Extensions

Browse the full index of Keycloak community extensions.

Showing 49-59 of 59 extensions

QR Code Authentication
12

Sign in to Keycloak using another device with QR Codes

Authenticator Hadley So · Updated
Push MFA
11

Keycloak Push-MFA Extension

Authenticator IT-Systemhaus der Bundesagentur für Arbeit · Updated
Vault Provider (OpenBao / HashiCorp Vault)
11

Keycloak Vault SPI provider for OpenBao and HashiCorp Vault

Misc Nordix · Updated
Client Certificate Lookup for Envoy
9

Keycloak X509 client certificate lookup SPI implementation for Envoy

Authenticator Nordix · Updated
TikTok Identity Provider
6

Keycloak social login provider for TikTok

Identity Provider MPOWR IT · Updated
Personal Access Tokens
3
Credential mrulex · Updated
REST Claim Mapper
2

Custom OIDC and SAML Protocol Mapper for Keycloak 26.x that enriches federated users with attributes fetched from external REST APIs at token issuance time.

Mapper Joakim Westlund · Updated
Client Webhook
1

The primary objective is to address the current absence of a Keycloak extension that supports webhook calls from individual Keycloak clients. Typically, webhook configurations are set up at the realm level, resulting in their application to all clients within that realm.

Event Listener Mr Buch · Updated
HiOrg-Server Identity Provider
1

Keycloak extension to add HiOrg-Server as an identity provider

Identity Provider Martin Böhmer
Token Authenticator
1

A Keycloak authenticator that enables login with an ID or Access token

Authenticator Michael Kunz · Updated
Proof of Work
0

Keycloak PoW Extension — adds computational PoW (proof-of-work) challenges to login, registration, and password-reset flows. Protects against bot spam and brute-force attacks by requiring clients to solve a light cryptographic puzzle before authenticating. Uses Argon2 (memory-hard, GPU-resistant) or SHA-256, with IP-adaptive difficulty that scales challenge hardness based on per-IP request patterns. Rate state is stored in Infinispan, enabling shared difficulty tracking across clustered Keycloak instances. Deploy as a standard Keycloak SPI plugin — works with any Keycloak 26.6 instance. Three-layer defense on every submission: 1. Honeypot — silently rejects bots that auto-fill all form fields 2. Solve-time validation — rejects submissions arriving faster than configured minimum (default 500ms) 3. Hash verification — verifies proof-of-work correctness and prevents nonce replay attacks

Authenticator Mr Buch · Updated