Get a Quote

Custom Keycloak extension (SPI) development

Custom login actions, specific identity providers, your own user database: almost anything is possible with Keycloak extensions. We design, build and maintain them.

Let's talk about your project

Extend Keycloak without forking it

Keycloak covers most standard authentication needs. When your use case goes beyond that — a specific check during login, business data to put in tokens, an existing user database to plug in — Keycloak is extended through its Service Provider Interfaces (SPI): Java extension points, packaged as a JAR and deployed next to the server, without touching its source code.

We have been building these extensions for years, for our clients and as open source.

What we build

Authenticators and flows

Custom login steps: filtering by IP address, user agent or email domain, PIN codes, step-up authentication, business checks during login.

Required actions and action tokens

Mandatory user journeys, secure single-use links sent by email, letting users pick a secondary email address.

Event listeners

React to Keycloak events (login, registration, account updates, admin actions): webhooks, audit trails, sync with your tools, workflows.

Protocol mappers

Put data from an HTTP header, an API or an external identity provider into tokens, or reshape existing claims.

Users and federation

Plug an existing user database or an API as an identity source, authenticate LDAP-only applications through Keycloak.

REST endpoints and integrations

New API endpoints, configuration generation for your authentication proxies, business metrics exposed to Prometheus.

How we work

  • The need is written down before the first line of code: which SPI, which flow, which limits.
  • From a working prototype to a tested, production-ready solution.
  • A complete delivery: source code, unit tests, deployment guide and maintenance documentation.
  • Your extensions maintained across Keycloak versions, whose internal APIs change regularly.
  • Extensions that run on self-hosted Keycloak as well as on managed Keycloak on Clever Cloud.

Our open source extensions

Part of our work is published on GitHub and runs in production:

Frequently asked questions

What is a Keycloak SPI?

A Service Provider Interface is a Keycloak extension point: a Java interface you implement, package as a JAR and drop into the server providers folder. Authentication, token contents, user storage, events, REST endpoints: most Keycloak behaviors can be extended this way, without changing its source code.

Will my extension survive Keycloak upgrades?

Keycloak internal APIs change between major versions. We favor documented interfaces to limit the impact, and we can maintain your extensions at every upgrade as part of our support.

Can I install an extension on a managed Keycloak?

Yes, if the offer allows it. On Keycloak by Clever Cloud, you drop the JAR into the providers/ folder of the FS Bucket, then rebuild and restart the application.

Let's talk about your Keycloak

Tell us about your context in a few lines: we will get back to you quickly to discuss it and suggest the right approach.

contact@please-open.it

Or follow us: LinkedIn · GitHub · Blog