realmlint
For teams running Keycloak

Find the risky settings in your Keycloak realms.

realmlint reads a realm export and tells you what is wrong, in plain English, with the fix for each problem. It is free, open source, and runs on your machine. Your exports never leave it.

24 checks No telemetry Apache 2.0
What it checks

The settings that get inherited Keycloak instances into trouble.

Every finding says what was found, why it matters, and where to fix it in the admin console. Keycloak's own built-in clients are left alone, so you only see what you can act on.

6 checks

Realm settings

HTTPS not required, brute-force protection off, weak password policy, missing admin events, apps in the master realm.

3 checks

Tokens and sessions

Long-lived access tokens, login sessions that last for days, offline sessions that never expire.

7 checks

Clients

Wildcard and plain-HTTP redirect URIs, CORS for any origin, implicit flow, password grant, missing PKCE, full scope.

3 checks

Admin access

Service accounts with realm-admin, admins without a second factor, a forgotten temporary bootstrap admin.

5 checks

Keys, certificates, versions

Expiring realm and identity-provider certificates, keys never rotated, unsigned SAML, outdated Keycloak.

See the full check catalog

Use it

Two minutes from install to findings.

1. Install

One binary for Linux, macOS and Windows. The script checks the download against the release checksum.

curl -fsSL https://raw.githubusercontent.com/realmlint/realmlint/main/scripts/install.sh | bash

Or go install, or the Docker image ghcr.io/realmlint/realmlint.

2. Export and check

Export a realm with Keycloak's own tool, then point realmlint at the file or directory.

kc.sh export --realm acme --dir exports/
realmlint check exports/
realmlint diff before.json after.json

3. Keep it checked in CI

The GitHub Action fails the build on new problems and shows findings in the Security tab.

- uses: realmlint/realmlint@v1
  with:
    paths: keycloak/realms/*.json
    fail-on: high
Hosted realmlint · planned

Know when your Keycloak changes, and who changed it.

The CLI checks a snapshot. The hosted version would watch your instances continuously. It is not built yet: join the waitlist to shape it and get early access.

  • Drift detection with namesWhat changed since last week, and which admin changed it.
  • Alerts in Slack or emailNew risky settings and expiring certificates, routed to the right team.
  • Access reviewsA quarterly report of who holds admin rights, ready for SOC 2 and security questionnaires.
  • Your secrets stay with youA small open-source agent runs next to Keycloak and strips secrets before anything is sent.