This is a REST API reference for the Keycloak Admin
Full LLM thinking from the 4-phase benchmark pipeline.
{
"service_type": "platform",
"base_url": "https://keycloak.local",
"auth_method": "oauth2",
"auth_config": {
"description": "Keycloak Admin REST API uses OAuth 2.0 / OpenID Connect. Typically authenticated with an access token obtained from the Keycloak token endpoint using the client credentials grant or password grant with an admin user.",
"token_endpoint": "https://keycloak.local/realms/{realm}/protocol/openid-connect/token",
"grants": ["client_credentials", "password", "authorization_code"],
"header": "Authorization: Bearer <access_token>"
},
"endpoints": [
{
"path": "/admin/realms/{realm}/users",
"method": "GET",
"description": "List or search users in a realm"
},
{
"path": "/admin/realms/{realm}/users",
"method": "POST",
"description": "Create a new user"
},
{
"path": "/admin/realms/{realm}/users/{id}",
"method": "GET",
"description": "Get a specific user"
},
{
"path": "/admin/realms/{realm}/users/{id}",
"method": "PUT",
"description": "Update a user"
},
{
"path": "/admin/realms/{realm}/users/{id}",
"method": "DELETE",
"description": "Delete a user"
},
{
"path": "/admin/realms/{realm}/clients",
"method": "GET",
"description": "List clients in a realm"
},
{
"path": "/admin/realms/{realm}/groups",
"method": "GET",
"description": "List groups in a realm"
},
{
"path": "/admin/realms/{realm}/roles",
"method": "GET",
"description": "List roles in a realm"
},
{
"path": "/admin/realms",
"method": "GET",
"description": "List all realms"
},
{
"path": "/admin/realms",
"method": "POST",
"description": "Create a new realm"
},
{
"path": "/admin/realms/{realm}/identity-provider/instances",
"method": "GET",
"description": "List identity providers configured in a realm"
},
{
"path": "/admin/realms/{realm}/sessions",
"method": "GET",
"description": "List active user sessions in a realm"
}
],
"pricing_model": {
"type": "free",
"details": {
"note": "Keycloak is an open-source identity and access management solution. The software itself is free under Apache License 2.0. Costs may apply for hosting, support, or managed offerings (e.g., Red Hat build of Keycloak / RH-SSO)."
}
},
"rate_limits": {
"note": "No built-in public rate limits are documented for the Admin REST API itself. Rate limiting depends on deployment/proxy configuration. Admin API operations can be resource-intensive."
},
"capabilities": [
"Identity and Access Management (IAM)",
"Single Sign-On (SSO) via OpenID Connect and SAML 2.0",
"User federation (LDAP, Active Directory, custom providers)",
"User and group management",
"Role-based access control (RBAC)",
"Fine-grained authorization services",
"Client registration and management",
"Identity brokering (social login, external IdPs)",
"Multi-realm support (multi-tenancy)",
"Authentication flows and required actions",
"Session management and token revocation",
"Admin REST API for programmatic management"
],
"raw_analysis": "Keycloak is a mature, widely adopted open-source Identity and Access Management (IAM) platform, originally developed by Red Hat / JBoss. It provides SSO, identity brokering, user federation, and fine-grained authorization for applications and services.\n\nThis entry refers specifically to the Keycloak Admin REST API, a comprehensive HTTP API used to administer a Keycloak server. It is a genuine REST API (not merely a dashboard), though the base URL in this record (https://keycloak.local) is a placeholder/local instance rather than a hosted public service — meaning the actual API is self-hosted by the user deploying Keycloak.\n\nThe Admin REST API mirrors nearly all administrative console functionality: managing realms, users, groups, roles, clients, identity providers, sessions, authentication flows, and more. It is organized under the /admin/realms/{realm}/... path structure.\n\nAuthentication is via OAuth 2.0 / OpenID Connect. Callers obtain an access token (often with the master realm admin credentials using the password grant, or via client credentials with a service account that has admin roles) and include it as a Bearer token. The relevant role is typically 'admin' from the 'realm-management' client or master admin roles.\n\nMaturity: very high — Keycloak has been in development for over a decade, with broad enterprise adoption and a large ecosystem. It is backed by Red Hat and has managed offerings.\n\nTarget users: developers, DevOps/identity engineers, and administrators of applications needing authentication/authorization, as well as organizations implementing SSO and identity federation.\n\nIntegrations: Keycloak integrates with OIDC/SAML identity providers, L0/3 tests passed
| Test | Endpoint | Status | Latency |
|---|---|---|---|
| website_uptime | GET / | None | 103ms |
| robots_txt | GET /robots.txt | None | 86ms |
| llms_txt | GET /llms.txt | None | 102ms |
{
"overall": 62,
"dimensions": {
"token_efficiency": 8.0,
"first_try_success": 3.0,
"response_parseability": 9.0,
"error_clarity": 6.0,
"doc_quality": 8.0,
"auth_simplicity": 4.0,
"latency": 8.0,
"consistency": 7.0
},
"pricing_normalized": {
"model": "free_open_source",
"license": "Apache 2.0",
"note": "Keycloak software is free; costs may apply for hosting, managed offerings, or enterprise support (Red Hat build of Keycloak / RH-SSO)",
"agent_recommendation_angle": "Zero licensing cost makes it easy to recommend, but TCO includes self-hosting ops burden"
},
"issues": [
"DNS resolution failed for all three checks (website, robots.txt, llms.txt) — the probed host is not resolving, so no uptime/security-header/latency signal could be validated",
"Latency readings (86–103ms) are pre-resolution failures, not real response times — misleading if surfaced to users",
"Self-hosted/self-managed model means 'first try success' depends on the user's own Docker/K8s/DB setup, not a simple sign-up flow",
"No llms.txt or agent-oriented documentation surface detected, limiting agent discoverability",
"Auth setup for agents requires registering a client, configuring realms, flows, and scopes — non-trivial multi-step onboarding",
"pricing_model is unstructured free-text rather than a normalized schema"
],
"recommendations": [
"Verify the correct canonical hostname and re-run uptime/robots/llms checks — current DNS failures invalidate the latency and uptime dimensions",
"Publish an llms.txt pointing agents to the Admin REST API, OIDC discovery doc (/realms/{realm}/.well-known/openid-configuration), and quickstart guide",
"Provide a single-container 'try Keycloak' quickstart with pre-seeded realm/client so agents can onboard in one step",
"Document a machine-friendly client-credentials quickstart (create client → get token → call admin API) in 3 copy-pasteable steps",
"Normalize pricing metadata into a structured schema (free / paid-managed / enterprise-support tiers) for downstream parsing",
"Expose a status page URL and reference it in docs to strengthen the consistency signal",
"Clarify in docs the auth requirements and rate limits of the Admin API to improve error_clarity"
]
}Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.
<a href="https://prowl.world/service/keycloak-admin-rest-api">
<img src="https://prowl.world/badge/keycloak-admin-rest-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>
See operational metrics, LLM evaluations, agent readiness, and more.
Open in Dashboard