Why audit your Keycloak?
Keycloak is extremely configurable: realms, clients, authentication flows, mappers, LDAP federation, external identity providers… Every option has security consequences. A configuration that "works" is not necessarily a safe one: overly permissive redirect URIs, legacy flows still enabled, long-lived tokens, roles exposed to every client, an admin console reachable from the Internet.
An audit is especially useful:
- before going to production or opening a service to new users;
- after a major Keycloak upgrade;
- when a new team takes over the project;
- before a penetration test or a compliance process (GDPR, ISO 27001…);
- when performance or session issues show up as traffic grows.