Keycloak
keycloak.org · Authentication and identity
Open-source identity and access management with single sign-on.
57 items · 51 source threads · 2 source types · updated 2026-08
No items match these filters.
Pain points 34
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Setting up Keycloak requires hard-won knowledge that is slow to acquire The commenter says Keycloak can do anything, but learning how to configure it takes a lot of time and the knowledge is not easy to pick up. |
Setup & onboarding | Blocks work | 5 sources | 2026-08 |
| ||||
| Requests drop between Apache and Keycloak until connection settings are changed With Keycloak behind Apache as reverse proxy, requests randomly dropped and the user had to change obscure connection pooling or keep-alive settings. Affects: Self-hoster using Apache |
Self-hosting & upgrades | Blocks work | 2 sources | 2024-04 |
| ||||
| Admin API ignores user ID supplied on user creation Creating a user through the admin REST API ignores the specified id and generates a random one. Affects: Developers using the admin API |
API & developer experience | Blocks work | 2 sources | 2022-07 |
| ||||
| Keycloak SPIs poorly or not documented, forcing code reading Customizing Keycloak requires reading code and knowing Java EE because many SPIs are poorly documented or undocumented, even for simple extras like profile fields. Affects: Developers extending Keycloak |
Documentation | Blocks work | 2 sources | 2021-01 |
| ||||
| Keycloak realm configuration is complex and RAM-hungry Setting up Keycloak for user management on Kubernetes needs OAuth and complex realm configuration and consumes a lot of RAM, which the commenter finds excessive. Affects: Kubernetes operators |
Performance | Annoyance | 2 sources | 2025-06 |
| ||||
| Must build an optimized image or face long startup in containers Affects: Self-hoster using Docker |
Self-hosting & upgrades | Annoyance | 2 sources | 2024-02 |
| Keycloak clustering on AWS ECS was a prolonged struggle Affects: Enterprise platform engineer on AWS ECS |
Self-hosting & upgrades | Causes churn | 1 source | 2024-02 |
| Keycloak seen as bloated, overly complex and regretted | Reliability & bugs | Causes churn | 1 source | 2023-06 |
| Keycloak hard to run both stable and scalable in production Affects: Team running Keycloak in production |
Reliability & bugs | Blocks work | 1 source | 2026-08 |
| Multi-stage Docker builds fail --optimized validation after upgrade Affects: Teams building custom Keycloak images with themes |
Self-hosting & upgrades | Blocks work | 1 source | 2025-04 |
| Disabling a user leaves their sessions active Affects: Admins disabling users |
Permissions & security | Blocks work | 1 source | 2025-03 |
| Deleting a user sends no backchannel logout to clients Affects: Admins with backchannel logout configured |
Permissions & security | Blocks work | 1 source | 2025-03 |
| 2FA bypass took ten months to be fixed | Permissions & security | Blocks work | 1 source | 2024-11 |
| Token exchange drops requested scopes since Keycloak 24 Affects: Developers using token exchange |
Reliability & bugs | Blocks work | 1 source | 2024-05 |
| Admin API user PUT now clears name and email fields Affects: Developers using the admin API |
API & developer experience | Blocks work | 1 source | 2024-03 |
| start-dev fails on fresh download with a database exception Affects: Developers trying Keycloak locally |
Setup & onboarding | Blocks work | 1 source | 2024-01 |
| SAML IdP-initiated login fails with cookie_not_found Affects: Admins configuring SAML SSO with external IdPs |
Integrations | Blocks work | 1 source | 2023-05 |
| No zero-downtime deployment in Keycloak | Self-hosting & upgrades | Blocks work | 1 source | 2023-05 |
| Cannot install packages in Keycloak container since version 21 Affects: Docker users adding health checks |
Self-hosting & upgrades | Blocks work | 1 source | 2023-02 |
| Default Content Security Policy is too permissive | Permissions & security | Blocks work | 1 source | 2023-01 |
| Custom identity providers cannot be configured in new admin console Affects: Developers writing custom identity providers |
Customization | Blocks work | 1 source | 2022-11 |
| New admin console fails to load under some hostname setups Affects: Admins behind reverse proxies or custom hostnames |
Reliability & bugs | Blocks work | 1 source | 2022-09 |
| External IdP tokens not refreshed when retrieved Affects: Developers using GitHub apps as external IdP |
Integrations | Blocks work | 1 source | 2022-09 |
| Refresh token rotation breaks with multiple browser tabs Affects: SPA developers |
Reliability & bugs | Blocks work | 1 source | 2022-08 |
| Valid refresh token randomly rejected with 400 Affects: SPA developers using keycloak-js |
Reliability & bugs | Blocks work | 1 source | 2022-08 |
| Impersonation broken when admin hostname differs from realm hostname Affects: Admins with a separate admin hostname |
Reliability & bugs | Blocks work | 1 source | 2022-03 |
| Authentication flow steps skipped after external IdP login Affects: Admins with external identity providers |
Permissions & security | Blocks work | 1 source | 2022-02 |
| Keycloak maintenance hindered by weak documentation | Documentation | Blocks work | 1 source | 2020-07 |
| LDAP user rename deletes and recreates the Keycloak account Affects: Teams using LDAP integration |
Reliability & bugs | Blocks work | 1 source | 2020-04 |
| Keycloak seems overkill for small private deployments Affects: Small self-hosted deployments |
Setup & onboarding | Annoyance | 1 source | 2026-02 |
| Keycloak UI and data model add avoidable difficulty | UI & usability | Annoyance | 1 source | 2025-11 |
| Realm JSON import has unreadable structure and cannot maintain realm | Data export & migration | Annoyance | 1 source | 2023-04 |
| Cannot create users without first and last name Affects: Operators of game servers and username-only communities |
Customization | Annoyance | 1 source | 2022-05 |
| WebAuthn-first factor ordering still pushes users to a switch-method button | UI & usability | Annoyance | 1 source | 2022-04 |
Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.
Feature requests 17
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Ability to set order of credential types in auth flows In an identifier-first flow, the password authenticator always runs before the passwordless WebAuthn one, forcing users to pick another way to use passkeys. Affects: Admins building passwordless flows |
Customization | Blocks work | 2 sources | 2023-12 |
| ||||
| GitOps-style declarative configuration for Keycloak realms The commenter wants Keycloak to read a config file at startup and create/update/delete resources accordingly, and dislikes the Terraform plugin because of state. Affects: Teams running Keycloak on Kubernetes |
API & developer experience | Blocks work | 2 sources | 2023-06 |
| ||||
| Multiple email domains per linked IdP in organizations Organizations allow several mail domains, but each linked IdP only one, forcing duplicate IdP configurations for customers with several domains. Affects: B2B providers with customers using multiple mail domains |
Integrations | Blocks work | 1 source | 2024-10 |
| ||||
| Clone a realm from the admin interface Partial export and import into a new realm fails on duplicate keys, so an admin needing 25 near-identical realms without command-line access wants a clone function. Affects: Admins without command-line access managing many similar realms |
Data export & migration | Blocks work | 1 source | 2023-11 |
| ||||
| SMTP OAuth 2.0 authentication for outgoing email Providers like Microsoft and Google are ending basic SMTP auth, so Keycloak will be unable to send email unless it supports OAuth 2.0. Affects: Admins using Microsoft or Google mail |
Integrations | Blocks work | 1 source | 2023-03 |
| ||||
| SCIM support for user provisioning Affects: Teams integrating identity systems |
Integrations | Blocks work | 1 source | 2022-08 |
| Allow customizing CORS Access-Control-Allow-Headers Affects: Teams using distributed tracing |
API & developer experience | Blocks work | 1 source | 2022-06 |
| Automatically disable dormant user accounts Affects: Enterprise security administrators |
Permissions & security | Blocks work | 1 source | 2022-05 |
| Allow groups to have multiple parent groups Affects: Teams syncing Active Directory via LDAP |
Integrations | Blocks work | 1 source | 2022-04 |
| Restore realm import on startup via environment variable Affects: Docker Compose users automating setup |
Data export & migration | Blocks work | 1 source | 2022-02 |
| Built-in metrics for operations teams Affects: Operations and SRE teams |
Reporting & analytics | Blocks work | 1 source | 2021-12 |
| Trusted device option to skip 2FA for 30 days Affects: End users and realm admins |
Permissions & security | Blocks work | 1 source | 2021-11 |
| Helm chart for the Keycloak operator Affects: Kubernetes teams using Helm and ArgoCD |
Self-hosting & upgrades | Annoyance | 1 source | 2025-02 |
| Easier way to build custom login and registration UI | Customization | Annoyance | 1 source | 2023-06 |
| Read secrets such as DB password from files Affects: Container and Docker secrets users |
Self-hosting & upgrades | Annoyance | 1 source | 2022-03 |
| Expose role attributes as OIDC claims without script mapper Affects: Teams syncing users and groups from an external source |
Customization | Annoyance | 1 source | 2022-02 |
| Support for non-SQL datastores such as DynamoDB Affects: Teams with a global user base on AWS |
Self-hosting & upgrades | Annoyance | 1 source | 2020-04 |
Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.
Workarounds 5
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Keycloak behind Apache reverse proxy breaks connections without tuning Behind a reverse proxy Keycloak connections sometimes break; the user had to add proxy settings disabling pooling and keep-alive to stabilize it. Affects: Self-hoster using Apache as reverse proxy |
Self-hosting & upgrades | Blocks work | 1 source | 2024-02 |
| ||||
| Login state not shared across Keycloak nodes forces sticky sessions Stateful login on one server was missing on others, so plain load balancing did not work and sticky sessions were the only option. Affects: Enterprise platform engineer |
Self-hosting & upgrades | Blocks work | 1 source | 2024-02 |
| ||||
| Disabling group inheritance preserves sync but loses AD structure Turning off Preserve Group Inheritance avoids the LDAP sync failure but loses the whole Active Directory group structure inside Keycloak. Affects: Teams syncing Active Directory via LDAP |
Integrations | Blocks work | 1 source | 2022-04 |
| ||||
| Long Keycloak startup times unless an optimized image is built A self-hoster says startup is annoyingly long unless you build the optimized image, which was a pain point until done. Affects: Self-hoster |
Self-hosting & upgrades | Annoyance | 1 source | 2024-02 |
| ||||
| Customizing CSP requires overriding the whole header The only way to tune CSP today is to completely override the header, which weakens it across all Keycloak endpoints. |
Permissions & security | Annoyance | 1 source | 2023-01 |
| ||||
Switching reasons 1
| Item | Area | Severity | Support | Last seen |
|---|---|---|---|---|
| Built own auth server after missing Keycloak flow features The commenter built their own auth server after tiring of Keycloak quirks, including missing common functionality such as accepting terms before profile creation. Affects: Product developer |
Customization | Causes churn | 1 source | 2023-05 |
| ||||