Keycloak MCP Server

MCP server for Keycloak

Local serverstdioTypeScript

What is the Keycloak MCP server?

MCP server for Keycloak. Exposed over MCP by the keycloak mcp server, that capability becomes something an assistant can invoke while it works, not something you go and do afterwards.

What it actually does

A Model Context Protocol (MCP) server implementation for Keycloak, providing a standardized interface for managing Keycloak users and realms.

This project implements an MCP server that integrates with Keycloak, allowing you to manage Keycloak users and realms through a standardized protocol. It uses the official Keycloak Admin Client to interact with Keycloak's API.

Configuration

You will need 3 environment variables: KEYCLOAK_URL, KEYCLOAK_ADMIN, KEYCLOAK_ADMIN_PASSWORD. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

  • Node.js (Latest LTS version recommended) - npm - A running Keycloak instance

Adding it to your client

Installation goes through your MCP client rather than a global install: point it at @smithery/cli on npm and it is fetched when the client starts. The copy-paste blocks for Claude Desktop, Claude Code and Cursor are further down this page.

When to reach for it

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. It is maintained by haithamoumer; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Keycloak's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Caveats

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the keycloak mcp server does with a few real requests.

How to install the Keycloak MCP server

### For Local Development

```json
{
  "mcpServers": {
    "keycloak": {
      "command": "node",
      "args": ["path/to/dist/server.js"],
      "env": {
        "KEYCLOAK_URL": "http://localhost:8080",
        "KEYCLOAK_ADMIN": "admin",
        "KEYCLOAK_ADMIN_PASSWORD": "admin"
      }
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

  • Node.js (Latest LTS version recommended) - npm - A running Keycloak instance
VariableDescriptionRequired
KEYCLOAK_URLCredential the server authenticates with.Yes
KEYCLOAK_ADMINCredential the server authenticates with.Yes
KEYCLOAK_ADMIN_PASSWORDCredential the server authenticates with.Yes

Frequently asked questions

It connects Keycloak to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Keycloak directly.