Configure Authentication
Keycloak provides a flexible authentication framework that supports password policies, multi-factor authentication (MFA), custom authentication flows, and advanced methods such as WebAuthn and X.509 certificates.
TOC
Password PoliciesConfigure Password PoliciesAvailable Password PoliciesOTP PoliciesConfigure OTP PolicyRequire OTP for All UsersAuthentication FlowsBuilt-in FlowsCreate a Custom Authentication FlowBind a Custom FlowWebAuthn / Passwordless AuthenticationEnable WebAuthn as a Second FactorEnable Passwordless LoginConfigure WebAuthn PolicyX.509 Client Certificate AuthenticationEnable X.509 AuthenticationKerberos / SPNEGO AuthenticationEnable Kerberos AuthenticationStep-Up AuthenticationConfigure ACR-to-LoA MappingUser Session LimitsPassword Policies
Password policies enforce credential complexity and lifecycle rules for users within a Realm.
Configure Password Policies
- In the Admin Console, go to Authentication > Policies > Password policy tab.
- Click Add policy and select a policy type from the dropdown.
- Configure the policy parameter and click Save.
Available Password Policies
Password policies are enforced when users set or change their password. Existing users are not retroactively affected unless you add the Update Password required action to enforce a password reset on next login.
OTP Policies
One-Time Password (OTP) provides a second authentication factor. Keycloak supports both TOTP (time-based) and HOTP (counter-based) algorithms.
Configure OTP Policy
- Go to Authentication > Policies > OTP policy tab.
- Configure the following settings:
- Click Save.
Require OTP for All Users
To enforce OTP as a required action for all users:
- Go to Authentication > Required actions.
- Find Configure OTP and enable the Set as default action toggle.
- All users will be prompted to set up OTP on their next login.
Authentication Flows
Authentication Flows define the sequence of steps a user must complete to authenticate. Keycloak includes built-in flows and supports creating custom flows.
Built-in Flows
Create a Custom Authentication Flow
- Go to Authentication > Flows tab.
- Click the menu icon on an existing flow and select Duplicate.
- Enter a name for the custom flow (for example,
Custom Browser Flow). - Modify the flow by adding, removing, or reordering authentication steps:
- Click Add step to insert an authenticator.
- Set each step's Requirement to one of:
Required— must succeed.Alternative— one of the alternative steps must succeed.Conditional— evaluated only if the condition is met.Disabled— skipped.
- Click Save.
Bind a Custom Flow
After creating a custom flow, bind it to a Realm:
- Go to Authentication > Flows tab.
- Select your custom flow.
- Click Action > Bind flow.
- Select the binding type (for example, Browser flow).
- Click Save.
WebAuthn / Passwordless Authentication
Keycloak supports the WebAuthn standard for hardware security keys, platform authenticators (fingerprint, Face ID), and fully passwordless login.
Enable WebAuthn as a Second Factor
- Go to Authentication > Flows tab.
- Duplicate the Browser flow.
- In the duplicated flow, add a WebAuthn Authenticator step after the username/password step.
- Set the WebAuthn step requirement to
RequiredorAlternative. - Bind the custom flow as the Browser flow.
Enable Passwordless Login
- Duplicate the Browser flow.
- Add a WebAuthn Passwordless Authenticator step.
- Set the username form to
Alternativeand the WebAuthn Passwordless step toAlternative. - Bind the custom flow as the Browser flow.
- Go to Authentication > Required actions and enable Webauthn Register Passwordless.
Configure WebAuthn Policy
- Go to Authentication > Policies > WebAuthn policy tab (or WebAuthn Passwordless policy tab).
- Configure:
- Click Save.
X.509 Client Certificate Authentication
Keycloak can authenticate users based on X.509 client certificates presented during TLS handshake.
X.509 authentication requires the TLS termination point (Keycloak Pod or reverse proxy) to be configured to request and pass client certificates. This typically requires configuring mutual TLS (mTLS) at the Ingress controller or load balancer level. The specific configuration depends on your infrastructure setup.
Enable X.509 Authentication
- Duplicate the Browser flow.
- Add an X.509/Validate Username Form step.
- Configure the X.509 authenticator:
- Bind the custom flow as the Browser flow.
Kerberos / SPNEGO Authentication
Keycloak supports Kerberos-based single sign-on via the SPNEGO protocol, allowing users with valid Kerberos tickets to authenticate transparently.
Kerberos authentication requires a functioning Kerberos infrastructure (KDC) and proper DNS/SPN configuration. The Keycloak server must be registered as a service principal in the Kerberos realm. Configuration details depend on your Kerberos environment and are beyond the scope of this guide. Refer to the upstream Keycloak documentation for detailed Kerberos setup instructions.
Enable Kerberos Authentication
- Configure a User Federation provider (LDAP) with Kerberos integration enabled, or configure a standalone Kerberos provider.
- Provide the Kerberos Realm name, Server Principal, and KeyTab file location.
- Keycloak will attempt SPNEGO negotiation during browser login.
Step-Up Authentication
Step-Up Authentication allows you to require additional authentication factors for sensitive operations, using the Authentication Context Class Reference (ACR) mechanism.
Configure ACR-to-LoA Mapping
- Go to Authentication > Flows tab.
- In your browser flow, add Conditional sub-flows with conditions based on the requested Level of Assurance (LoA).
- Go to Realm Settings > General > ACR to LoA Mapping.
- Map ACR values to numeric LoA levels (for example,
acr-loa-1= Level 1,acr-loa-2= Level 2).
Applications can then request specific LoA levels by including the acr_values parameter in the authorization request, and Keycloak will enforce the corresponding authentication steps.
User Session Limits
To limit the number of concurrent sessions per user:
- Duplicate the Browser flow.
- Add a User session count limiter step.
- Configure the maximum number of sessions per user.
- Set the behavior when the limit is reached: deny the new login or terminate the oldest session.
- Bind the custom flow as the Browser flow.