PluginBench
MCP Server
Active
MIT

Keycloak Admin MCP Server

io.github.mrz1880/mcp-keycloak-admin

What is the Keycloak Admin MCP server?

Administer Keycloak via its Admin REST API: users, roles, clients, groups, IdP, events.

How to install Keycloak Admin

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • KEYCLOAK_BASE_URL
    required

    Base URL of the Keycloak server (no trailing slash).

  • KEYCLOAK_REALM
    required

    Realm the server operates on.

  • AUTH_MODE
    required

    Authentication mode: service_account or password.

  • KC_CLIENT_ID

    Confidential client id (service_account mode).

  • KC_CLIENT_SECRET
    secret

    Client secret (service_account mode).

  • KC_ADMIN_USERNAME

    Admin username (password mode).

  • KC_ADMIN_PASSWORD
    secret

    Admin password (password mode).

  • KC_ADMIN_REALM

    Realm holding the admin user (password mode; default master).

  • READ_ONLY

    When true, write and destructive tools are not registered.

  • ALLOWED_REALMS

    Comma-separated allow-list of realms the server may operate on.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "mcp-keycloak-admin": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-keycloak-admin"
      ],
      "env": {
        "KEYCLOAK_BASE_URL": "<YOUR_KEYCLOAK_BASE_URL>",
        "KEYCLOAK_REALM": "<YOUR_KEYCLOAK_REALM>",
        "AUTH_MODE": "<YOUR_AUTH_MODE>",
        "KC_CLIENT_ID": "<YOUR_KC_CLIENT_ID>",
        "KC_CLIENT_SECRET": "<YOUR_KC_CLIENT_SECRET>",
        "KC_ADMIN_USERNAME": "<YOUR_KC_ADMIN_USERNAME>",
        "KC_ADMIN_PASSWORD": "<YOUR_KC_ADMIN_PASSWORD>",
        "KC_ADMIN_REALM": "<YOUR_KC_ADMIN_REALM>",
        "READ_ONLY": "<YOUR_READ_ONLY>",
        "ALLOWED_REALMS": "<YOUR_ALLOWED_REALMS>"
      }
    }
  }
}

Related MCP servers

JSJsonFabrica logo

Generate realistic, relational synthetic JSON test data from templates, via the JsonFabrica API.

0
TypeScript
MIT
View repository →
DEDesignScan logo

DesignScan

Maintained

Extract a website’s design tokens (colors, type, spacing, shadows) as DESIGN.md, W3C, or CSS.

1
TypeScript
MIT
View repository →
AGagent-bom logo

agent-bom

Active

Security scanner and control plane for AI agents, MCP servers, and cloud infrastructure—discover vulnerabilities and trace blast radius.

29
Python
Apache-2.0
View repository →

Scan any public site for AI-agent visibility; get scored findings, a machine-readable fix pack, and

View repository →

Local Talkform schemas, bundled interview templates, and config validation for AI agents.

0
TypeScript
View repository →

RFC 9110 x402 Solana compliance screening and micropayments gateway for AI agents.

0
Java
Apache-2.0
View repository →