Der Skycloak MCP-Server gibt jedem MCP-Client, Claude, ChatGPT, Gemini, Grok oder Ihrem Editor Ihre gesamte Plattform: Cluster, Realms, Anwendungen, SSO, Custom Domains, WAF, Webhooks, SIEM und Branding. Ein Befehl, Browser-Anmeldung, nichts zu installieren.
$ claude mcp add --transport http skycloak https://mcp.skycloak.io
Das ist Claude Code. Überall sonst fügen Sie dieselbe URL ein: einen benutzerdefinierten Connector in Claude, ChatGPT, Gemini oder Grok, einen JSON-Eintrag in Cursor oder VS Code. Kein API-Schlüssel zum Erstellen, Einfügen in eine Konfigurationsdatei oder vergessen zu rotieren.
Richten Sie einen Agent auf eine Keycloak Admin API und er kann Realms bearbeiten. Er kann keinen Cluster bereitstellen, keine Custom Domain verifizieren, keine WAF-Regel ändern oder Events an Ihr SIEM senden. Diese Oberflächen sind die Managed Platform, und genau dort spart ein Assistant am meisten Zeit.
Provision, resize, upgrade and inspect the managed Keycloak clusters themselves.
Read and change the protection in front of the cluster, not just the settings inside it.
Add a domain, get back the DNS records to create, then trigger verification and manage routes.
Subscribe to platform events, inspect what is subscribed, and fire a test delivery.
Wire cluster events into Splunk, Datadog, Sentinel or a webhook sink, and test the pipe.
Query authentication and admin events, read logs, and export realms or event history.
The Keycloak layer: realms, users, roles, groups and membership.
OIDC and SAML clients, their roles and sessions, plus the identity providers behind sign-in.
Login and email branding, theme upload and per-client theme assignment.
Install and upgrade Keycloak extensions, and configure or test outbound mail.
Acht Aufgaben, die Teams dem MCP-Server jeden Tag übergeben, laufen gegen eine Live-Plattform. Wählen Sie eine aus oder lassen Sie es laufen.
$ claude mcp add --transport http skycloak https://mcp.skycloak.io
That is Claude Code. Everywhere else you paste the same URL: a custom connector in Claude, ChatGPT, Gemini or Grok, a JSON entry in Cursor or VS Code. No API key to create or rotate.
Bounded by your own access. Read questions run against your live platform. Anything that changes state is limited to your permissions, and deletions refuse to run without an explicit confirm=true.
The scary part of handing an assistant your Identitätsanbieter is not that it does nothing useful. It is that it does something very useful to the wrong realm. So there is no second permission system to reason about.
Tools werden gegen die Scopes des Credentials registriert, mit dem Sie sich angemeldet haben. Wenn Ihr Account kein Client Secret rotieren kann, kann es Ihr Assistant auch nicht. Nichts zu konfigurieren, nichts, das vom realen Zugriff abweichen kann.
Deleting a realm, an application or an Identitätsanbieter requires an explicit confirm=true. Without it the tool declines and says why, so an ambiguous instruction cannot cascade into a deletion.
Die Anmeldung läuft über Ihr Skycloak-Konto über OAuth. Es gibt keinen langlebigen Schlüssel in einer Konfigurationsdatei auf einem Laptop, und das Widerrufen des Zugriffs ist dieselbe Aktion, die Sie bereits verwenden.
https://mcp.skycloak.io and exposes every operation the Skycloak platform API supports, spanning managed Keycloak clusters, realms, applications, identity providers, users, custom domains, edge security and WAF, webhooks, SIEM destinations, branding, extensions, SMTP and audit logs. You connect with one command and sign in through your browser over OAuth, there is nothing to install, and an assistant only ever gets the access the signed-in account already has.https://mcp.skycloak.io and it does the rest. In Claude, ChatGPT, Gemini and Grok that means adding a custom connector; in Claude Code it is claude mcp add --transport http skycloak https://mcp.skycloak.io; in Cursor, VS Code and other editors it is a JSON entry with "type": "http" and that URL. On first use the server returns a 401 carrying its OAuth metadata and the client opens a browser for you to sign in. See the MCP documentation for the full setup.confirm=true, so a vague instruction cannot cascade into a deletion.Connect in one command, or start a kostenlose Testversion and spin up a cluster to point it at. unbegrenzte Benutzer on every plan, real upstream Keycloak, no lock-in.