keycloak-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| KEYCLOAK_REALM | No | The realm being administered. | |
| KEYCLOAK_BASE_URL | No | Base URL of the Keycloak server (must be HTTPS, except for loopback development). | |
| KEYCLOAK_CLIENT_ID | No | The confidential client ID with service accounts enabled. | |
| KEYCLOAK_AUTH_REALM | No | The realm that issues the service‑account token (typically 'master'). | |
| KEYCLOAK_MCP_CONFIG | No | Path to a private JSON file containing the Keycloak configuration (see README). If set, this file is authoritative and overrides any individual KEYCLOAK_* environment variables. | |
| KEYCLOAK_CLIENT_SECRET | No | The client secret for the service account. | |
| KEYCLOAK_MCP_LIVE_SOAK | No | Enable live soak tests (requires KEYCLOAK_MCP_SOAK_CREDENTIALS and a disposable realm). | false |
| KEYCLOAK_MCP_ALLOW_WRITE | No | Set to 'true' to enable mutation operations. Requires explicit compensation and write‑safety configuration. | false |
| KEYCLOAK_MCP_JOURNAL_DIR | No | Directory where workflow receipts are stored. | ~/.local/state/keycloak-mcp |
| KEYCLOAK_MCP_COVERAGE_OUT | No | Output file path for coverage report. | |
| KEYCLOAK_MCP_LIVE_COVERAGE | No | Enable live coverage testing. | false |
| KEYCLOAK_MCP_SINGLE_WRITER | No | Set to 'true' if only one process writes to the realm (alternative to lock database). | false |
| KEYCLOAK_MCP_MAX_BODY_BYTES | No | Maximum request/response body size in bytes (max 67108864). | 1048576 |
| KEYCLOAK_MCP_CATALOG_VERSION | No | Keycloak Admin REST catalog version: 'latest' or '26.3.5'. | latest |
| KEYCLOAK_MCP_SOAK_CREDENTIALS | No | Credentials/configuration for live soak tests. | |
| KEYCLOAK_MCP_ALLOW_REALM_ADMIN | No | Set to 'true' to allow global realm administration outside the configured realm. | false |
| KEYCLOAK_MCP_COVERAGE_FIXTURES | No | Set to 'true' to create test fixtures during coverage runs. | false |
| KEYCLOAK_MCP_EXTENSION_CATALOG | No | Path to a deployment‑specific extension catalog JSON file. | |
| KEYCLOAK_MCP_LOCK_DATABASE_URL | No | PostgreSQL URL for shared advisory locking across cooperating instances. | |
| KEYCLOAK_MCP_ALLOW_IRREVERSIBLE | No | Set to 'true' to permit steps explicitly marked as irreversible. | false |
| KEYCLOAK_MCP_ALLOW_SENSITIVE_READS | No | Set to 'true' to allow reading endpoints that are redacted by default. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues