Find the risky settings in your Keycloak realms.
realmlint reads a realm export and tells you what is wrong, in plain English, with the fix for each problem. It is free, open source, and runs on your machine. Your exports never leave it.
$ realmlint check acme-realm.json 23 findings in 1 realm: 5 high, 11 medium, 7 low. Realm acme (acme-realm.json) HIGH Redirect URIs use wildcards - client "web-spa": redirect URI "*" allows any destination Fix: In the client's Settings, replace wildcard Valid redirect URIs with the exact callback URLs. HIGH Service account has realm admin rights - service account of client "billing-service" Fix: Remove realm-admin and grant only the realm-management roles it needs. MEDIUM Brute-force protection is off LOW Offline sessions never expire ...
The settings that get inherited Keycloak instances into trouble.
Every finding says what was found, why it matters, and where to fix it in the admin console. Keycloak's own built-in clients are left alone, so you only see what you can act on.
Realm settings
HTTPS not required, brute-force protection off, weak password policy, missing admin events, apps in the master realm.
Tokens and sessions
Long-lived access tokens, login sessions that last for days, offline sessions that never expire.
Clients
Wildcard and plain-HTTP redirect URIs, CORS for any origin, implicit flow, password grant, missing PKCE, full scope.
Admin access
Service accounts with realm-admin, admins without a second factor, a forgotten temporary bootstrap admin.
Keys, certificates, versions
Expiring realm and identity-provider certificates, keys never rotated, unsigned SAML, outdated Keycloak.
Two minutes from install to findings.
1. Install
One binary for Linux, macOS and Windows. The script checks the download against the release checksum.
curl -fsSL https://raw.githubusercontent.com/realmlint/realmlint/main/scripts/install.sh | bash
Or go install, or the Docker image ghcr.io/realmlint/realmlint.
2. Export and check
Export a realm with Keycloak's own tool, then point realmlint at the file or directory.
kc.sh export --realm acme --dir exports/ realmlint check exports/ realmlint diff before.json after.json
3. Keep it checked in CI
The GitHub Action fails the build on new problems and shows findings in the Security tab.
- uses: realmlint/realmlint@v1
with:
paths: keycloak/realms/*.json
fail-on: high
Know when your Keycloak changes, and who changed it.
The CLI checks a snapshot. The hosted version would watch your instances continuously. It is not built yet: join the waitlist to shape it and get early access.
- Drift detection with namesWhat changed since last week, and which admin changed it.
- Alerts in Slack or emailNew risky settings and expiring certificates, routed to the right team.
- Access reviewsA quarterly report of who holds admin rights, ready for SOC 2 and security questionnaires.
- Your secrets stay with youA small open-source agent runs next to Keycloak and strips secrets before anything is sent.