Get a Quote

Keycloak audit: security, configuration and operations

An expert review of your Keycloak instance: we find security gaps, configuration mistakes and operational risks, then deliver a prioritized report with the fixes.

Let's talk about your project

Why audit your Keycloak?

Keycloak is extremely configurable: realms, clients, authentication flows, mappers, LDAP federation, external identity providers… Every option has security consequences. A configuration that "works" is not necessarily a safe one: overly permissive redirect URIs, legacy flows still enabled, long-lived tokens, roles exposed to every client, an admin console reachable from the Internet.

An audit is especially useful:

  • before going to production or opening a service to new users;
  • after a major Keycloak upgrade;
  • when a new team takes over the project;
  • before a penetration test or a compliance process (GDPR, ISO 27001…);
  • when performance or session issues show up as traffic grows.

What we check

Realms and clients

  • Public vs confidential clients, PKCE, secrets management
  • Redirect URIs and web origins (wildcards, forgotten domains)
  • Needlessly enabled flows: implicit, direct access grants
  • Default client scopes and the "full scope allowed" switch
  • Service accounts and admin permissions

Tokens and sessions

  • Access token, refresh token and SSO session lifespans
  • Offline sessions and revocation
  • Token contents: roles, claims, exposed personal data
  • Signature algorithms and key rotation

Authentication

  • Authentication flows and required actions
  • MFA: OTP, WebAuthn, passkeys
  • Password policy and brute force protection
  • Levels of authentication (ACR / LoA) and step-up

Federation

  • LDAP / Active Directory: edit mode, synchronization, mappers
  • OpenID Connect, SAML and social identity brokering
  • First broker login and account linking

Operations

  • Keycloak version and known vulnerabilities (CVE)
  • Cluster, Infinispan cache, database
  • Reverse proxy, hostname, admin console exposure
  • Logs, events, metrics and backups

Extensions and applications

  • Code review of custom extensions (SPI) and themes
  • Compatibility with upcoming Keycloak versions
  • How your applications use OAuth2 / OpenID Connect: chosen flows, token storage and validation

How an audit works

1

Scoping

Scope, environments and interviews with your teams.

2

Analysis

Review of configuration, infrastructure, application flows and extensions.

3

Report

Every finding with its severity, its impact and the recommended fix.

4

Debrief

Presentation to your teams and a prioritized action plan.

We have a rule: write everything. The report is written so that your teams can fix things on their own.

A tool born from our audits

We automated part of our checks in Keycloak config checker, an open source extension that detects bad configurations right inside Keycloak and can be plugged into your monitoring to catch regressions between two audits. Discover Keycloak config checker.

Frequently asked questions

How long does a Keycloak audit take?

It depends on the scope: number of realms, clients, extensions and environments. We define it together during a first call, then send you a detailed proposal.

Can you fix the issues you find?

Yes. The report is written so that your teams can act on their own, but we can also take care of the fixes, develop extensions or evolve your architecture.

Does the audit apply to a managed Keycloak?

Yes: self-hosted Keycloak, on Kubernetes or managed, for instance Keycloak on Clever Cloud. On a managed offer, the audit focuses on configuration, extensions and how your applications are integrated.

Let's talk about your Keycloak

Tell us about your context in a few lines: we will get back to you quickly to discuss it and suggest the right approach.

contact@please-open.it

Or follow us: LinkedIn · GitHub · Blog