Keycloak Connector for AI agents.
34 live capabilities
Manage your Identity and Access Management infrastructure through natural language.
Waiting for input…
Why people use Keycloak
Keycloak IAM Management and Security Auditing
This Connector changes that by letting you describe the change instead of clicking the buttons. You can tell your agent to create a new group for the marketing team or reset the password for the admin, and it handles the API calls for you. You get a faster way to manage your security infrastructure without leaving your chat interface.
What Vinkius changes
That you turn your AI agent into a functional admin for your Keycloak identity provider.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 6,100+ Connectors
- Real-world use case 01
Emergency Lockdown
A security breach is detected.
- Real-world use case 02
Rapid Onboarding
A new app needs OIDC.
- Real-world use case 03
Bulk User Cleanup
A project ends and 50 users need removal.
Complete set · 34capabilities
The complete Keycloak capability set.
These are the exact actions your AI can choose when you ask it to work with Keycloak.
01—04
4 capabilities in this set.
Part of 34 available through Keycloak.
- 01 Capability
Create group
Create a new top-level group in a realm. Use this to organize different departments or teams.
- 02 Capability
Create role
Create a new realm-level role for permissions. This helps define what different users can do.
- 03 Capability
List users
Get a list of all users within a specific realm. Use this to see everyone in a specific environment.
- 04 Capability
Logout all users
Terminate every active session in a realm immediately. Use this for an instant global logout.
05—08
4 capabilities in this set.
Part of 34 available through Keycloak.
- 05 Capability
Partial export realm
Export a specific subset of realm data. Use this to move small pieces of configuration.
- 06 Capability
Regenerate client secret
Create a new secret for an existing client. Use this to rotate keys for your applications.
- 07 Capability
Reset user password
Change the password for a specific user account. Use this to help users who are locked out.
- 08 Capability
Create auth flow
Create a new authentication flow for your users. This helps define how users log in.
09—12
4 capabilities in this set.
Part of 34 available through Keycloak.
- 09 Capability
Create client
Set up a new client for an application. This is used to connect new apps to your identity provider.
- 10 Capability
Update client
Modify the configuration of an existing client. Use this to change OIDC or SAML settings.
- 11 Capability
Update group
Edit the details or membership of a group. This allows you to change who belongs to which team.
- 12 Capability
Update realm
Change the core information of a realm. Use this for high-level realm configuration updates.
13—16
4 capabilities in this set.
Part of 34 available through Keycloak.
- 13 Capability
Update user
Modify user profile details and status. This is useful for changing emails or account statuses.
- 14 Capability
Create user
Add a new user account to your system. Use this to onboard new people into your platform.
- 15 Capability
Delete client
Remove a client from your realm. Use this to decommission old applications.
- 16 Capability
Delete group
Delete a group and its associated members. This helps clean up old organizational structures.
17—20
4 capabilities in this set.
Part of 34 available through Keycloak.
- 17 Capability
Delete realm
Permanently remove a realm from your instance. Use this for deleting entire environments.
- 18 Capability
Delete user
Remove a user account from your realm. Use this to offboard users who no longer need access.
- 19 Capability
Get client secret
Retrieve the secret key for a specific client. This is what you need for application configuration.
- 20 Capability
Get client
View the full representation of a client's configuration. Use this to check current client settings.
21—24
4 capabilities in this set.
Part of 34 available through Keycloak.
- 21 Capability
Get group
View the details and membership of a specific group. This shows you who is in a specific team.
- 22 Capability
Get realm
Retrieve the configuration details for a realm. Use this to see the high-level settings of a realm.
- 23 Capability
Get role
Get the details for a specific realm-level role. This helps you see what permissions a role has.
- 24 Capability
Get user
Fetch the profile information for a specific user. Use this to check a user's account status.
25—28
4 capabilities in this set.
Part of 34 available through Keycloak.
- 25 Capability
Import realm
Bring in a realm configuration from an external file. Use this to move configurations between environments.
- 26 Capability
List admin events
View a history of administrative actions within a realm. This is great for security auditing.
- 27 Capability
List auth flows
See all available authentication flows. Use this to check the different ways users can log in.
- 28 Capability
List client roles
View roles assigned at the client level. This shows you permissions specific to one application.
29—31
3 capabilities in this set.
Part of 34 available through Keycloak.
- 29 Capability
List clients
See a list of all clients registered in a realm. Use this to see all connected apps.
- 30 Capability
List groups
View the entire hierarchy of groups. This helps you see your full organizational structure.
- 31 Capability
List realms
See all realms available to your admin account. Use this to see all different environments.
32—34
3 capabilities in this set.
Part of 34 available through Keycloak.
- 32 Capability
List required actions
Check the actions required for specific security flows. This helps you understand login requirements.
- 33 Capability
List roles
See all realm-level roles currently available. Use this to audit all possible permissions.
- 34 Capability
List user groups
See which groups a specific user belongs to. Use this to check a user's team memberships.
Set up in minutes
One URL. Then ask Keycloak to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Keycloak from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it Keycloak, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable Keycloak for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the Keycloak URL.
- Step 03
Save and start
Save the connection and enable Keycloak in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"keycloak": {
"url": "https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using Keycloak
Open Agent mode in chat and ask: "Using Keycloak, help me...". 34 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"keycloak": {
"url": "https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using Keycloak
Ask Copilot: "Using Keycloak, help me...". 34 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"keycloak": {
"url": "https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using Keycloak
Open Cascade and ask: "Using Keycloak, help me...". 34 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"keycloak": {
"url": "https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using Keycloak
Ask Cline: "Using Keycloak, help me...". 34 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add keycloak --transport http "https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using Keycloak
Ask Claude: "Using Keycloak, show me...". 34 tools are ready
Where the request belongs
Work Keycloak can move forward.
This is for the security and platform engineers who are tired of the click-fatigue of managing thousands of users and complex OIDC configurations in a web UI.
Security Administrator
Handles emergency password resets and session terminations during active security incidents.
DevOps Engineer
Sets up new client credentials and realm configurations during automated deployment cycles.
Backend Developer
Creates test users and retrieves client secrets quickly while building new authentication flows.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsAuth0
Manage IAM operations—users, clients, connections, and logs in your Auth0 tenant directly via your AI agent.
Okta
Equip your AI agent with Okta Identity Cloud to manage users, groups, and seamless authentication effortlessly.
Clerk
Add production-ready authentication to your app with user management, SSO, multi-factor auth, and session handling out of the box.
Casdoor (IAM)
Manage identity and access control via Casdoor. list users, manage organizations, and configure applications directly from any AI agent.
Atlassian Crowd
Equip your AI agent to manage users, groups, and directory memberships via the Atlassian Crowd API.
Authing
Cloud-native identity and access management platform. manage users, roles, and security logs via AI.
Bring your own AI
Change the model, client or framework. Keep Keycloak connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about Keycloak.
The practical details behind the request, access and result.
Can the Keycloak MCP help me manage my users?
Yes, it lets you create, update, and delete user accounts using natural language. You can also reset passwords and check group memberships without opening the admin console.
How does Keycloak work with AI agents for security?
It allows your agent to perform administrative tasks like auditing events and managing roles. This means you can ask your agent to check logs or update security settings instantly.
Can I use Keycloak to manage my OIDC clients?
Absolutely. You can use the Connector to create new clients, update existing ones, and retrieve or regenerate client secrets for your applications.
Is Keycloak safe for managing my company's identity?
Yes, it's a standard capability for IAM. This Connector simply provides a way for your AI agent to interact with it using your existing admin credentials.
Can I use Keycloak to perform a global logout?
Yes, you can tell your agent to remove all active sessions in a realm. This is helpful for quickly mitigating threats during a security incident.
Can I use Keycloak to import realm configurations?
Yes, you can use the import_realm capability to bring in realm configurations from external files, making it easier to sync environments.
Can I reset a user's password using this integration?
Yes. You can use the reset_user_password capability by providing the realm name, the user ID, and the new credential representation. This allows for immediate password management via the AI.
Is it possible to audit administrative changes in a specific realm?
Absolutely. The list_admin_events capability retrieves the history of administrative actions for a target realm, helping you track who changed what and when.
Can I retrieve OIDC client secrets for my applications?
Yes, the get_client_secret capability allows you to fetch the secret for any configured client in a realm. You can also use regenerate_client_secret if a rotation is required.
One connection away
Give your agent a direct line to Keycloak.
Connect Keycloak once. Keep it beside 6,100+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available