Keycloak · Identity provider
Sign in to Casdoor with Keycloak
Already run Keycloak? Add it to Casdoor as an OpenID Connect provider and people sign in to your Casdoor applications with their Keycloak accounts, while Casdoor handles the rest: other social logins, MFA, applications and permissions.
https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.Set up Keycloak with Casdoor
- 1
Create a client in Keycloak
In the Keycloak admin console, switch to the
myrealmrealm, open Clients and click Create client. Choose OpenID Connect as the client type, enter a client ID such ascasdoor, and click Next. - 2
Turn on client authentication
Turn Client authentication on and keep Standard flow enabled, click Next, and fill in the login settings:
Valid redirect URIs https://auth.example.com/callback - 3
Copy the client secret
Save the client, open its Credentials tab and copy the Client secret. The client ID is the one you entered.
- 4
Add Keycloak as a provider in Casdoor
In the Casdoor console, open Providers, click Add, and fill in:
Category OAuth Type OIDC Display name Keycloak Client ID <client ID> Client secret <client secret> Issuer URL https://keycloak.example.com/realms/myrealm Auth URL https://keycloak.example.com/realms/myrealm/protocol/openid-connect/auth Token URL https://keycloak.example.com/realms/myrealm/protocol/openid-connect/token Scope openid profile email UserInfo URL https://keycloak.example.com/realms/myrealm/protocol/openid-connect/userinfo Logout URL https://keycloak.example.com/realms/myrealm/protocol/openid-connect/logout Enable PKCE On Request next to Issuer URL fills in the other URLs from Keycloak's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.
- 5
Add the provider to an application
Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a Keycloak button.
Good to know
- Keycloak matches redirect URIs exactly, so enter the Casdoor address people actually use, and avoid wildcards.
- Casdoor links each account to the Keycloak user ID (
sub), so renaming a user in Keycloak doesn't create a second Casdoor account.
Keycloak settings are from its documentation as of October 2026 (Keycloak OpenID Connect endpoints, Keycloak getting started). Keycloak is a trademark of its owner.
Frequently asked questions
My Keycloak URLs have /auth in them. Does this still work?
Yes. Keycloak 16 and older put /auth in front of every path; include it in the Keycloak URL, for example https://keycloak.example.com/auth.
Can I use SAML instead?
Casdoor also has a Keycloak SAML provider. OpenID Connect needs less setup on both sides, which is why this template uses it.
More identity providers
View allAuthelia
Identity providerLet people sign in to Casdoor through Authelia over OpenID Connect: the provider settings, and the client to add to Authelia's configuration.
authentik
Identity providerLet people sign in to Casdoor with their authentik accounts over OpenID Connect: the provider settings, and the application and OAuth2 provider to create in authentik.
GitLab Self-Managed
Identity providerLet people sign in to Casdoor with accounts on your own GitLab over OpenID Connect: the provider settings, and the OAuth application to create in GitLab.
