Blog

Insights on Identity, Security & Keycloak

Tutorials, deep dives, and best practices from the Skycloak team.

Request flow
Tutorials

Secure Your Spring Boot REST API with Keycloak Token

Secure your Spring Boot REST API using Keycloak Client Credentials Grant with OAuth2 Resource Server and role-based access control.

George Thomas George Thomas 6 min read
Tutorials

Restrict Keycloak Clients to Specific Users

Learn how to restrict Keycloak client access to specific users using client roles, custom authentication flows, and group-based access control.

George Thomas George Thomas 4 min read
Keycloak custom extensions
Tutorials

Using Email OTP Keycloak Extension with Skycloak

Learn how to install and configure the email OTP Keycloak extension with Skycloak to add email-based multi-factor authentication to your…

George Thomas George Thomas 3 min read
IAM Solutions ROI: Comparing Top Enterprise Options
business

IAM Solutions ROI: Comparing Top Enterprise Options

Compare the true ROI of Auth0, Okta, AWS Cognito, self-hosted Keycloak, and managed Keycloak to find the best enterprise IAM…

Guilliano Molaire Guilliano Molaire 10 min read
Keycloak ABAC Configuration: Step-by-Step Guide
security

Keycloak ABAC Configuration: Step-by-Step Guide

Learn how to configure Attribute-Based Access Control (ABAC) in Keycloak with this step-by-step guide covering policies, resources, and permissions.

Guilliano Molaire Guilliano Molaire 10 min read
best-practices

Keycloak SAML Security: Common Vulnerabilities and How to Harden Your Configuration

Explore Keycloak SAML security vulnerabilities including CVE-2024-8698, XML wrapping attacks, and assertion replay, with hardening steps.

Guilliano Molaire Guilliano Molaire 11 min read
Tutorials

Setting Up Microsoft Entra ID SSO with Keycloak (OIDC)

Learn how to configure Microsoft Entra ID SSO with Keycloak using OIDC. Step-by-step guide covering app registration, client setup, and…

Guilliano Molaire Guilliano Molaire 10 min read
Source: Pexels
Tutorials

How Keycloak Secures Node.js Microservices

Learn how to secure Node.js microservices with Keycloak by centralizing authentication, JWT token management, and role-based access control.

Guilliano Molaire Guilliano Molaire 15 min read
Articles

How to Enable User Registration in Keycloak

Learn how to enable user registration in Keycloak, configure email verification, customize fields, and enhance security with strong password policies.

Guilliano Molaire Guilliano Molaire 12 min read
Articles

Dynamic Authorization Policies in Keycloak

Explore how dynamic authorization policies in Keycloak enhance access control through real-time, context-aware decision-making.

Guilliano Molaire Guilliano Molaire 11 min read

Stay ahead on identity & security

Get tutorials, product updates, and Keycloak tips delivered to your inbox.

© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman