Articles about auth-patterns from the Skycloak team.
An MCP gateway proxies agent traffic to MCP servers and applies policy, but it does not replace token validation at…
Just-in-time provisioning creates a user at first login, but never removes one. Compare JIT and SCIM, and decide which your…
Home realm discovery sends [email protected] to the right corporate IdP without a picker. How Keycloak 26.8 Organizations does it, and…
SP-initiated SSO starts in your app; IdP-initiated SSO starts in the customer's portal. Learn the security tradeoffs and what to…
Keycloak 26.8 moves token exchange delegation to preview: users consent, FGAP V2 gates the agent, and the delegated token carries…
Keycloak 26.8.0 adds an experimental OpenID4VP verifier as an identity provider. What it supports, what it lacks, and a checklist…
MCP authorization is optional and stdio servers should skip OAuth. A decision tree for when to use API keys, OAuth,…
An IETF draft lets workloads authenticate to an OAuth server with SPIFFE JWT-SVIDs, not client secrets. What it specifies and…
AI shopping agents need two separate proofs: a token saying who acts for whom, and a signed mandate saying what…
Keycloak's OID4VP wallet verifier is merged upstream behind an experimental flag but ships in no release as of 26.7.3. Here…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.