Invite users before they have an account. Roles, tenants and validity period are defined with the invitation – onboarding runs automatically.
Multi-tenancy within a realm. Each tenant gets its own attributes, roles and contexts – ideal for SaaS, B2B and enterprise structures.
Self-service portal for delegated administrators. Partner admins manage their users, roles and settings in a dedicated interface.
Quotas and limits per tenant or user group. The extension checks licenses in the login flow and automatically blocks when limits are exceeded.
Users choose their preferred MFA method during login – TOTP, SMS or passkey.
Connects existing SMS services to Keycloak. Central management of templates and failover gateways.
Two-factor authentication via SMS. The user receives a one-time password and enters it during login – without installing an app.
Feature flags in the token – enable or block functions without deployment.
Extracts structured attributes from complex LDAP fields using regular expressions.
Generates OpenAPI specifications for your Keycloak extensions with an interactive UI.
