Skip to content
Vinkius

Keycloak Connector for AI agents.

34 live capabilities

Manage your Identity and Access Management infrastructure through natural language.

Live agent request Keycloak / Connector

Waiting for input…

AI Agent

Why people use Keycloak

Keycloak IAM Management and Security Auditing

This Connector changes that by letting you describe the change instead of clicking the buttons. You can tell your agent to create a new group for the marketing team or reset the password for the admin, and it handles the API calls for you. You get a faster way to manage your security infrastructure without leaving your chat interface.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • Visual Studio Code
  • Windsurf

What Vinkius changes

That you turn your AI agent into a functional admin for your Keycloak identity provider.

Use it from Claude, ChatGPT, Cursor or another AI client you already have.

One account · 6,100+ Connectors

  1. Real-world use case 01

    Emergency Lockdown

    A security breach is detected.

  2. Real-world use case 02

    Rapid Onboarding

    A new app needs OIDC.

  3. Real-world use case 03

    Bulk User Cleanup

    A project ends and 50 users need removal.

Complete set · 34capabilities

The complete Keycloak capability set.

These are the exact actions your AI can choose when you ask it to work with Keycloak.

Capability set01 / 09

01—04

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 01 Capability

    Create group

    Create a new top-level group in a realm. Use this to organize different departments or teams.

  2. 02 Capability

    Create role

    Create a new realm-level role for permissions. This helps define what different users can do.

  3. 03 Capability

    List users

    Get a list of all users within a specific realm. Use this to see everyone in a specific environment.

  4. 04 Capability

    Logout all users

    Terminate every active session in a realm immediately. Use this for an instant global logout.

Capability set02 / 09

05—08

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 05 Capability

    Partial export realm

    Export a specific subset of realm data. Use this to move small pieces of configuration.

  2. 06 Capability

    Regenerate client secret

    Create a new secret for an existing client. Use this to rotate keys for your applications.

  3. 07 Capability

    Reset user password

    Change the password for a specific user account. Use this to help users who are locked out.

  4. 08 Capability

    Create auth flow

    Create a new authentication flow for your users. This helps define how users log in.

Capability set03 / 09

09—12

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 09 Capability

    Create client

    Set up a new client for an application. This is used to connect new apps to your identity provider.

  2. 10 Capability

    Update client

    Modify the configuration of an existing client. Use this to change OIDC or SAML settings.

  3. 11 Capability

    Update group

    Edit the details or membership of a group. This allows you to change who belongs to which team.

  4. 12 Capability

    Update realm

    Change the core information of a realm. Use this for high-level realm configuration updates.

Capability set04 / 09

13—16

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 13 Capability

    Update user

    Modify user profile details and status. This is useful for changing emails or account statuses.

  2. 14 Capability

    Create user

    Add a new user account to your system. Use this to onboard new people into your platform.

  3. 15 Capability

    Delete client

    Remove a client from your realm. Use this to decommission old applications.

  4. 16 Capability

    Delete group

    Delete a group and its associated members. This helps clean up old organizational structures.

Capability set05 / 09

17—20

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 17 Capability

    Delete realm

    Permanently remove a realm from your instance. Use this for deleting entire environments.

  2. 18 Capability

    Delete user

    Remove a user account from your realm. Use this to offboard users who no longer need access.

  3. 19 Capability

    Get client secret

    Retrieve the secret key for a specific client. This is what you need for application configuration.

  4. 20 Capability

    Get client

    View the full representation of a client's configuration. Use this to check current client settings.

Capability set06 / 09

21—24

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 21 Capability

    Get group

    View the details and membership of a specific group. This shows you who is in a specific team.

  2. 22 Capability

    Get realm

    Retrieve the configuration details for a realm. Use this to see the high-level settings of a realm.

  3. 23 Capability

    Get role

    Get the details for a specific realm-level role. This helps you see what permissions a role has.

  4. 24 Capability

    Get user

    Fetch the profile information for a specific user. Use this to check a user's account status.

Capability set07 / 09

25—28

4 capabilities in this set.

Part of 34 available through Keycloak.

  1. 25 Capability

    Import realm

    Bring in a realm configuration from an external file. Use this to move configurations between environments.

  2. 26 Capability

    List admin events

    View a history of administrative actions within a realm. This is great for security auditing.

  3. 27 Capability

    List auth flows

    See all available authentication flows. Use this to check the different ways users can log in.

  4. 28 Capability

    List client roles

    View roles assigned at the client level. This shows you permissions specific to one application.

Capability set08 / 09

29—31

3 capabilities in this set.

Part of 34 available through Keycloak.

  1. 29 Capability

    List clients

    See a list of all clients registered in a realm. Use this to see all connected apps.

  2. 30 Capability

    List groups

    View the entire hierarchy of groups. This helps you see your full organizational structure.

  3. 31 Capability

    List realms

    See all realms available to your admin account. Use this to see all different environments.

Capability set09 / 09

32—34

3 capabilities in this set.

Part of 34 available through Keycloak.

  1. 32 Capability

    List required actions

    Check the actions required for specific security flows. This helps you understand login requirements.

  2. 33 Capability

    List roles

    See all realm-level roles currently available. Use this to audit all possible permissions.

  3. 34 Capability

    List user groups

    See which groups a specific user belongs to. Use this to check a user's team memberships.

Set up in minutes

One URL. Then ask Keycloak to work.

Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Keycloak from the conversation.

Choose your client

Live preview
Advanced clients IDE · CLI

Claude · Web + desktop

Official guide ↗

Connector URL · ready to paste

Streamable HTTP
https://edge.vinkius.com/vk_preview_VDd8VBVZZLNJBW8pUCGwjhe4HqDkWkhkqiAnNHpc/mcp
  1. Step 01

    Open Connectors

    In Claude Web or Claude Desktop, open Settings and choose Connectors.

  2. Step 02

    Add the URL

    Choose Add custom connector, name it Keycloak, and paste the URL above.

  3. Step 03

    Turn it on in chat

    Select +, open Connectors, and enable Keycloak for the conversation.

Where the request belongs

Work Keycloak can move forward.

Built around the request

This is for the security and platform engineers who are tired of the click-fatigue of managing thousands of users and complex OIDC configurations in a web UI.

01

Security Administrator

Handles emergency password resets and session terminations during active security incidents.

02

DevOps Engineer

Sets up new client credentials and realm configurations during automated deployment cycles.

03

Backend Developer

Creates test users and retrieves client secrets quickly while building new authentication flows.

Bring your own AI

Change the model, client or framework. Keep Keycloak connected.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • VS Code
  • Windsurf
  • ZCode
  • Cline
  • Zed
  • Continue
  • Kiro
  • Roo Code
  • Zencoder
  • Goose
  • Void
  • Augment Code
  • Amp
  • Qodo
  • Tabnine
  • Pieces
  • Sourcegraph Cody
  • JetBrains
  • Warp
  • Amazon Q
  • Antigravity
  • BoltAI
  • Raycast
  • Jan
  • LM Studio
  • AnythingLLM
  • Open WebUI
  • Msty
  • Cherry Studio
  • LibreChat
  • TypingMind
  • Chorus
  • 5ire
  • n8n
  • LangChain
  • LlamaIndex
  • CrewAI
  • Vercel AI SDK

Before you connect

Questions about Keycloak.

The practical details behind the request, access and result.

Can the Keycloak MCP help me manage my users?

Yes, it lets you create, update, and delete user accounts using natural language. You can also reset passwords and check group memberships without opening the admin console.

How does Keycloak work with AI agents for security?

It allows your agent to perform administrative tasks like auditing events and managing roles. This means you can ask your agent to check logs or update security settings instantly.

Can I use Keycloak to manage my OIDC clients?

Absolutely. You can use the Connector to create new clients, update existing ones, and retrieve or regenerate client secrets for your applications.

Is Keycloak safe for managing my company's identity?

Yes, it's a standard capability for IAM. This Connector simply provides a way for your AI agent to interact with it using your existing admin credentials.

Can I use Keycloak to perform a global logout?

Yes, you can tell your agent to remove all active sessions in a realm. This is helpful for quickly mitigating threats during a security incident.

Can I use Keycloak to import realm configurations?

Yes, you can use the import_realm capability to bring in realm configurations from external files, making it easier to sync environments.

Can I reset a user's password using this integration?

Yes. You can use the reset_user_password capability by providing the realm name, the user ID, and the new credential representation. This allows for immediate password management via the AI.

Is it possible to audit administrative changes in a specific realm?

Absolutely. The list_admin_events capability retrieves the history of administrative actions for a target realm, helping you track who changed what and when.

Can I retrieve OIDC client secrets for my applications?

Yes, the get_client_secret capability allows you to fetch the secret for any configured client in a realm. You can also use regenerate_client_secret if a rotation is required.

One connection away

Give your agent a direct line to Keycloak.

Connect Keycloak once. Keep it beside 6,100+ managed Connectors when the next task needs more.

Explore every Connector No credit card required · Free tier available