Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Easy Breadcrumb 2.0.11 — Minor update available for module easy_breadcrumb (2.0.11). Release: Bootstrap 8.x-3.42 — Minor update available for theme bootstrap (8.x-3.42). Release: Editoria11y Accessibility Checker 3.0.10 — Minor update available for module editoria11y (3.0.10). Release: Editoria11y Accessibility Checker 2.2.24 — Minor update available for module editoria11y (2.2.24). Release: Leaflet 10.4.13 — Minor update available for module leaflet (10.4.13). Release: Flag 5.1.1 — Minor update available for module flag (5.1.1). Release: MCP Sentinel 2.33.0 — Minor update available for module mcp_sentinel (2.33.0). Module Revived: Bootstrap 8.x-3.41 — Theme bootstrap updated after 6 months of inactivity (8.x-3.41). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

Keycloak Registration

15 sites No security coverage Drupal 10–11

Part of the Keycloak ecosystem · 4 projects

View on drupal.org

This module enhances the Keycloak User Sync module by automatically sending account setup emails to new Drupal users. It also synchronizes user's first and last names, manages their group memberships in Keycloak, and sets their language locale.

Keycloak Registration is a companion module to Keycloak User Sync. It fills three gaps that Keycloak User Sync cannot cover through its own configuration, so that a user created in Drupal is fully provisioned in Keycloak — with their real name, their group memberships, and the account-setup email that actually lets them log in.

The two modules are designed to work together: Keycloak User Sync creates, updates, and deletes the Keycloak user and its flat attributes; Keycloak Registration layers the remaining provisioning on top.

Features

  • First/last name sync — reads a compound Name field (its given/family columns) from a configurable source entity (e.g. a Profile, or the user itself) and pushes it to Keycloak firstName/lastName. Keycloak User Sync can only map flat field values.
  • Group membership sync — maps a user field holding Keycloak group names to the user's top-level Keycloak group memberships (nested group trees are searched). Optionally removes memberships not present in the field, or leaves groups managed directly in Keycloak untouched.
  • Account-setup ("welcome") email — triggers Keycloak's execute-actions-email, so a newly created user actually receives the "set password / verify email" message. Keycloak User Sync only sets required actions; it never asks Keycloak to send the email. Sent exactly once per user, with a configurable minimum delay and cron-based retries.
  • Locale sync — sets the Keycloak user's locale from the Drupal account language, so the email and its action link render in the user's language.

Requirements

  • Keycloak User Sync, installed and configured (this module reuses its connection and service-account credentials from settings.php).
  • The Keycloak service-account client needs the realm-management roles manage-users, view-users, query-users, and query-groups.
  • Keycloak realm SMTP must be configured to deliver the account-setup email.
  • Optional: the Name module for the first/last name sync feature.

Installation

  1. Install as you would normally install a contributed Drupal module: composer require drupal/keycloak_registration.
  2. Enable the module. It sets its own module weight to 10 so its hooks run after Keycloak User Sync's — the Keycloak user must already exist when this module looks it up.

Configuration

Configure the module at Administration » People » Keycloak Registration (/admin/people/keycloak-registration): enable the account-setup email and the group/name sync features, and point them at your field machine names. The Keycloak connection itself comes from Keycloak User Sync's settings:

$settings['keycloak_user_sync.connection'] = [
  'url'   => 'https://keycloak.example.com',
  'realm' => 'your-realm',
];
$settings['keycloak_user_sync.credentials'] = [
  'client_id'     => 'drupal-sync',
  'client_secret' => '…',
];

Use cases

  • Editorial or HR workflows where accounts are created in Drupal and users must receive a Keycloak "set your password / verify your email" message automatically.
  • Sites storing structured names in a compound Name field (e.g. on a Profile) that should appear as first/last name in Keycloak and downstream SSO clients.
  • Managing Keycloak group memberships from Drupal user data — additively, or authoritatively with removal of unmanaged memberships.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
7
Tracked since
Aug 2026
Latest release
5 days ago
Releases (12 mo)
7 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
1.3.2 Stable 10–11 Oct 2, 2026
1.3.1 Stable 10–11 Oct 2, 2026
1.3.0 Stable 10–11 Oct 2, 2026
1.2.5 Stable 10–11 Aug 20, 2026
1.2.0 Stable 10–11 Aug 19, 2026
1.1.0 Stable 10–11 Aug 19, 2026
1.0.0 Stable 10–11 Aug 19, 2026