Friction

Keycloak

keycloak.org · Authentication and identity

Open-source identity and access management with single sign-on.

57 items · 51 source threads · 2 source types · updated 2026-08

Compare

Pain points 34

ItemAreaSeveritySupportLast seen
Setting up Keycloak requires hard-won knowledge that is slow to acquire

The commenter says Keycloak can do anything, but learning how to configure it takes a lot of time and the knowledge is not easy to pick up.

Setup & onboardingBlocks work5 sources2026-08

“there's a lot of knowledge of how to set things up that takes time and is not readily acquired”

“it was annoying to setup but worked okay in practice”

Requests drop between Apache and Keycloak until connection settings are changed

With Keycloak behind Apache as reverse proxy, requests randomly dropped and the user had to change obscure connection pooling or keep-alive settings.

Affects: Self-hoster using Apache

Self-hosting & upgradesBlocks work2 sources2024-04

“if you have Keycloak running behind Apache as a reverse proxy, I've had requests between those two randomly drop”

“sometimes acts in stupid ways behind a reverse proxy”

Admin API ignores user ID supplied on user creation

Creating a user through the admin REST API ignores the specified id and generates a random one.

Affects: Developers using the admin API

API & developer experienceBlocks work2 sources2022-07

“it is not possible to create a user or a group through an api call that has already mapped these role and client role”

“the specified user ID parameter is ignored and a random ID is generated instead”

Keycloak SPIs poorly or not documented, forcing code reading

Customizing Keycloak requires reading code and knowing Java EE because many SPIs are poorly documented or undocumented, even for simple extras like profile fields.

Affects: Developers extending Keycloak

DocumentationBlocks work2 sources2021-01

“Implementing the user federation SPI for Keycloak is actually pretty tricky”

“are poorly documented at best, or totally undocumented at worst”

Keycloak realm configuration is complex and RAM-hungry

Setting up Keycloak for user management on Kubernetes needs OAuth and complex realm configuration and consumes a lot of RAM, which the commenter finds excessive.

Affects: Kubernetes operators

PerformanceAnnoyance2 sources2025-06

“complex realm configuration. It's a mess. It requires a lot of RAM to work”

“Keycloak is much heavier than Hydra”

Must build an optimized image or face long startup in containers

Affects: Self-hoster using Docker

Self-hosting & upgradesAnnoyance2 sources2024-02
Keycloak clustering on AWS ECS was a prolonged struggle

Affects: Enterprise platform engineer on AWS ECS

Self-hosting & upgradesCauses churn1 source2024-02
Keycloak seen as bloated, overly complex and regretted
Reliability & bugsCauses churn1 source2023-06
Keycloak hard to run both stable and scalable in production

Affects: Team running Keycloak in production

Reliability & bugsBlocks work1 source2026-08
Multi-stage Docker builds fail --optimized validation after upgrade

Affects: Teams building custom Keycloak images with themes

Self-hosting & upgradesBlocks work1 source2025-04
Disabling a user leaves their sessions active

Affects: Admins disabling users

Permissions & securityBlocks work1 source2025-03
Deleting a user sends no backchannel logout to clients

Affects: Admins with backchannel logout configured

Permissions & securityBlocks work1 source2025-03
2FA bypass took ten months to be fixed
Permissions & securityBlocks work1 source2024-11
Token exchange drops requested scopes since Keycloak 24

Affects: Developers using token exchange

Reliability & bugsBlocks work1 source2024-05
Admin API user PUT now clears name and email fields

Affects: Developers using the admin API

API & developer experienceBlocks work1 source2024-03
start-dev fails on fresh download with a database exception

Affects: Developers trying Keycloak locally

Setup & onboardingBlocks work1 source2024-01
SAML IdP-initiated login fails with cookie_not_found

Affects: Admins configuring SAML SSO with external IdPs

IntegrationsBlocks work1 source2023-05
No zero-downtime deployment in Keycloak
Self-hosting & upgradesBlocks work1 source2023-05
Cannot install packages in Keycloak container since version 21

Affects: Docker users adding health checks

Self-hosting & upgradesBlocks work1 source2023-02
Default Content Security Policy is too permissive
Permissions & securityBlocks work1 source2023-01
Custom identity providers cannot be configured in new admin console

Affects: Developers writing custom identity providers

CustomizationBlocks work1 source2022-11
New admin console fails to load under some hostname setups

Affects: Admins behind reverse proxies or custom hostnames

Reliability & bugsBlocks work1 source2022-09
External IdP tokens not refreshed when retrieved

Affects: Developers using GitHub apps as external IdP

IntegrationsBlocks work1 source2022-09
Refresh token rotation breaks with multiple browser tabs

Affects: SPA developers

Reliability & bugsBlocks work1 source2022-08
Valid refresh token randomly rejected with 400

Affects: SPA developers using keycloak-js

Reliability & bugsBlocks work1 source2022-08
Impersonation broken when admin hostname differs from realm hostname

Affects: Admins with a separate admin hostname

Reliability & bugsBlocks work1 source2022-03
Authentication flow steps skipped after external IdP login

Affects: Admins with external identity providers

Permissions & securityBlocks work1 source2022-02
Keycloak maintenance hindered by weak documentation
DocumentationBlocks work1 source2020-07
LDAP user rename deletes and recreates the Keycloak account

Affects: Teams using LDAP integration

Reliability & bugsBlocks work1 source2020-04
Keycloak seems overkill for small private deployments

Affects: Small self-hosted deployments

Setup & onboardingAnnoyance1 source2026-02
Keycloak UI and data model add avoidable difficulty
UI & usabilityAnnoyance1 source2025-11
Realm JSON import has unreadable structure and cannot maintain realm
Data export & migrationAnnoyance1 source2023-04
Cannot create users without first and last name

Affects: Operators of game servers and username-only communities

CustomizationAnnoyance1 source2022-05
WebAuthn-first factor ordering still pushes users to a switch-method button
UI & usabilityAnnoyance1 source2022-04

Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.

Feature requests 17

ItemAreaSeveritySupportLast seen
Ability to set order of credential types in auth flows

In an identifier-first flow, the password authenticator always runs before the passwordless WebAuthn one, forcing users to pick another way to use passkeys.

Affects: Admins building passwordless flows

CustomizationBlocks work2 sources2023-12

“there seems to be no way to cancel/deny the passkey option”

“The Password form authenticator is shown after the username form authenticator”

GitOps-style declarative configuration for Keycloak realms

The commenter wants Keycloak to read a config file at startup and create/update/delete resources accordingly, and dislikes the Terraform plugin because of state.

Affects: Teams running Keycloak on Kubernetes

API & developer experienceBlocks work2 sources2023-06

“an official solution for configuration management other than the K8s operator which is missing a lot of features”

“I miss the ability to use some kind of GitOps with Keycloak”

Multiple email domains per linked IdP in organizations

Organizations allow several mail domains, but each linked IdP only one, forcing duplicate IdP configurations for customers with several domains.

Affects: B2B providers with customers using multiple mail domains

IntegrationsBlocks work1 source2024-10

“It would be great to also support multiple mail domains for linked IDPs”

Clone a realm from the admin interface

Partial export and import into a new realm fails on duplicate keys, so an admin needing 25 near-identical realms without command-line access wants a clone function.

Affects: Admins without command-line access managing many similar realms

Data export & migrationBlocks work1 source2023-11

“The ability to clone a realm to a new realm would be a huge time saver”

SMTP OAuth 2.0 authentication for outgoing email

Providers like Microsoft and Google are ending basic SMTP auth, so Keycloak will be unable to send email unless it supports OAuth 2.0.

Affects: Admins using Microsoft or Google mail

IntegrationsBlocks work1 source2023-03

“In the current situation Keycloak will not be able to send e-mail for service providers that disabled SMTP basic authentication”

SCIM support for user provisioning

Affects: Teams integrating identity systems

IntegrationsBlocks work1 source2022-08
Allow customizing CORS Access-Control-Allow-Headers

Affects: Teams using distributed tracing

API & developer experienceBlocks work1 source2022-06
Automatically disable dormant user accounts

Affects: Enterprise security administrators

Permissions & securityBlocks work1 source2022-05
Allow groups to have multiple parent groups

Affects: Teams syncing Active Directory via LDAP

IntegrationsBlocks work1 source2022-04
Restore realm import on startup via environment variable

Affects: Docker Compose users automating setup

Data export & migrationBlocks work1 source2022-02
Built-in metrics for operations teams

Affects: Operations and SRE teams

Reporting & analyticsBlocks work1 source2021-12
Trusted device option to skip 2FA for 30 days

Affects: End users and realm admins

Permissions & securityBlocks work1 source2021-11
Helm chart for the Keycloak operator

Affects: Kubernetes teams using Helm and ArgoCD

Self-hosting & upgradesAnnoyance1 source2025-02
Easier way to build custom login and registration UI
CustomizationAnnoyance1 source2023-06
Read secrets such as DB password from files

Affects: Container and Docker secrets users

Self-hosting & upgradesAnnoyance1 source2022-03
Expose role attributes as OIDC claims without script mapper

Affects: Teams syncing users and groups from an external source

CustomizationAnnoyance1 source2022-02
Support for non-SQL datastores such as DynamoDB

Affects: Teams with a global user base on AWS

Self-hosting & upgradesAnnoyance1 source2020-04

Top 5 shown with evidence. The rest are listed by title; open any item for its evidence.

Workarounds 5

ItemAreaSeveritySupportLast seen
Keycloak behind Apache reverse proxy breaks connections without tuning

Behind a reverse proxy Keycloak connections sometimes break; the user had to add proxy settings disabling pooling and keep-alive to stabilize it.

Affects: Self-hoster using Apache as reverse proxy

Self-hosting & upgradesBlocks work1 source2024-02

“Keycloak is known to be a bit odd in how it sometimes works behind a reverse proxy”

Login state not shared across Keycloak nodes forces sticky sessions

Stateful login on one server was missing on others, so plain load balancing did not work and sticky sessions were the only option.

Affects: Enterprise platform engineer

Self-hosting & upgradesBlocks work1 source2024-02

“Stateful login on one server was missing from the others so dumb load balancing was off the table”

Disabling group inheritance preserves sync but loses AD structure

Turning off Preserve Group Inheritance avoids the LDAP sync failure but loses the whole Active Directory group structure inside Keycloak.

Affects: Teams syncing Active Directory via LDAP

IntegrationsBlocks work1 source2022-04

“Disabling this switch results in losing the whole AD structure within Keycloak”

Long Keycloak startup times unless an optimized image is built

A self-hoster says startup is annoyingly long unless you build the optimized image, which was a pain point until done.

Affects: Self-hoster

Self-hosting & upgradesAnnoyance1 source2024-02

“otherwise the startup times will be annoyingly long”

Customizing CSP requires overriding the whole header

The only way to tune CSP today is to completely override the header, which weakens it across all Keycloak endpoints.

Permissions & securityAnnoyance1 source2023-01

“Currently this is done by completely overriding the header, but this is not great as it results in a less secure CSP header”

Switching reasons 1

ItemAreaSeveritySupportLast seen
Built own auth server after missing Keycloak flow features

The commenter built their own auth server after tiring of Keycloak quirks, including missing common functionality such as accepting terms before profile creation.

Affects: Product developer

CustomizationCauses churn1 source2023-05

“some missing functionality that needs to be implemented very often, like "Accept ToS before profile is created”