Octodet Keycloak

Octodet Keycloak is an MCP server that connects AI assistants to Keycloak instances for identity and access management administration. Designed for system administrators, DevOps engineers, and security teams, it provides a standardized Model Context Protocol interface to execute identity management tasks through plain language. Users can manage the complete lifecycle of accounts across different realms, including creating users with verified emails or temporary credentials, removing obsolete accounts, and listing users to inspect their unique identifiers. It also supports discovering configured realms across the Keycloak server and inspecting available client roles. In addition to read operations, the server allows operators to assign or revoke specific client roles for designated users in a single atomic modification. By eliminating the need to manually navigate the Keycloak web administrative console or formulate raw REST API calls, the server enables streamlined user onboarding, routine role audits, and permission adjustments directly from compatible LLM clients.

Category: Cloud & Infrastructure

Tags: authentication, authorization, iam, identity, keycloak

Visit Octodet Keycloak

How to install and configure Octodet Keycloak

  1. Ensure Node.js 18 or higher is installed and you have access to a running Keycloak server. 2. In your MCP client configuration (such as Claude Desktop or VS Code settings.json), define the server under the mcpServers block: json { "mcpServers": { "keycloak": { "command": "npx", "args": ["-y", "@octodet/keycloak-mcp"], "env": { "KEYCLOAK_URL": "http://localhost:8080", "KEYCLOAK_ADMIN": "admin", "KEYCLOAK_ADMIN_PASSWORD": "admin" } } } } 3. Adjust KEYCLOAK_URL, KEYCLOAK_ADMIN, and KEYCLOAK_ADMIN_PASSWORD to match your actual Keycloak administrative credentials and host. 4. Restart your MCP client to load the tools.

What you can do with Octodet Keycloak

  • Creating new user accounts across target realms with predefined temporary passwords and contact information directly via conversational commands. - Listing and reviewing active realms on a Keycloak server to verify environment settings before executing administrative changes. - Auditing available client roles and retrieving user UUIDs to inspect current permission architectures across registered applications. - Adding or removing application-specific client roles for existing users to adjust administrative access or team responsibilities in one operation. - Permanently deleting deprecated user profiles from target realms by identifier during offboarding workflows.

Key facts

  • https://github.com/Octodet/keycloak-mcp
  • Cloud & Infrastructure, Security & Compliance
  • authentication, authorization, iam, identity, keycloak

Part of MCP Servers

Related MCP servers

  • MCP KQL Server — MCP KQL Server is an MCP server that connects AI assistants to Azure Data Explorer clusters using Azure CLI authentication.…
  • MCP Media Player — MCP Media Player is an MCP server that exposes playback controls for Home Assistant media players to AI agents. It…
  • MCP Kubernetes Server — MCP Kubernetes Server is an MCP server that provides tools for managing and inspecting Kubernetes clusters directly through Large Language…
  • MCP Nomad Go — MCP Nomad Go is an MCP server that connects AI assistants to HashiCorp Nomad clusters. Written in Go, it allows…
  • MCP Minecraft Remote — MCP Minecraft Remote is an MCP server that enables AI assistants to remotely connect to and control a player character…
  • MCP My Mac — MCP My Mac is an MCP server that exposes macOS system hardware specifications, system configurations, and environment details to AI…

How do I install Octodet Keycloak?

You can run Octodet Keycloak directly through npx by executing npx -y @octodet/keycloak-mcp, or install it globally with npm install -g @octodet/keycloak-mcp. In clients like Claude Desktop or VS Code, you configure it under the mcpServers configuration block using npx along with required environment variables like KEYCLOAK_URL, KEYCLOAK_ADMIN, and KEYCLOAK_ADMIN_PASSWORD.

What can Octodet Keycloak do?

Octodet Keycloak exposes administrative tools to create, list, and delete users across realms. It also provides tools to list all configured realms, retrieve available client roles, and update client role assignments for specific users by adding or removing roles in a single request.

Which MCP clients work with Octodet Keycloak?

Octodet Keycloak works with any MCP-compatible environment that supports running local stdio commands, including Claude Desktop, VS Code with MCP extensions, and the MCP Inspector for local testing and debugging.

Is Octodet Keycloak open source?

Yes, Octodet Keycloak is open-source software licensed under the MIT License. The code repository is publicly available on GitHub at https://github.com/Octodet/keycloak-mcp and published as an NPM package under @octodet/keycloak-mcp.

Does Octodet Keycloak require user IDs or usernames for role updates?

Most operations involving existing users, such as deleting users or updating role assignments, require the user UUID rather than a plain username. You can obtain the user ID by running the list-users tool against the target realm.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories