Open Source Identity and Access Management For Modern Applications and Services https://www.keycloak.org
  • Java 92.1%
  • TypeScript 6.9%
  • FreeMarker 0.6%
  • JavaScript 0.1%
  • Shell 0.1%
Find a file
Simon Vacek 38f29b2f00 Update Registry to use FatalTestClassException
Closes: #53322

Signed-off-by: Simon Vacek <vaceksimon-github@pm.me>
2026-10-05 07:35:00 -03:00
.claude Adding a skill for reviewing community translations with Claude or Copilot 2026-09-18 09:00:10 +02:00
.github Add OpenJDK 27 to test matrix (#53295) 2026-10-01 11:10:24 +02:00
.idea Add Intellij project icon 2023-09-18 12:39:16 +02:00
.mvn Update to Maven 3.9.16 2026-06-04 11:13:13 +02:00
.trivy Ignore Bootstrap CVEs as we are not affected by them since bootstrap javascript components are not distriburted or used (#51704) 2026-08-14 09:30:02 +02:00
adapters Format string mismatches in logging statements causing silent argument loss and potential MissingFormatArgumentException 2026-09-24 17:39:52 +02:00
authz Format string mismatches in logging statements causing silent argument loss and potential MissingFormatArgumentException 2026-09-24 17:39:52 +02:00
authzen Prevent AuthZEN requests with user tokens 2026-07-13 16:19:14 +00:00
boms Add Spotless plugin with removeUnusedImports check enabled 2025-10-13 13:32:01 +02:00
common Promote Client v2 to preview (#53215) 2026-09-30 13:59:24 +00:00
core Harden RSA1_5 JWE decryption against timing-based padding oracles 2026-09-24 11:22:03 +02:00
crypto Add explicit EC point-on-curve validation in ECDH-ES providers 2026-10-05 11:30:45 +02:00
dependencies Add missing artifact descriptions to allow Maven Central Portal Publisher pass validation process. (#40822) 2025-08-12 16:50:17 +02:00
distribution Parse pom.properties as data instead of sourcing it as shell (#53076) 2026-09-22 14:00:47 -04:00
docs Avoid substitution in the 25.0.0 upgrading changes (#53459) 2026-10-02 11:51:53 +02:00
federation fix(ldap): prevent User LDAP filter from leaking into group lookupById queries 2026-10-05 07:19:13 -03:00
integration Filter groups by view permission in getGroupsInRole 2026-10-01 14:38:25 +02:00
js When selecting an option in the UI, wait for the UI to settle 2026-10-05 08:37:41 +02:00
misc Use Keycloak parent in misc/test-stability to inherit dependency versions 2026-10-01 09:34:46 +00:00
model Clear CRL and public key storage within the cluster 2026-10-02 11:23:09 +02:00
operator Promote Client v2 to preview (#53215) 2026-09-30 13:59:24 +00:00
quarkus Limit metric series creation via idp tag on broker login endpoint 2026-10-02 08:42:19 +02:00
rest Filter authentication flow usage by client and IdP view permissions (#53315) 2026-09-30 14:28:45 -04:00
saml-core [CVE-2026-18217] SAML Redirect Binding Parameter Pollution (#51861) 2026-09-22 15:08:47 +02:00
saml-core-api Fix SAML artifact binding failing to validate signed nested samlp:Response (#50862) 2026-07-17 13:51:40 +02:00
scim Make sure user by id lookup resolves cached adapter 2026-09-30 09:38:16 -03:00
server-spi Add an IdP config option to control IdP admin role escalation. 2026-09-29 11:52:15 -03:00
server-spi-private Allow OAuth scope characters in organization alias 2026-10-01 22:56:33 +02:00
services FGAP v2 custom role injection via oidc-hardcoded-role-mapper bypasses removeTransientAdminRoles 2026-10-02 13:00:42 -03:00
skills Release notes and upgrading guide for 26.8 2026-09-22 13:42:27 +02:00
ssf Fix SSF discovery document omitting /realms/{realm} path when fronten… (#53214) 2026-09-29 12:39:17 -04:00
test-framework Update Registry to use FatalTestClassException 2026-10-05 07:35:00 -03:00
tests FGAP v2 custom role injection via oidc-hardcoded-role-mapper bypasses removeTransientAdminRoles 2026-10-02 13:00:42 -03:00
testsuite test(ldap): cover group lookup under customUserSearchFilter 2026-10-05 07:19:13 -03:00
themes Do not sanitize the plain-text organization invitation email (#52461) 2026-09-30 15:09:40 -04:00
util Fix CVEs inherited from ApacheDS/Kerby dependencies (#51899) 2026-08-21 07:59:36 +02:00
.editorconfig Proposed import order (#43432) 2025-11-14 09:34:49 +01:00
.gitattributes enforce LF line endings on *.tsx files (#45997) 2026-02-18 10:28:55 +00:00
.gitignore [OID4VCI] Credential Offer must be created by Issuer not Holder (#44255) 2025-11-27 16:07:10 +01:00
.gitleaks.toml Updated .gitleaks.toml to ignore false positive in RedirectUtilsTest (#33346) 2024-09-27 14:32:36 +02:00
ADOPTERS.md Add Xata to ADOPTERS.md (#40802) 2025-06-30 19:32:32 +02:00
AGENTS.md Adding instructions on how to create issues for AI 2026-09-25 08:52:21 +02:00
CONTRIBUTING.md Adding instructions on how to create issues for AI 2026-09-25 08:52:21 +02:00
get-version.sh Make shebang in bash scripts consistent (#37369) 2026-02-17 11:32:28 +01:00
GOVERNANCE.md Update governance model around changes in maintainership (#29292) 2024-05-22 08:24:10 +02:00
LICENSE.txt Added text version of ASL2 license 2019-11-08 12:43:10 +01:00
MAINTAINERS.md Adding maintainer affiliations (#52222) 2026-08-31 11:50:08 +00:00
maven-settings.xml [KEYCLOAK-11764] Upgrade to Wildfly 19 2020-04-24 08:19:43 -03:00
mvnw Handle special characters in mvnw.cmd Windows paths 2026-04-07 18:24:21 +02:00
mvnw.cmd Handle special characters in mvnw.cmd Windows paths 2026-04-07 18:24:21 +02:00
pom.xml Add OpenJDK 27 to test matrix (#53295) 2026-10-01 11:10:24 +02:00
PR-CHECKLIST.md Introduce CODEOWNERS (#16637) 2023-01-30 13:05:45 +01:00
README.md Add client libraries repository to README 2026-05-28 10:59:02 +02:00
RELEASES.md Describing the Keycloak release strategy 2026-09-16 09:23:49 +02:00
SECURITY-INSIGHTS.yml Provide an OpenSSF security insights manifest file 2024-02-15 11:02:33 -03:00
SECURITY.md Update SECURITY.md to align with keycloak.org security policy 2026-07-02 21:11:31 +02:00
set-version.sh Make shebang in bash scripts consistent (#37369) 2026-02-17 11:32:28 +01:00

Keycloak

GitHub Release OpenSSF Best Practices CLOMonitor OpenSSF Scorecard Artifact Hub GitHub Repo stars GitHub commit activity Translation status

Open Source Identity and Access Management

Add authentication to applications and secure services with minimum effort. No need to deal with storing users or authenticating users.

Keycloak provides user federation, strong authentication, user management, fine-grained authorization, and more.

Help and Documentation

Reporting Security Vulnerabilities

If you have found a security vulnerability, please look at the instructions on how to properly report it.

Reporting an issue

If you believe you have discovered a defect in Keycloak, please open an issue. Please remember to provide a good summary, description as well as steps to reproduce the issue.

Getting started

To run Keycloak, download the distribution from our website. Unzip and run:

bin/kc.[sh|bat] start-dev

Alternatively, you can use the Docker image by running:

docker run quay.io/keycloak/keycloak start-dev

For more details refer to the Keycloak Documentation.

Building from Source

To build from source, refer to the building and working with the code base guide.

Testing

To run tests, refer to the running tests guide.

Writing Tests

To write tests, refer to the writing tests guide.

Contributing

Before contributing to Keycloak, please read our contributing guidelines. Participation in the Keycloak project is governed by the CNCF Code of Conduct.

Joining a community meeting is a great way to get involved and help shape the future of Keycloak.

Code of Conduct

We are committed to providing a safe, welcoming, and constructive environment for all Keycloak contributors and users. To protect this space, we actively enforce our Code of Conduct. If you wish to report an incident or appeal a moderation decision, please email keycloak-coc@googlegroups.com.

Other Keycloak Projects

License