Prowl
66/100
prowl
Benchmarked Sep 19, 2026

Keycloak Admin REST API

This is a REST API reference for the Keycloak Admin

api platform_profile
Benchmark Your API

Score Breakdown

Parseability9/10
Latency8/10
Documentation8/10
Token Efficiency8/10
Consistency7/10
Error Clarity6/10
Auth Simplicity4/10
First-Try Success3/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
{
  "service_type": "platform",
  "base_url": "https://keycloak.local",
  "auth_method": "oauth2",
  "auth_config": {
    "description": "Keycloak Admin REST API uses OAuth 2.0 / OpenID Connect. Typically authenticated with an access token obtained from the Keycloak token endpoint using the client credentials grant or password grant with an admin user.",
    "token_endpoint": "https://keycloak.local/realms/{realm}/protocol/openid-connect/token",
    "grants": ["client_credentials", "password", "authorization_code"],
    "header": "Authorization: Bearer <access_token>"
  },
  "endpoints": [
    {
      "path": "/admin/realms/{realm}/users",
      "method": "GET",
      "description": "List or search users in a realm"
    },
    {
      "path": "/admin/realms/{realm}/users",
      "method": "POST",
      "description": "Create a new user"
    },
    {
      "path": "/admin/realms/{realm}/users/{id}",
      "method": "GET",
      "description": "Get a specific user"
    },
    {
      "path": "/admin/realms/{realm}/users/{id}",
      "method": "PUT",
      "description": "Update a user"
    },
    {
      "path": "/admin/realms/{realm}/users/{id}",
      "method": "DELETE",
      "description": "Delete a user"
    },
    {
      "path": "/admin/realms/{realm}/clients",
      "method": "GET",
      "description": "List clients in a realm"
    },
    {
      "path": "/admin/realms/{realm}/groups",
      "method": "GET",
      "description": "List groups in a realm"
    },
    {
      "path": "/admin/realms/{realm}/roles",
      "method": "GET",
      "description": "List roles in a realm"
    },
    {
      "path": "/admin/realms",
      "method": "GET",
      "description": "List all realms"
    },
    {
      "path": "/admin/realms",
      "method": "POST",
      "description": "Create a new realm"
    },
    {
      "path": "/admin/realms/{realm}/identity-provider/instances",
      "method": "GET",
      "description": "List identity providers configured in a realm"
    },
    {
      "path": "/admin/realms/{realm}/sessions",
      "method": "GET",
      "description": "List active user sessions in a realm"
    }
  ],
  "pricing_model": {
    "type": "free",
    "details": {
      "note": "Keycloak is an open-source identity and access management solution. The software itself is free under Apache License 2.0. Costs may apply for hosting, support, or managed offerings (e.g., Red Hat build of Keycloak / RH-SSO)."
    }
  },
  "rate_limits": {
    "note": "No built-in public rate limits are documented for the Admin REST API itself. Rate limiting depends on deployment/proxy configuration. Admin API operations can be resource-intensive."
  },
  "capabilities": [
    "Identity and Access Management (IAM)",
    "Single Sign-On (SSO) via OpenID Connect and SAML 2.0",
    "User federation (LDAP, Active Directory, custom providers)",
    "User and group management",
    "Role-based access control (RBAC)",
    "Fine-grained authorization services",
    "Client registration and management",
    "Identity brokering (social login, external IdPs)",
    "Multi-realm support (multi-tenancy)",
    "Authentication flows and required actions",
    "Session management and token revocation",
    "Admin REST API for programmatic management"
  ],
  "raw_analysis": "Keycloak is a mature, widely adopted open-source Identity and Access Management (IAM) platform, originally developed by Red Hat / JBoss. It provides SSO, identity brokering, user federation, and fine-grained authorization for applications and services.\n\nThis entry refers specifically to the Keycloak Admin REST API, a comprehensive HTTP API used to administer a Keycloak server. It is a genuine REST API (not merely a dashboard), though the base URL in this record (https://keycloak.local) is a placeholder/local instance rather than a hosted public service — meaning the actual API is self-hosted by the user deploying Keycloak.\n\nThe Admin REST API mirrors nearly all administrative console functionality: managing realms, users, groups, roles, clients, identity providers, sessions, authentication flows, and more. It is organized under the /admin/realms/{realm}/... path structure.\n\nAuthentication is via OAuth 2.0 / OpenID Connect. Callers obtain an access token (often with the master realm admin credentials using the password grant, or via client credentials with a service account that has admin roles) and include it as a Bearer token. The relevant role is typically 'admin' from the 'realm-management' client or master admin roles.\n\nMaturity: very high — Keycloak has been in development for over a decade, with broad enterprise adoption and a large ecosystem. It is backed by Red Hat and has managed offerings.\n\nTarget users: developers, DevOps/identity engineers, and administrators of applications needing authentication/authorization, as well as organizations implementing SSO and identity federation.\n\nIntegrations: Keycloak integrates with OIDC/SAML identity providers, L
Execute

0/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /None103ms
robots_txtGET /robots.txtNone86ms
llms_txtGET /llms.txtNone102ms
Interpret
{
  "overall": 62,
  "dimensions": {
    "token_efficiency": 8.0,
    "first_try_success": 3.0,
    "response_parseability": 9.0,
    "error_clarity": 6.0,
    "doc_quality": 8.0,
    "auth_simplicity": 4.0,
    "latency": 8.0,
    "consistency": 7.0
  },
  "pricing_normalized": {
    "model": "free_open_source",
    "license": "Apache 2.0",
    "note": "Keycloak software is free; costs may apply for hosting, managed offerings, or enterprise support (Red Hat build of Keycloak / RH-SSO)",
    "agent_recommendation_angle": "Zero licensing cost makes it easy to recommend, but TCO includes self-hosting ops burden"
  },
  "issues": [
    "DNS resolution failed for all three checks (website, robots.txt, llms.txt) — the probed host is not resolving, so no uptime/security-header/latency signal could be validated",
    "Latency readings (86–103ms) are pre-resolution failures, not real response times — misleading if surfaced to users",
    "Self-hosted/self-managed model means 'first try success' depends on the user's own Docker/K8s/DB setup, not a simple sign-up flow",
    "No llms.txt or agent-oriented documentation surface detected, limiting agent discoverability",
    "Auth setup for agents requires registering a client, configuring realms, flows, and scopes — non-trivial multi-step onboarding",
    "pricing_model is unstructured free-text rather than a normalized schema"
  ],
  "recommendations": [
    "Verify the correct canonical hostname and re-run uptime/robots/llms checks — current DNS failures invalidate the latency and uptime dimensions",
    "Publish an llms.txt pointing agents to the Admin REST API, OIDC discovery doc (/realms/{realm}/.well-known/openid-configuration), and quickstart guide",
    "Provide a single-container 'try Keycloak' quickstart with pre-seeded realm/client so agents can onboard in one step",
    "Document a machine-friendly client-credentials quickstart (create client → get token → call admin API) in 3 copy-pasteable steps",
    "Normalize pricing metadata into a structured schema (free / paid-managed / enterprise-support tiers) for downstream parsing",
    "Expose a status page URL and reference it in docs to strengthen the consistency signal",
    "Clarify in docs the auth requirements and rate limits of the Admin API to improve error_clarity"
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
No
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/keycloak-admin-rest-api">
  <img src="https://prowl.world/badge/keycloak-admin-rest-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard