Founder at Skycloak
Guilliano is the founder of Skycloak and a cloud infrastructure specialist with deep expertise in product development and scaling SaaS products. He discovered Keycloak while consulting on enterprise IAM and built Skycloak to make managed Keycloak accessible to teams of every size.
TrustSink turns a rogue Entra external MFA provider into a password trap after an admin compromise. What it needs, why…
Login is one of the biggest sections of a vendor security questionnaire. What the SSO, MFA, access review, audit log…
Connect Cursor to the Skycloak MCP server at mcp.skycloak.io, sign in with browser OAuth, and manage Keycloak clusters, realms, apps…
Use Claude Code or Cursor to review Keycloak realm exports safely: redact secrets, catch PKCE and audience mistakes, and keep…
CVE-2026-95503 lets an adjacent-network attacker spoof the KDC when Keycloak does Kerberos password authentication without SPNEGO. No fixed release yet.
Okta shipped Resource Access Certifications for AI agents on 22 September 2026. What the control does, and how to run…
A one-page identity vendor risk brief: the three risks worth five minutes of a CTO's time, the one question to…
AI coding agents find bugs and bad configs. They do not replace token issuance, audience checks, step-up, or revocation. Here…
CVE-2026-17526 let a Keycloak impersonation-role holder take over a realm admin. Fixed in 26.7.4 on 16 September 2026, and on…
Keycloak 26.x ships no push authenticator, so MFA fatigue lands differently here. The exposure that matters is authenticator enrollment, and…