Configure Identity Providers
Keycloak can broker authentication to external Identity Providers (IdPs), allowing users to log in with their existing accounts from OIDC, SAML, or social identity providers.
For foundational concepts on identity federation, see Identity Federation.
TOC
Add an OpenID Connect Identity ProviderAdd a SAML Identity ProviderAdd a Social Identity ProviderSupported Social ProvidersExample: Add GitHub as an Identity ProviderIdP MappersAdd an IdP MapperFirst Login FlowDefault First Login Flow BehaviorCustomize the First Login FlowDefault Identity ProviderBroker LogoutAdd an OpenID Connect Identity Provider
Use this procedure to integrate any OIDC-compliant identity provider (for example, Microsoft Entra ID, Okta, or another Keycloak instance).
- In the Admin Console, select the target Realm.
- Go to Identity providers in the left navigation.
- Click Add provider and select OpenID Connect v1.0.
- Configure the following:
- Click Save.
Add a SAML Identity Provider
- Go to Identity providers > Add provider > SAML v2.0.
- Configure the following:
- Click Save.
After creating the SAML IdP, download the Keycloak SP metadata to register with the external IdP:
Add a Social Identity Provider
Keycloak provides built-in templates for popular social identity providers. The configuration is similar for each; only the provider-specific client registration differs.
Supported Social Providers
Example: Add GitHub as an Identity Provider
-
Register a new OAuth App at GitHub:
- Homepage URL:
https://<keycloak-host>/realms/<realm> - Authorization callback URL:
https://<keycloak-host>/realms/<realm>/broker/github/endpoint - Note the Client ID and Client Secret.
- Homepage URL:
-
In the Keycloak Admin Console:
- Go to Identity providers > Add provider > GitHub.
- Enter the Client ID and Client Secret from the GitHub OAuth App.
- Click Save.
-
The GitHub login button appears on the Realm login page.
IdP Mappers
IdP Mappers control how user attributes and roles from the external IdP are mapped to Keycloak users.
Add an IdP Mapper
- In the IdP detail view, click the Mappers tab.
- Click Add mapper.
- Select a mapper type:
- Configure the source (IdP claim or attribute) and target (Keycloak attribute or role).
- Click Save.
First Login Flow
When a user authenticates via an external IdP for the first time, Keycloak executes a First Login Flow to determine how to handle the new identity.
Default First Login Flow Behavior
- Review Profile — The user is prompted to review and complete their profile.
- Create User — If no existing user matches, a new user is created.
- Link Existing Account — If a user with the same email already exists, the user is prompted to link accounts.
Customize the First Login Flow
- Go to Authentication > Flows tab.
- Duplicate the First broker login flow.
- Modify the steps as needed:
- Remove Review Profile to skip the profile review step.
- Add conditions to automatically link accounts without user confirmation.
- In the IdP configuration, set First login flow to your custom flow.
Default Identity Provider
You can configure a default IdP so that the Keycloak login page automatically redirects to the external IdP without showing the local login form.
- Go to Authentication > Flows > Browser flow.
- Add an Identity Provider Redirector step.
- Configure the Default Identity Provider in the step configuration.
- Set the step requirement to
Alternative.
Alternatively, applications can suggest an IdP by passing the kc_idp_hint query parameter in the authorization request:
Broker Logout
By default, when a user logs out of Keycloak, the session with the external IdP is not terminated. To enable cascading logout:
- In the IdP configuration, enable Backchannel logout or Front-channel logout (depending on IdP support).
- Ensure the external IdP is configured to accept logout requests from Keycloak.