Last updated: September 2026
Claude Code and Cursor are useful Keycloak reviewers when you feed them the right artifacts. They are dangerous change agents when you let them “fix production.” This playbook treats coding agents as senior reviewers of exportable identity config: realm JSON, Terraform plans, client lists, and authentication flows, with humans still owning apply and rollback.
Day-two identity risk is misconfigured clients, over-broad grants, and admin paths without step-up. Keycloak lets you export and diff that config, which gives an AI reviewer something concrete to read.
This is not a guide to authenticating AI agents as OAuth clients. For that, see Authenticating AI Agents with Keycloak. It is also not CIMD or MCP client registration; see Keycloak CIMD for MCP when that is your problem.
What to hand the agent (and what never to paste)
Safe inputs
- A redacted realm export (remove client secrets, SMTP passwords, IdP client secrets, private keys).
- Terraform or OpenTofu plans for Keycloak resources, with sensitive values masked.
- A table of clients: public vs confidential, redirect URIs, direct access grants, token lifespans.
- Screenshots or text dumps of authentication flows and required actions (no secrets).
- Your written policy: “admin console requires MFA,” “no public clients without PKCE,” “no shared service account across prod apps.”
Unsafe inputs
- Live admin passwords or recovery codes.
- Unredacted
kc.sh exportoutput from production. - Paste of
clientSecretvalues “so the agent can test.” - Permission to apply changes in production from the agent session.
If the agent needs to call live APIs, prefer a non-prod cluster and short-lived credentials. On Skycloak, the hosted Skycloak MCP server at https://mcp.skycloak.io is built for conversational ops with browser OAuth and tools bounded to your account scopes (destructive tools need explicit confirmation). Use that for inventory questions; still review mutations.
Prompt patterns that catch real IdP bugs
Ask for findings with severity and evidence, not a rewrite of the whole realm.
Public clients and PKCE. “List every public client. Flag any without PKCE. Flag any with http://localhost redirects left in a production-named realm.”
Direct access grants and weak grant types. “Which confidential clients still allow direct access grants or implicit flow? Cite the export fields.”
Audience and roles. “Which clients get full realm-management roles? Which have fullScopeAllowed: true or no audience mapper, so their tokens carry more roles and audiences than they need?”
Admin and step-up. “Is the admin console or account console protected by OTP or WebAuthn required actions? Are brute-force settings enabled?”
Federation footguns. “List identity providers. Flag trustEmail: true on IdPs you do not control, email mappers with config.syncMode: FORCE, and any realm with sslRequired: none.”
Pair the agent with the human checklist in Keycloak security audit and hardening so you are not inventing policy from scratch.
Verify in staging; never apply blind diffs
- Agent produces a finding list with file or JSON paths.
- Human accepts, rejects, or edits each item.
- Changes land via Terraform PR, realm import to staging, or console clicks you can replay.
- Run auth regression: login, refresh, client credentials, one broken-audience negative test.
- Only then promote to production with the same artifact.
Coding agents are excellent at proposing “set pkce.code.challenge.method to S256.” They are poor at knowing your change window, your customer IdP outage risk, or whether a mapper change will lock out a partner federation.
Generate tests from the agent (“write a checklist for Cypress or k6 hitting /token with wrong audience”) and keep those tests in git.
Where managed Keycloak fits
The agent reviews config. Someone still patches Keycloak, runs HA Postgres, and owns upgrades. If that someone should not be your on-call rotation, managed upstream Keycloak is the shorter path: same exportable model, platform handles the runtime. Start the 21-day free trial (no card), or pick the 7-day Expert path if you want a dedicated cluster from day one. Compliance posture includes SOC 2 Type II, ISO 27001, GDPR, and HIPAA.
Terraform users can keep IaC as the source of truth (Terraform for Keycloak, advanced patterns) and still use Claude Code or Cursor to review plans before apply.
Copy-paste starter prompt
You are reviewing a REDACTED Keycloak realm export for production readiness.
Do not invent settings that are not in the file.
Output: (1) critical findings with JSON paths, (2) medium findings,
(3) questions where the export is ambiguous, (4) a staging test plan.
Policy: public clients must use PKCE; no unused direct access grants;
admin paths need OTP or WebAuthn; prefer short access-token lifespans;
flag clients with realm-admin roles.
Sample finding format (make the agent use it)
Ask the agent to emit a table, not a prose essay:
| Severity | Finding | Evidence (path) | Suggested fix | Risk if ignored |
|---|---|---|---|---|
| Critical | Public client without PKCE | clients[3].attributes |
Require S256 PKCE | Auth code interception |
| High | Direct access grants on confidential client | clients[7].directAccessGrantsEnabled |
Disable if unused | Password grant abuse |
| Medium | Access token lifespan 24h | clients[2].attributes["access.token.lifespan"] |
Lower to minutes | Stolen token window |
Reject answers that rewrite the entire realm without citations. If the export does not contain a field, the agent must say “not present in export” instead of guessing.
Redaction recipe before you paste
- Export realm JSON from non-prod when possible.
- Strip keys named like
secret,password,privateKey,clientSecret,smtpServer.password. - Replace redirect URIs that contain customer hostnames with
https://example-app.invalid/callbackif you are sharing outside your org. - Keep client IDs and flow aliases intact so findings stay actionable.
- Store the redacted file in a scratch path; do not commit secrets to git “for the agent.”
What good looks like after one afternoon
- A PR or ticket list of accepted findings with owners.
- Staging import or Terraform apply of those fixes only.
- Three automated checks: happy-path login, client-credentials for one service client, negative test for wrong audience.
- A note in the runbook: “AI may draft Keycloak changes; humans apply.”
That is enough to prove the loop while production changes stay with a human reviewer.