Octodet Keycloak is an MCP server that connects AI assistants to Keycloak instances for identity and access management administration. Designed for system administrators, DevOps engineers, and security teams, it provides a standardized Model Context Protocol interface to execute identity management tasks through plain language. Users can manage the complete lifecycle of accounts across different realms, including creating users with verified emails or temporary credentials, removing obsolete accounts, and listing users to inspect their unique identifiers. It also supports discovering configured realms across the Keycloak server and inspecting available client roles. In addition to read operations, the server allows operators to assign or revoke specific client roles for designated users in a single atomic modification. By eliminating the need to manually navigate the Keycloak web administrative console or formulate raw REST API calls, the server enables streamlined user onboarding, routine role audits, and permission adjustments directly from compatible LLM clients.
Category: Cloud & Infrastructure
Tags: authentication, authorization, iam, identity, keycloak
settings.json), define the server under the mcpServers block: json { "mcpServers": { "keycloak": { "command": "npx", "args": ["-y", "@octodet/keycloak-mcp"], "env": { "KEYCLOAK_URL": "http://localhost:8080", "KEYCLOAK_ADMIN": "admin", "KEYCLOAK_ADMIN_PASSWORD": "admin" } } } } 3. Adjust KEYCLOAK_URL, KEYCLOAK_ADMIN, and KEYCLOAK_ADMIN_PASSWORD to match your actual Keycloak administrative credentials and host. 4. Restart your MCP client to load the tools.Part of MCP Servers
You can run Octodet Keycloak directly through npx by executing npx -y @octodet/keycloak-mcp, or install it globally with npm install -g @octodet/keycloak-mcp. In clients like Claude Desktop or VS Code, you configure it under the mcpServers configuration block using npx along with required environment variables like KEYCLOAK_URL, KEYCLOAK_ADMIN, and KEYCLOAK_ADMIN_PASSWORD.
Octodet Keycloak exposes administrative tools to create, list, and delete users across realms. It also provides tools to list all configured realms, retrieve available client roles, and update client role assignments for specific users by adding or removing roles in a single request.
Octodet Keycloak works with any MCP-compatible environment that supports running local stdio commands, including Claude Desktop, VS Code with MCP extensions, and the MCP Inspector for local testing and debugging.
Yes, Octodet Keycloak is open-source software licensed under the MIT License. The code repository is publicly available on GitHub at https://github.com/Octodet/keycloak-mcp and published as an NPM package under @octodet/keycloak-mcp.
Most operations involving existing users, such as deleting users or updating role assignments, require the user UUID rather than a plain username. You can obtain the user ID by running the list-users tool against the target realm.