Import and Export
Keycloak supports importing and exporting Realm configurations for backup, migration, and environment replication purposes.
TOC
Export MethodsExport via Admin Console (Partial Export)Export via CLI (Full Export)Export via REST APIImport MethodsImport via KeycloakRealmImport CRD (Recommended for Initial Setup)Import via CLI (Startup Import)Import via Admin ConsoleMigration Between EnvironmentsExport Methods
Export via Admin Console (Partial Export)
- In the Admin Console, select the target Realm.
- Go to Realm Settings > Action menu (top right) > Partial export.
- Select what to include:
- Groups and related roles
- Clients
- Roles
- Click Export.
- A JSON file is downloaded containing the selected Realm configuration.
Partial export does not include user data, secrets, or credentials. It exports only the structural configuration (clients, roles, groups, authentication flows, etc.).
Export via CLI (Full Export)
For a full export including users and credentials, use the Keycloak CLI export command. In a Kubernetes environment, run this as a Job or exec into a Pod:
Export options:
The Keycloak CLI export command requires the server to be stopped or run in a special export mode. In Kubernetes, this is best done as a one-off Job or by scaling down the deployment, running the export, and scaling back up. Alternatively, use the Admin REST API for live exports.
Export via REST API
Use the Admin REST API for live, non-disruptive partial exports:
Import Methods
Import via KeycloakRealmImport CRD (Recommended for Initial Setup)
The KeycloakRealmImport CRD is the preferred method for initial Realm provisioning in Kubernetes deployments. See Manage Realms for details.
The KeycloakRealmImport CRD performs a one-time import when the resource is created. It is not a continuous synchronization controller — subsequent changes made via the Admin Console or REST API are not reflected back to the CR, and updating the CR does not automatically re-apply changes to an existing Realm.
Specifically:
- It creates a new Realm at import time. If a Realm with the same name already exists, the import will not overwrite or update the existing Realm.
- It does not track or reconcile ongoing Realm state.
- Modifying the CR after the initial import does not trigger a re-import automatically.
- It does not delete Realms or Realm objects — it is a create-only mechanism.
- It should not be relied upon as a full lifecycle management or GitOps sync mechanism.
For ongoing Realm configuration changes after initial import, use the Admin Console or Admin REST API.
Import via CLI (Startup Import)
Place export files in a directory and configure Keycloak to import on startup:
Import via Admin Console
- Go to Create Realm (top-left dropdown > Create Realm).
- Click Browse and select a realm export JSON file.
- Click Create.
This method creates a new realm from the JSON file. It does not merge into existing realms.
Migration Between Environments
To replicate a Keycloak configuration from one environment to another:
- Export the realm from the source environment (using partial export or REST API).
- Review and sanitize the export:
- Remove environment-specific URLs and hostnames.
- Remove or replace client secrets (use
KeycloakRealmImportplaceholders for secrets). - Update redirect URIs to match the target environment.
- Import into the target environment using the
KeycloakRealmImportCRD.
For migration from Red Hat Single Sign-On, see Migrate from RH-SSO.