Removing custom user attribute indexes | New default client scope basic | Removed session_state claim | sub claim is added to access token via protocol mapper | Nonce claim is only added to the ID token | Changed userId for events related to refresh token | Using older javascript adapter | Default http-pool-max-threads reduced | Management port for metrics and health endpoints | Escaping slashes in group paths | Change to class EnvironmentDependentProviderFactory | Removal of the deprecated LinkedIn provider | Improved performance of findGrantedResources and findGrantedOwnerResources queries | Removing deprecated methods from AccessToken , IDToken , Sections: Server Administration Guide | Keycloak features and concepts | Features | Basic Keycloak operations | Core concepts and terms | Creating the first administrator | Creating the account on the local host | Creating the account remotely | Configuring realms | Using the Admin Console | The master realm | Creating a realm | Configuring SSL for a realm | Configuring email for a realm | XOAUTH2 email configuration with third-party vendors | Configuring themes | Enabling internationalization | User locale selection | Controlling login options | Enabling forgot password | Enabling Remember Me | ACR to Level of Authentication (LoA) Mapping | Update Email Workflow (UpdateEmail) | Configuring realm keys | Rotating keys | Adding a generated key pair | Rotating keys by extracting a certificate | Adding an existing key pair and certificate | Loading keys from a Java Keystore | Making keys passive | Disabling keys | Compromised keys | Using external storage | Adding a provider | Dealing with provider failures | Lightweight Directory Access Protocol (LDAP) and Active Directory | Configuring federated LDAP storage | Storage mode | Edit mode | Other configuration options | Connecting to LDAP over SSL | Connecting to multiple LDAP servers for failover | Synchronizing LDAP users to Keycloak | LDAP mappers | Password hashing | Enabling password change after reset | Configuring the connection pool | Troubleshooting | SSSD and FreeIPA Identity Management integration | FreeIPA/IdM server | SSSD and D-Bus | Enabling the SSSD federation provider | Configuring a federated SSSD store | Custom providers | Managing users | Creating users | Managing user attributes | Understanding the Default Configuration | Understanding the User Profile Contexts | Understanding Managed and Unmanaged Attributes | Managing the User Profile | Managing Attributes | Validating Attributes | Defining UI Annotations | Managing Attribute Groups | Using the JSON configuration | Customizing How UIs are Rendered | Enabling Progressive Profiling | Using Internationalized Messages | Defining user credentials | Setting a password for a user | Requesting a user reset a password | Creating an OTP | Verifying a user’s email address | Allowing users to self-register | Enabling user registration | Registering as a new user | Requiring user to agree to terms and conditions during registration | Defining actions required at login | Setting required actions for one user | Setting required actions for all users | Enabling terms and conditions as a required action | Application initiated actions | Re-authentication during AIA | Parameterized AIA | Available actions | Searching for a user | Default search | Search by fields | Attribute search | Deleting a user | Enabling account deletion by users | Enabling the Delete Account Capability | Giving a user the delete-account role | Deleting your account | Impersonating a user | Enabling reCAPTCHA | Setting up Google reCAPTCHA | Setting up Google reCAPTCHA Enterprise | Personal data collected by Keycloak | Managing user sessions | Administering sessions | Signing out all active sessions | Viewing client sessions | Viewing user sessions | Revoking active sessions | Session and token timeouts | Offline access | Transient sessions | Assigning permissions using roles and groups | Creating a realm role | Client roles | Converting a role to a composite role | Assigning role mappings | Using default roles | Role scope mappings | Groups | Groups compared to roles | Using default groups | Configuring authentication | Password policies | Password policy types | One Time Password (OTP) policies | Time-based or counter-based one time passwords | TOTP configuration options | HOTP configuration options | Authentication flows | Built-in flows | Creating flows | Creating a password-less browser login flow | Using Client Policies to Select an Authentication Flow | Creating a browser login flow with step-up mechanism | Step-up authentication for SAML | Registra
Capabilities
Available capabilities
Tags
Tags
No tags filed yet.
Ways to use it
Ways to use it
No integrations filed yet.