Keycloak Spiffe, sh. By contrast, while SPIRE does generate SPIFFE identities that can be used to authenticate to other systems, SPIRE does not aim to store existing keys (such as a database password) on behalf of a workload. Jul 29, 2025 · Explains how to use SPIFFE and Keycloak for secure, non-anonymous dynamic client registration in MCP authorization, addressing enterprise security concerns. Aug 4, 2025 · In the previous blog, we dug into dynamically registering OAuth clients leveraging SPIFFE and SPIRE. We used SPIRE to issue software statements in the SPIFFE JWT SVID that Keycloak can trust as Nov 17, 2022 · Step By Step Guide To Setup Keycloak Configuration For Tornjak Introduction to Tornjak + IAM Integration Tornjak is an open-source project under the CNCF (Cloud Native Computing Foundation Aug 21, 2025 · Client authentication with SPIFFE Leveraging SPIFFE for authenticating clients helps in reducing the credentials required to manage clients; and can also open the door for a trusted way to automatically register clients. Jul 29, 2025 · Walking through how to do a OAuth client credentials flow and use a SPIFFE JWT SVID to authenticate to the Keycloak IdP Aug 15, 2025 · In Keycloak clients can authenticate via mTLS, but using mTLS is a more complicated setup for SPIFFE/SPIRE and a simpler integration would be via JWT SVID. For Dynamic Client Registration (DCR), we need to implement the ClientRegistrationProviderFactory interface to create a custom DCR endpoint that understands SPIFFE software statements. It allows services with SPIFFE SVIDs (SPIFFE Verifiable Identity Documents) to automatically register as OAuth 2. This can be created by running configure-keycloak. SPIRE’s attestation policies provide a flexible and powerful solution for secure introduction to secrets managers. Jul 29, 2025 · Keycloak is written in Java and has a nice “Service Provider Interface” model for extending many parts of Keycloak. Supporting SPIFFE/SPIRE can be broken down into the following milestones: Contribute to ayatb/keycloak-poc development by creating an account on GitHub. Jul 30, 2025 · Factory Class - Tells Keycloak how to create our provider Provider Class - Implements the actual DCR logic with SPIFFE support Service Registration - Makes Keycloak discover our extension This SPI extends Keycloak's Dynamic Client Registration capabilities to support SPIFFE (Secure Production Identity Framework for Everyone) identities. 0 server. 0 clients without requiring pre-shared secrets or admin intervention. The admin console is exposed to the public and every admin account in the master realm is protected with 2FA. See keycloak/keycloak#41907 Configuring Keycloak The demo requires setting up a realm in Keycloak, with a Kubernetes identity provider, and a client configured to use Kubernetes service accounts for authentication. Configuring Keycloak The demo requires setting up a realm in Keycloak, with a Kubernetes identity provider, and a client configured to use Kubernetes service accounts for authentication. Jan 26, 2026 · SPIFFE Leverage any identity provider supporting SPIFFE APIs for federated client authentication as long as it can issue SPIFFE JWT SVIDs and provides a SPIFFE Bundle Endpoint accessible by Keycloak. This SPI extends Keycloak's Dynamic Client Registration capabilities to support SPIFFE (Secure Production Identity Framework for Everyone) identities. Feb 17, 2026 · Secret-less Authentication with Keycloak and SPIFFE/SPIRE Ayat Bouchouareb Solution Architect | Designing IAM/CIAM and API Security solutions at scale Published Feb 17, 2026 + Follow Jul 29, 2025 · By integrating SPIFFE JWT SVIDs with Keycloak’s client authentication flow, we eliminated the need for static secrets and created a more secure, scalable model for authenticating MCP clients especially in environments where agents and services need short-lived, verifiable credentials. SPIRE (the SPIFFE Runtime Environment) is a toolchain of APIs for establishing trust between software systems across a wide variety of hosting platforms. Jul 29, 2025 · Walk through OAuth dynamic client registration using SPIFFE / SPIRE software statements with Keycloak IdP Dec 21, 2023 · Hey everyone, I am looking for some help with configuring Keycloak to use mTLS with certificates issued by Spire (SPIFFE | Documentation). SPIFFE, the Secure Production Identity Framework For Everyone (SPIFFE) Project defines a framework and set of standards for identifying and securing communications between application services. For more background information, please…. We are now making of use of keycloak-config-cli to manage Dec 8, 2022 · This is a step-by-step guide to integrating Tornjak with Keycloak as an example OAuth2. One important distinction between SPIFFE and other providers is the lack of an iss claim. First some context: We run Keycloak with three instances deployed inside a GKE cluster. cph5we3g, caqvap, gsw, wn1, ghvb, gaz, qw2whjm, hn086n2m, aeittb, udlf,