Skip to main content
Glama
ireland-samantha

keycloak-mcp

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
KEYCLOAK_REALMNoThe realm being administered.
KEYCLOAK_BASE_URLNoBase URL of the Keycloak server (must be HTTPS, except for loopback development).
KEYCLOAK_CLIENT_IDNoThe confidential client ID with service accounts enabled.
KEYCLOAK_AUTH_REALMNoThe realm that issues the service‑account token (typically 'master').
KEYCLOAK_MCP_CONFIGNoPath to a private JSON file containing the Keycloak configuration (see README). If set, this file is authoritative and overrides any individual KEYCLOAK_* environment variables.
KEYCLOAK_CLIENT_SECRETNoThe client secret for the service account.
KEYCLOAK_MCP_LIVE_SOAKNoEnable live soak tests (requires KEYCLOAK_MCP_SOAK_CREDENTIALS and a disposable realm).false
KEYCLOAK_MCP_ALLOW_WRITENoSet to 'true' to enable mutation operations. Requires explicit compensation and write‑safety configuration.false
KEYCLOAK_MCP_JOURNAL_DIRNoDirectory where workflow receipts are stored.~/.local/state/keycloak-mcp
KEYCLOAK_MCP_COVERAGE_OUTNoOutput file path for coverage report.
KEYCLOAK_MCP_LIVE_COVERAGENoEnable live coverage testing.false
KEYCLOAK_MCP_SINGLE_WRITERNoSet to 'true' if only one process writes to the realm (alternative to lock database).false
KEYCLOAK_MCP_MAX_BODY_BYTESNoMaximum request/response body size in bytes (max 67108864).1048576
KEYCLOAK_MCP_CATALOG_VERSIONNoKeycloak Admin REST catalog version: 'latest' or '26.3.5'.latest
KEYCLOAK_MCP_SOAK_CREDENTIALSNoCredentials/configuration for live soak tests.
KEYCLOAK_MCP_ALLOW_REALM_ADMINNoSet to 'true' to allow global realm administration outside the configured realm.false
KEYCLOAK_MCP_COVERAGE_FIXTURESNoSet to 'true' to create test fixtures during coverage runs.false
KEYCLOAK_MCP_EXTENSION_CATALOGNoPath to a deployment‑specific extension catalog JSON file.
KEYCLOAK_MCP_LOCK_DATABASE_URLNoPostgreSQL URL for shared advisory locking across cooperating instances.
KEYCLOAK_MCP_ALLOW_IRREVERSIBLENoSet to 'true' to permit steps explicitly marked as irreversible.false
KEYCLOAK_MCP_ALLOW_SENSITIVE_READSNoSet to 'true' to allow reading endpoints that are redacted by default.false

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources