Configure Identity Providers

Keycloak can broker authentication to external Identity Providers (IdPs), allowing users to log in with their existing accounts from OIDC, SAML, or social identity providers.

For foundational concepts on identity federation, see Identity Federation.

Add an OpenID Connect Identity Provider

Use this procedure to integrate any OIDC-compliant identity provider (for example, Microsoft Entra ID, Okta, or another Keycloak instance).

Web Console
CLI
  1. In the Admin Console, select the target Realm.
  2. Go to Identity providers in the left navigation.
  3. Click Add provider and select OpenID Connect v1.0.
  4. Configure the following:
FieldDescription
AliasA unique identifier for this IdP (for example, corporate-idp). Used in redirect URLs.
Display NameShown on the login page button (for example, Corporate SSO)
Discovery EndpointThe OIDC discovery URL (for example, https://idp.example.com/.well-known/openid-configuration). If provided, most fields are auto-populated.
Authorization URLThe IdP's authorization endpoint (auto-filled from discovery)
Token URLThe IdP's token endpoint (auto-filled from discovery)
Client IDThe client ID registered at the external IdP for this Keycloak instance
Client SecretThe client secret registered at the external IdP
Client AuthenticationMethod used to authenticate with the IdP: Client secret sent as post, Client secret sent as basic auth, or JWT signed with client secret
  1. Click Save.

Add a SAML Identity Provider

Web Console
  1. Go to Identity providers > Add provider > SAML v2.0.
  2. Configure the following:
FieldDescription
AliasUnique identifier for this IdP (for example, adfs-idp)
Display NameShown on the login page
Service Provider Entity IDThe entity ID that Keycloak uses as SP (defaults to the Keycloak Realm URL)
Single Sign-On Service URLThe IdP's SSO endpoint URL
Single Logout Service URLThe IdP's logout endpoint (optional)
NameID Policy FormatThe name ID format to request (for example, urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress)
Want AuthnRequests SignedWhether to sign SAML authentication requests
Want Assertions SignedWhether to require the IdP to sign assertions
Validating X509 CertificatesThe IdP's signing certificate (PEM format)
  1. Click Save.

After creating the SAML IdP, download the Keycloak SP metadata to register with the external IdP:

https://<keycloak-host>/realms/<realm>/broker/<alias>/endpoint/descriptor

Add a Social Identity Provider

Keycloak provides built-in templates for popular social identity providers. The configuration is similar for each; only the provider-specific client registration differs.

Supported Social Providers

ProviderProvider IDRegistration URL
GitHubgithubhttps://github.com/settings/developers
Googlegooglehttps://console.cloud.google.com/apis/credentials
Microsoftmicrosofthttps://entra.microsoft.com/
GitLabgitlabSelf-hosted GitLab: Admin > Applications
Facebookfacebookhttps://developers.facebook.com/apps

Example: Add GitHub as an Identity Provider

  1. Register a new OAuth App at GitHub:

    • Homepage URL: https://<keycloak-host>/realms/<realm>
    • Authorization callback URL: https://<keycloak-host>/realms/<realm>/broker/github/endpoint
    • Note the Client ID and Client Secret.
  2. In the Keycloak Admin Console:

    • Go to Identity providers > Add provider > GitHub.
    • Enter the Client ID and Client Secret from the GitHub OAuth App.
    • Click Save.
  3. The GitHub login button appears on the Realm login page.

IdP Mappers

IdP Mappers control how user attributes and roles from the external IdP are mapped to Keycloak users.

Add an IdP Mapper

  1. In the IdP detail view, click the Mappers tab.
  2. Click Add mapper.
  3. Select a mapper type:
Mapper TypeDescription
Attribute ImporterMaps an IdP claim/attribute to a Keycloak user attribute
Hardcoded RoleAssigns a fixed role to all users from this IdP
Hardcoded GroupAdds all users from this IdP to a fixed group
Hardcoded AttributeSets a fixed user attribute for all users from this IdP
Username Template ImporterConstructs the Keycloak username from IdP claims using a template
Advanced Claim to RoleMaps IdP claim values to Keycloak roles using conditions
SAML Attribute to RoleMaps a SAML attribute value to a Keycloak role
  1. Configure the source (IdP claim or attribute) and target (Keycloak attribute or role).
  2. Click Save.

First Login Flow

When a user authenticates via an external IdP for the first time, Keycloak executes a First Login Flow to determine how to handle the new identity.

Default First Login Flow Behavior

  1. Review Profile — The user is prompted to review and complete their profile.
  2. Create User — If no existing user matches, a new user is created.
  3. Link Existing Account — If a user with the same email already exists, the user is prompted to link accounts.

Customize the First Login Flow

  1. Go to Authentication > Flows tab.
  2. Duplicate the First broker login flow.
  3. Modify the steps as needed:
    • Remove Review Profile to skip the profile review step.
    • Add conditions to automatically link accounts without user confirmation.
  4. In the IdP configuration, set First login flow to your custom flow.

Default Identity Provider

You can configure a default IdP so that the Keycloak login page automatically redirects to the external IdP without showing the local login form.

  1. Go to Authentication > Flows > Browser flow.
  2. Add an Identity Provider Redirector step.
  3. Configure the Default Identity Provider in the step configuration.
  4. Set the step requirement to Alternative.

Alternatively, applications can suggest an IdP by passing the kc_idp_hint query parameter in the authorization request:

https://<keycloak-host>/realms/<realm>/protocol/openid-connect/auth?
  client_id=my-app&
  redirect_uri=https://my-app.example.com/callback&
  response_type=code&
  kc_idp_hint=github

Broker Logout

By default, when a user logs out of Keycloak, the session with the external IdP is not terminated. To enable cascading logout:

  1. In the IdP configuration, enable Backchannel logout or Front-channel logout (depending on IdP support).
  2. Ensure the external IdP is configured to accept logout requests from Keycloak.