CasdoorMarketplace
Submit

Keycloak · Identity provider

Sign in to Casdoor with Keycloak

Already run Keycloak? Add it to Casdoor as an OpenID Connect provider and people sign in to your Casdoor applications with their Keycloak accounts, while Casdoor handles the rest: other social logins, MFA, applications and permissions.

Verified by CasdoorOIDCPKCESelf-hosted
You need a running Casdoor, self-hosted or on Casdoor Cloud. In the examples, replace https://auth.example.com with your Casdoor address (on Casdoor Cloud, something like https://acme.casdoor.com) and the other example.com addresses with your own.

Set up Keycloak with Casdoor

  1. 1

    Create a client in Keycloak

    In the Keycloak admin console, switch to the myrealm realm, open Clients and click Create client. Choose OpenID Connect as the client type, enter a client ID such as casdoor, and click Next.

  2. 2

    Turn on client authentication

    Turn Client authentication on and keep Standard flow enabled, click Next, and fill in the login settings:

    Valid redirect URIshttps://auth.example.com/callback
  3. 3

    Copy the client secret

    Save the client, open its Credentials tab and copy the Client secret. The client ID is the one you entered.

  4. 4

    Add Keycloak as a provider in Casdoor

    In the Casdoor console, open Providers, click Add, and fill in:

    CategoryOAuth
    TypeOIDC
    Display nameKeycloak
    Client ID<client ID>
    Client secret<client secret>
    Issuer URLhttps://keycloak.example.com/realms/myrealm
    Auth URLhttps://keycloak.example.com/realms/myrealm/protocol/openid-connect/auth
    Token URLhttps://keycloak.example.com/realms/myrealm/protocol/openid-connect/token
    Scopeopenid profile email
    UserInfo URLhttps://keycloak.example.com/realms/myrealm/protocol/openid-connect/userinfo
    Logout URLhttps://keycloak.example.com/realms/myrealm/protocol/openid-connect/logout
    Enable PKCEOn

    Request next to Issuer URL fills in the other URLs from Keycloak's discovery document. Casdoor links users of every OIDC-type provider in an organization through the same field, so if the organization already has one, set Type to Custom Flexible instead, which links accounts per provider.

  5. 5

    Add the provider to an application

    Open Applications, edit the application people sign in to, and add the provider on its Providers tab. Its sign-in page now has a Keycloak button.

Good to know

  • Keycloak matches redirect URIs exactly, so enter the Casdoor address people actually use, and avoid wildcards.
  • Casdoor links each account to the Keycloak user ID (sub), so renaming a user in Keycloak doesn't create a second Casdoor account.

Keycloak settings are from its documentation as of October 2026 (Keycloak OpenID Connect endpoints, Keycloak getting started). Keycloak is a trademark of its owner.

Frequently asked questions

My Keycloak URLs have /auth in them. Does this still work?

Yes. Keycloak 16 and older put /auth in front of every path; include it in the Keycloak URL, for example https://keycloak.example.com/auth.

Can I use SAML instead?

Casdoor also has a Keycloak SAML provider. OpenID Connect needs less setup on both sides, which is why this template uses it.