Can AI agents automate Keycloak?

Keycloak · hybrid · identityopen-source

Keycloak is automatable today through the Admin REST API. The Server Developer Guide states that the Admin REST API has all features provided by the Admin Console. The current reference lives at {base url}/admin/realms and publishes preview OpenAPI JSON and YAML. Authentication is an OAuth 2.0 access token: a username and password grant against admin-cli, or a confidential-client service account using client credentials. Official tooling includes the Java keycloak-admin-client library and the Admin CLI (kcadm.sh / kcadm.bat) packaged with the server distribution. kc.sh export and import write and read realm JSON. Keycloak 26.7.3 is the opened download. Vendor docs describe Keycloak as an authorization server for other MCP servers; they do not declare an official Keycloak admin MCP, so first-party MCP ownership stays unknown. A maintained third-party server, @dockndevai/mcp-keycloak, is listed in the official MCP registry and wraps a subset of Admin REST tools. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path. CLI scores 7. MCP scores 4 for one maintained third-party implementation.

Best path today: api · Overall automatability: 8/10

Modalities

ModalityStatusDetail
APIyesrestopenapioauth2-passwordoauth2-client-credentials
coverage: full · docs
SDKyesjava
official: yes
MCPyes
verdict: unknown
mcp-keycloak · maintained: True
Integrationsunknown
CLIyes
Extensibilityyeskc-import-export
webhooks: unknown
Data access
export: realm-json · import: realm-json
RPA / UI automationunknownweb-dom
No repeatable UI probe was run. The Admin REST API, official Java admin client, and kcadm Admin CLI cover realm, user, client, and role administration without browser control. The opened Keycloak MCP guide is an authorization-server setup for other MCP servers, not a first-party Keycloak admin MCP. Red Hat build of Keycloak is outside this record.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
8478

Evidence

FactTierSourceDate
homepagedeclaredsource2026-09-13
licensedeclaredsource2026-09-13
deploymentdeclaredsource2026-09-13
platforms[0]declaredsource2026-09-13
platforms[1]declaredsource2026-09-13
platforms[2]declaredsource2026-09-13
statusdeclaredsource2026-09-13
modalities.api.existsdeclaredsource2026-09-13
modalities.api.kinds[0]declaredsource2026-09-13
modalities.api.kinds[1]declaredsource2026-09-13
modalities.api.auth[0]declaredsource2026-09-13
modalities.api.auth[1]declaredsource2026-09-13
modalities.api.coveragedeclaredsource2026-09-13
modalities.api.docsdeclaredsource2026-09-13
modalities.sdk.existsdeclaredsource2026-09-13
modalities.sdk.languages[0]declaredsource2026-09-13
modalities.sdk.officialdeclaredsource2026-09-13
modalities.mcp.first_partydeclaredsource2026-09-13
modalities.mcp.third_party[0]scrapedsource2026-09-13
modalities.mcp.third_party[0]scrapedsource2026-09-13
modalities.cli.existsdeclaredsource2026-09-13
modalities.extensibility.scripting[0]declaredsource2026-09-13
modalities.data_access.export[0]declaredsource2026-09-13
modalities.data_access.import[0]declaredsource2026-09-13
modalities.agent_docs.llms_txtscrapedsource2026-09-13
verdict.scores.apideclaredsource2026-09-13
verdict.scores.mcpscrapedsource2026-09-13
verdict.scores.clideclaredsource2026-09-13
freshness.watch[0].urldeclaredsource2026-09-13
freshness.watch[1].urldeclaredsource2026-09-13
freshness.watch[2].urldeclaredsource2026-09-13
freshness.watch[3].urlscrapedsource2026-09-13
freshness.watch[4].urldeclaredsource2026-09-13
freshness.watch[5].urldeclaredsource2026-09-13

Related tools

Other products in this database that share a category with Keycloak.

Last verified 2026-09-13 · volatility medium · JSON record