Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Usage Milestone: Time Field for Drupal 8+ Module time_field crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Keycloak OpenID Connect

4,762 sites Security covered Drupal 10–11 Keycloak ecosystem
View on drupal.org

This module allows your Drupal users to log in using Keycloak, an open-source identity and access management system. It synchronizes user information between Drupal and Keycloak, supporting multi-language configurations for a seamless user experience.

The Keycloak module provides a Keycloak login provider client for the OpenID Connect module.

What does the module do?

The module allows you to authenticate your users against a Keycloak authentication server.

Keycloak is an Open Source Identity and Access Management system that supports OpenID Connect, OAuth 2.0 and SAML 2.0 login, LDAP and Active Directory user federation, OpenID Connect or SAML 2.0 identity brokering and various Social Logins out of the box.

Features

  • Login to Drupal using Keycloak OpenID Connect.
  • Synchronize user fields with OpenID attributes provided by Keycloak using the OpenID Connect module's claim mapping.
  • Additionally synchronize email address changes from within Keycloak with the connected Drupal user's email address.
  • Multi-language support:
    • Forward language parameters to Keycloak, so the login/user registration of Keycloak opens up in the same language as your multi-language Drupal site.
    • Map Keycloak's user locale settings to Drupal languages.

Version differences

8.x-1.x version

NEW: Added Drupal 10 support!

Integrates with OpenID Connect 2.x

2.2.x version

Drupal 10 version. Only supports OpenID Connect 3.x

The 2.x version contains a breaking change. Please check #3251827: Role mappping uses "user_data" instead of "userinfo" before upgrading to the 2.x version.

2.x Roadmap

Dependencies

Similar Projects

Keycloak supports OpenID Connect, OAuth2 and SAML standards for authentication clients. You might wish to also have a look to the following contributed modules to authenticate your Drupal users with Keycloak:

  • SAML Authentication
    This module features SAML-based user authentication. User attributes mapping is in development.
  • simpleSAMLphp Authentication
    This module requires a working setup of SimpleSAMLphp as service provider on your webserver to connect to the Keycloak Identity Provider. It features SAML-based authentication and user role provisioning.
  • OAuth2 Client
    A basic OAuth2.0 client for Drupal that can be extended programmatically.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
6
Tracked since
Jan 2025
Latest release
9 months ago
Releases (12 mo)
2 ▼ from 4
Maintenance
Slowing

Release Timeline

Releases

Version Type Core Release date
2.2.3-rc1 Pre-release 10–11 Nov 28, 2025
2.2.2 Stable 10–11 Nov 19, 2025
2.2.1 Stable 10–11 Jan 29, 2025
2.2.1-rc1 Pre-release 8–10 Jan 19, 2025
2.2.0 Stable 8–10 Jan 13, 2025
2.2.0-beta13 Pre-release 8–10 Jan 13, 2025