Tutorials, deep dives, and best practices from the Skycloak team.
Learn how to secure MCP servers with Keycloak using Dynamic Client Registration (DCR), enabling anonymous AI agents to authenticate safely.
A complete guide to Keycloak auditing: login and admin events, event listeners, retention, SIEM forwarding, alerting, and security best practices.
Learn how to customize Keycloak themes using Keycloakify and deploy them in Skycloak managed Keycloak environments.
Set up passkeys and WebAuthn in Keycloak for passwordless login and two-factor auth: required actions, authentication flows, policies, and browser…
Configure Keycloak as a SAML 2.0 Service Provider: identity brokering, metadata exchange, assertion validation, attribute mapping, and common SP errors.
Locke is an Apache 2.0 distribution of Keycloak that ships with both embedded Infinispan and a Redis cache backend, selectable…
A practical guide to configuring MFA in Keycloak, covering OTP policies, WebAuthn, conditional flows, client-specific overrides, and token-based MFA detection.
Monitor Keycloak with Prometheus and Grafana: enable metrics, track authentication KPIs, build dashboards, and define SLOs for your identity stack.
Learn how to customize Keycloak error pages, handle OAuth/OIDC errors in your app, and configure brute force protection for secure,…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.