Skip to content
mcp/skillhub

Keycloak Admin MCP Server

by mrz1880io.github.mrz1880/mcp-keycloak-adminv0.2.3

Administer Keycloak via its Admin REST API: users, roles, clients, groups, identity providers, federation and events, with a read-only mode.

2Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained54d ago

Install Keycloak Admin MCP server

Install in Claude Code

claude mcp add keycloak-admin -e KEYCLOAK_BASE_URL='<keycloak-base-url>' -e KEYCLOAK_REALM='<keycloak-realm>' -e AUTH_MODE='<auth-mode>' -e KC_CLIENT_SECRET='<kc-client-secret>' -e KC_ADMIN_PASSWORD='<kc-admin-password>' -- npx -y mcp-keycloak-admin

Configuration

VariableRequiredSecretDescription
KEYCLOAK_BASE_URLyes—Base URL of the Keycloak server (no trailing slash).
KEYCLOAK_REALMyes—Realm the server operates on.
AUTH_MODEyes—Authentication mode: service_account or password.
KC_CLIENT_ID——Confidential client id (service_account mode).
KC_CLIENT_SECRET—yesClient secret (service_account mode).
KC_ADMIN_USERNAME——Admin username (password mode).
KC_ADMIN_PASSWORD—yesAdmin password (password mode).
KC_ADMIN_REALM——Realm holding the admin user (password mode; default master).
READ_ONLY——When true, write and destructive tools are not registered.
ALLOWED_REALMS——Comma-separated allow-list of realms the server may operate on.

Freshness

Maintained — last maintenance signal 54d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-08-16 · 54d ago · GitHub

  2. Latest release

    2026-06-26 · 4mo ago · GitHub · v0.2.3

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-06-26 · 4mo ago · official registry · v0.2.3

FAQ

›How do I install the Keycloak Admin MCP server in Claude Code?

Run: claude mcp add keycloak-admin -e KEYCLOAK_BASE_URL='<keycloak-base-url>' -e KEYCLOAK_REALM='<keycloak-realm>' -e AUTH_MODE='<auth-mode>' -e KC_CLIENT_SECRET='<kc-client-secret>' -e KC_ADMIN_PASSWORD='<kc-admin-password>' -- npx -y mcp-keycloak-admin. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does Keycloak Admin require an API key?

Yes. It expects KEYCLOAK_BASE_URL, KEYCLOAK_REALM, AUTH_MODE, KC_CLIENT_SECRET, KC_ADMIN_PASSWORD, of which 2 are secrets.

›Can I use Keycloak Admin as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Keycloak Admin in the official MCP registry?

Yes, as io.github.mrz1880/mcp-keycloak-admin.

Alternatives to Keycloak Admin

Other security MCP servers.

View all