Articles about definition and basics from the Skycloak team.
Cross-App Access (ID-JAG) lets your identity provider broker scoped API access for AI agents instead of per-app consent and refresh-token…
MCP clients get a 401 from Keycloak-protected servers because of a wrong aud claim. Here is the RFC 8707 cause,…
HIPAA compliance means meeting the U.S. rules that protect health data. Learn the HIPAA rules, who must comply, what PHI…
User provisioning is how accounts get created, updated and deactivated across your apps. The four approaches, what each costs, and…
Keycloak's latest version is 26.7.0, released July 9, 2026. See the full version history, support policy, and how to upgrade…
IdP vs SP explained: what each role does in SAML and OIDC, and how Keycloak plays both at once through…
A SAMLRequest is the Base64-encoded, deflate-compressed XML authentication request an SP sends to an IdP. Learn how to decode it…
The complete guide to Keycloak: open source IAM for SSO, MFA, user federation, and RBAC. Architecture, features, version history, and…
SCIM (System for Cross-domain Identity Management) is the open standard for automated user provisioning. How it works, SCIM 2.0 endpoints,…
What a JWKS (JSON Web Key Set) is, every field explained (kty, kid, use, n, e), how Keycloak publishes keys…
Get tutorials, product updates, and Keycloak tips delivered to your inbox.