Keycloak 26.8.0 released
October 01 2026
To download the release go to Keycloak downloads.
Highlights
This release features new capabilities for users and administrators of Keycloak.
The highlights of this release are:
-
Issue and verify digital wallet credentials with OID4VCI and OID4VP
-
Automate user provisioning across identity systems with the SCIM API
-
Run multi-cluster deployments without an external cache using stateless mode (now supported)
-
Simpler administration with automatic index creation, reduced memory usage, and enhanced HTTP performance
-
Token exchange delegation for AI agents and automation with consent and FGAP authorization
Security and Standards
Credential lifecycle management now includes revocation when refresh tokens are revoked, and a new Application Initiated Action (AIA) lets users request credential issuance within an authenticated session.
Key attestation is configurable in the admin console with hardened x5c certificate validation following the HAIP profile.
This release also adds experimental support for the mdoc format, provided by the new experimental feature oid4vc-mdoc.
Integration guides for the Lissi and Valera wallets are available, along with documentation for SD-JWT signing key setup, credential management, and revocation.
Example applications are provided in this release (for illustration, not officially supported):
The attestation-based client authentication (client-auth-abca), pre-authorized code grant (oid4vc-vci-preauth-code), REST credential offer endpoint (oid4vc-vci-rest-credential-offer), and OpenID4VP (oid4vc-vp) remain experimental features.
Many community members were involved in the development.
Many thanks to Awambeng,
Babis Routis, ShurongCAO,
Pascal Knüppel, Thomas Darimont,
Dominik Schlosser, forkimenjeckayang,
Francis Pouatcha, Hager Khamis,
Ingrid Kamga, Naman Jain,
Asish Kumar, Ogen Bertrand,
Hugo Hakim Damer, Rohit Behera,
rameshkumarkoyya, Shashank RM,
Thomas Diesler, Vinod Anandan,
Palpable and Stefan Wiedemann for the contributions!
Verify credentials with OID4VP (experimental)
Organizations adopting verifiable credentials need a way to accept credential presentations from digital wallets as part of login flows, without requiring a traditional password.
Keycloak can now act as an OID4VP verifier, enabling authentication flows where users present verifiable credentials from their wallets.
The verifier supports cross-device presentation flows and the direct_post.jwt encrypted response mode.
Trust material for credential verification can be delegated to an external identity provider by alias, and SD-JWT User Attribute and Session mappers are available to extract claims from presented credentials.
React to account status changes with Shared Signals Framework (experimental)
The experimental Shared Signals Framework (SSF) support now emits RISC account-disabled and account-enabled event types when a user is enabled or disabled, extending coverage beyond the CAEP session and credential events that shipped in 26.7. Additionally, the event structure has been revised for better alignment with the CAEP and RISC specifications, and the admin event store no longer receives unvalidated payloads to prevent PII leakage.
Parameterized scopes (formerly known as dynamic scopes) allow clients to pass a parameter value along with the scope name in an OAuth 2.0 authorization request. This is especially useful when a scope represents an entity with a large or dynamic set of values (for example a project name like project:12345), preventing the need to pre-define countless individual client scopes in Keycloak.
Parameterized scopes have officially moved from experimental to preview status.
Token exchange delegation with consent, FGAP authorization, and audit trail (preview)
Applications such as AI agents and automation tools need limited, consent-based access to act on behalf of a user without requiring administrator privileges or exposing sensitive credentials.
Users can now delegate access to a client application through OAuth consent using the new delegation:client:<client-id> parameterized scope.
The resulting token includes an act claim identifying the client as the actor.
Unlike admin-user delegation, client delegation does not grant Admin API access even if the client holds service account credentials, ensuring that a leaked delegation token cannot escalate privileges.
The delegation:user and delegation:client client scopes are now auto-created as Optional scopes in all realms, and delegation authorization is controlled exclusively through Fine-Grained Admin Permissions V2 using the delegate and delegate-members scopes.
Delegation audit events now include the client identity, and standard token exchange rejects subject tokens carrying delegation claims to prevent bypass.
A new client policy executor allows administrators to restrict the may_act claim in access tokens, giving per-client control over which clients can participate in delegation.
Token exchange delegation support status is now preview.
Track impersonation across token lifecycle and downstream services
When an administrator impersonates a user, downstream resource servers and audit systems had no reliable way to identify that a token was issued under impersonation or who the impersonator was.
Token lifecycle events (CODE_TO_TOKEN, REFRESH_TOKEN, and others) are now enriched with impersonator and impersonator_id details, providing a complete audit trail across all token operations performed under impersonation.
Additionally, tokens issued from impersonation sessions now include the act (actor) claim (RFC 8693 Section 4.1) in both access tokens and ID tokens, allowing downstream resource servers to identify the impersonator.
The claim is always present and cannot be disabled.
Secure client cluster node registration
A new client policy executor, secure-client-node-hostname, is available to protect against server-side request forgery (SSRF) via the legacy adapter cluster node registration endpoint (/clients-managements/register-node).
A confidential client could previously register an attacker-chosen hostname, which Keycloak would later use as the destination for management callbacks such as logout propagation and push-revocation.
When the executor is attached to a client policy, node hostnames are validated against an administrator-configured list of regex patterns before being persisted. Registrations that do not match any pattern are rejected.
This protection is opt-in and must be explicitly configured to take effect.
Administrators managing deployments that use the legacy adapter node registration feature should add the secure-client-node-hostname executor to a client policy and configure the allowed hostname patterns.
Hostname patterns match against DNS hostnames and IPv4 addresses. Port suffixes are always rejected. Patterns are matched against the bare hostname or IP address.
Administration
Declarative client management with Admin API v2 (preview)
The Client Admin API v2, introduced as an experimental feature in Keycloak 26.7, has been promoted to preview.
It can now be enabled with --features=preview or --features=client-admin-api:v2.
The API provides strict validation, declarative configuration, and an accurate OpenAPI specification for managing OIDC and SAML clients.
It can be consumed through a Java client, an auto-generated JavaScript client, and a CLI, and the Keycloak Operator uses it to manage clients declaratively via the KeycloakOIDCClient and KeycloakSAMLClient custom resources.
The Operator’s KeycloakOIDCClient and KeycloakSAMLClient custom resources were also promoted to Preview.
Client Secret Rotation (supported)
Rotating client secrets in production without downtime required manual coordination and risked service interruptions if the old secret was invalidated before all consumers switched to the new one.
Client Secret Rotation allows confidential clients to rotate their secrets through client policies, keeping up to two concurrently active secrets for seamless rotation without downtime.
Administrators can plan the rotation schedule and anticipate when applications need to adopt the new secret, reducing the risk of secret leakage.
Invite users automatically with workflows
Sending invitation emails to newly created users previously required external automation or a call to the Admin REST API’s execute-actions-email endpoint.
The new invite-user workflow step sends an action-token email automatically when a user is created, without requiring external tooling or a custom workflow step provider.
Administrators can configure which required actions the user must complete (defaulting to password update and email verification), and optionally specify a client and redirect URI for the post-completion flow.
Thanks to bilkoua for this contribution.
Protocol mapper allow-list for Admin REST API
Client Policies now provide the allowed-protocol-mappers executor to restrict protocol mapper types that can be created or updated through the dedicated Admin REST API protocol mapper endpoints.
SCIM API (supported)
The SCIM (System for Cross-domain Identity Management) API provides a standards-based interface for managing users and groups within a realm. It enables seamless integration with identity management systems and applications that support the SCIM protocol.
In this release, the SCIM API is promoted from preview to supported. The SCIM API received extensive improvements including support for multivalued user attributes, User Profile permissions, Fine-Grained Admin Permissions in search filters, and improved performance for large user bases.
For more details, see the Managing users and groups through SCIM documentation.
Configuring and Running
Multi-cluster v2 (supported)
Multi-cluster v2 enables connecting two or more Keycloak clusters without an external Infinispan cluster by using the stateless feature.
Session data is stored in the database, simplifying the deployment architecture compared to multi-cluster v1.
In this release, multi-cluster v2 and the stateless feature are promoted from preview to supported.
The feature is disabled by default and can be enabled with --features=stateless.
A new deployment guide for bare-metal and VM environments is now available alongside the existing Kubernetes guide.
For more details, see <@links.ha id="multi-cluster-v2-introduction" />.
Multi-cluster v1 (deprecated)
Multi-cluster v1 (the multi-site feature) is deprecated and will be removed in a future major release.
Multi-cluster v2, which uses the stateless feature, is the recommended replacement.
It simplifies the deployment architecture by eliminating the external Infinispan cluster and its cross-site replication.
Support for encrypted PEM files for TLS certificate and private key
Deploying Keycloak with encrypted private keys previously required converting them to an unencrypted format or using a keystore, adding operational complexity.
Keycloak now supports encrypted PKCS#8 private keys in PEM format for HTTPS configuration.
Use the new --https-certificate-key-file-password option to provide the decryption password.
The management interface also supports this via --https-management-certificate-key-file-password.
For details, see <@links.server id="enabletls"/>.
Login failures now stored in the database
Brute force detection data is now persisted in the database by default, so temporarily locked-out users remain locked out across cluster restarts.
Deployments using the multi-site or clusterless features continue to store login failures in the external Infinispan cluster.
The previous in-memory behavior is available as login-failures:v1 but is deprecated.
For details, see the Upgrading Guide.
First-class CLI options for cluster and node name
The embedded cache cluster name and node name can now be configured with the new --cache-embedded-cluster-name and --cache-embedded-node-name CLI options, replacing the low-level SPI options that were previously required.
By default, the node name is a random value generated on each start, making it difficult to correlate metrics, logs, and JGroups diagnostics across restarts.
Setting a stable node name is especially useful for observability tools such as Grafana dashboards and log aggregation.
When deploying with the Keycloak Operator, the node name is now automatically set to the Kubernetes pod name (for example, keycloak-0).
For standalone deployments on Kubernetes, set KC_CACHE_EMBEDDED_NODE_NAME using the downward API to inject the pod name.
For non-Kubernetes deployments, pass --cache-embedded-node-name=<name> with a value that uniquely identifies each node.
Automatic non-blocking index creation for large tables
When upgrading Keycloak with large database tables, index creation was previously skipped during schema migration to avoid blocking startup.
Operators had to create the missing indexes manually.
Keycloak now automatically creates skipped indexes in the background after startup using non-blocking index creation on PostgreSQL, Oracle, MySQL/MariaDB, and supported Microsoft SQL Server editions.
Invalid PostgreSQL indexes left by failed previous attempts are detected and recreated automatically.
On databases without non-blocking support, Keycloak continues to log the SQL for manual execution.
Vert.x-based outbound HTTP client (experimental)
Keycloak uses the Apache HTTP Client for all outgoing connections to external services such as identity providers, OCSP responders, and backchannel logout endpoints.
As Keycloak already runs on Vert.x/Netty for inbound traffic, using a separate HTTP stack for outbound connections adds unnecessary complexity and dependency overhead.
Keycloak now provides an experimental Vert.x-based HTTP client that replaces the Apache HTTP Client with Vert.x/Netty for all outgoing connections.
To enable it, start Keycloak with --features=http-client:v2.
When enabled, all outgoing HTTP traffic uses the Vert.x HTTP client.
Existing configuration options work the same way.
Helm Chart Operator install (experimental)
Keycloak now releases an experimental Helm chart to install the Operator.
Organizations
Shared identity providers across organizations
Identity providers can now be linked to multiple organizations, enabling scenarios such as a single corporate identity provider serving users across different business units or subsidiaries, each represented as a separate organization. Each identity provider link carries its own auto-membership and membership type configuration, allowing fine-grained control over how users are onboarded per organization.
Domain routing has been moved from the identity provider to the domain entity. Each domain can independently specify which identity provider handles authentication and whether users are auto-redirected. The domain gate ensures cross-organization isolation — a user is only auto-added to an organization that claims their email domain, even when multiple organizations share the same identity provider.
New identity provider links created after upgrading default to the Unmanaged membership type. Existing links are migrated with the Managed type to preserve previous behavior.
Themes
Redesigned identity provider buttons on the login page
The social identity provider section on the login page has been refreshed with updated icons, a new divider layout, and improved button labels.
If you have a custom login theme, see the Upgrading Guide for details on what changed.
Upgrading
Before upgrading refer to the migration guide for a complete list of changes.
All resolved issues
Security fixes
- #50444 [CVE-2026-12388] IdP mapper admin role escalation identity-brokering
- #50618 [CVE-2026-14781] OIDC broker applies id_token email_verified to userinfo email, marking unverified addresses as verified oidc
- #51865 [CVE-2026-19608] Name-only group claims let same-name groups satisfy path-specific group policies authorization-services
- #52168 CVE-2026-54515 CVE-2026-59889 com.fasterxml.jackson.core:jackson-databind 2.22.0 dist/quarkus
- #52169 CVE-2026-59903 io.netty:netty-codec-http:4.1.136.Final dist/quarkus
Weaknesses
- #47295 LDAP bind credentials sent to new server when connection URL is changed ldap
- #49022 SAML ECP endpoint returns inconsistent Content-Type on error responses saml
- #49220 Client GET endpoints return raw client secrets to view-clients role holders admin/rbac
- #49239 Stop storing client private keys in the database and deprecate generate endpoints admin/rbac
- #49242 SMTP masked credential substitution does not verify destination fields haven't changed admin/api
- #49610 Document trust boundaries for attribute-based conditions with self-registration enabled workflows
- #49784 UserInfo Endpoint: Add null-check for SignatureProvider when validating JWT bearer tokens oidc
- #49785 UserInfo Endpoint: Handle malformed Content-Type header gracefully oidc
- #50123 Client baseUrl URI-scheme validation missing during realm and partial import admin/api
- #50124 OIDC: Inverted return value in `compareSessionIdWithSessionCookie()` backwards-compatibility path oidc
- #50131 Client Policies: `allowed-protocol-mappers` enforcement missing for Admin REST API protocol mapper operations admin/api
- #50135 OIDC: PAR request URIs stored in single-use cache without realm binding oidc
- #50368 OID4VCI: Account API delete endpoint for issued verifiable credentials missing ownership validation oid4vc
- #50468 Parameterized Scopes: Pre-authentication username enumeration via username/delegation scope types
- #50469 Parameterized Scopes: First-match prefix resolution allows permissive scope to shadow stricter scope
- #50470 Parameterized Scopes: CustomRegexScopeType applies admin regex to unbounded attacker input without length cap
- #50471 SCIM: Missing lower-bound validation on count parameter in list operations scim
- #50473 SCIM: Groups endpoint members operations do not enforce isAdminUser check scim
- #50475 SCIM: PATCH operations list has no size limit — missing maxOperations enforcement scim
- #50489 Client API v2: Temporary client creation via addClient() shim bypasses realm-level authorization admin/api-v2
- #50493 Client API v2: Operator disables TLS hostname verification for admin connection admin/api-v2
- #50517 OID4VCI: key_attestations_required not enforced when key_attestation header absent from proof JWT oid4vc
- #50518 OID4VCI: Key attestation x5c chain validated against system cacerts with no EKU or revocation oid4vc
- #50520 OID4VCI: Unbounded expire parameter on /create-credential-offer allows indefinite pre-auth codes oid4vc
- #50521 OID4VCI: getAttestationRequirements() hardcodes proof-type key to jwt ignoring other types oid4vc
- #50523 OID4VCI: LD-VC signer fetches remote @context URLs over HTTP with no allowlist or cache oid4vc
- #50524 OID4VCI: User-editable did attribute used as credential subject with realm-local uniqueness only oid4vc
- #50533 Identity Broker v2: Wrong-IdP token returned after account-linking due to un-namespaced session note oidc
- #50602 Handling HTTP/2 connection coalescing issues originating from wildcard certificates dist/quarkus
- #50749 OID4VC JWT proof JWK claim type confusion crashes proof validation oid4vc
- #50934 Credential request decryption accepts RSA1_5 for RSA-OAEP-256 encryption keys oid4vc
- #50965 URI client-policy executors omit OIDC front-channel logout URI oidc
- #50985 SCIM Users filter leaks hidden group membership under FGAP scim
- #50986 SCIM Groups filter leaks hidden user membership under FGAP scim
- #50987 SCIM reads and filters bypass user-profile view permissions for mapped attributes scim
- #50988 Workflow group membership events confuse slash-named groups with nested paths workflows
- #50989 Workflow role grant events match client and realm roles by bare name workflows
- #50991 SCIM user writes bypass user-profile edit permissions for custom attributes scim
- #50999 Same-second refresh-token rotation allows stale token replay oidc
- #51109 SD-JWT verification accepts signatures whose algorithm differs from the JWS header oidc
- #51127 Persistent User Sessions: cache-miss unconditionally re-hydrates cache from DB, resurrecting deleted sessions storage
- #51139 Server info exposes database operational details to view-realm administrators dist/quarkus
- #51158 User partial filters ignore ancestor group membership denies admin/fine-grained-permissions
- #51211 SAML: Add signature verification for inbound LogoutResponse messages saml
- #51212 JOSE: Base64Url decoder throws unchecked exception on padding-only input oidc
- #51241 Client update admin events retain private-key attributes admin/api
- #51242 Registration access token regeneration stores live bearer tokens in admin events admin/api
- #51243 RP-initiated logout can suppress upstream broker logout with forged initiating_idp oidc
- #51276 Unrestricted Class.forName() on query parameter in ComponentResource.getSubcomponentConfig admin/api
- #51311 Unauthenticated NullPointerException (HTTP 500) on OIDC Dynamic Client Registration PUT via the "scope" field (CWE-476) oidc
- #51328 Client type read-only client properties can be bypassed during registration oidc
- #51535 Admin API v2 client update does not clean up stale rotated secret attributes admin/api-v2
- #51699 Missing security headers on root-path redirect when http-relative-path is configured dist/quarkus
- #52013 [OID4VCI] unauthenticated RSA1_5 padding oracle in OID4VCI credential requests oid4vc
- #52058 Add warning about dynamic urls to reflect the danger of hostname pollution docs
- #52105 OID4VC issued credential deletion not scoped to path user or realm oid4vc
- #52106 SAML metadata key cache is not invalidated on client updates saml
- #52398 Concurrent completion of one WebAuthn registration ceremony persists multiple passwordless credentials authentication/webauthn
- #52400 LDAP password-policy response control parser defects — warning/error tag collision (forced-password-change forgery and suppression) plus uncaught NumberFormatException login failure ldap
- #52598 SCIM membership PATCH events omit the changed relationship from audit trail scim
- #52599 SCIM legacy query roles infer cross-resource memberships when FGAP is disabled scim
- #52640 SCIM Group DELETE bypasses administrative-resource protection through cascade
- #52642 SCIM user deletion skips security-state cleanup
- #52644 Absence-based completion predicate cannot distinguish consumed from never-persisted events
- #52645 Bulk HQL executeUpdate bypasses AsyncCommitIntegrator security classification
- #52646 Concurrent failures at brute-force reset boundary can erase newly recorded attempts
- #52650 LoginFailureEntity async commit classification can discard failure counters after failover infinispan
- #52651 Multi-Cluster v2 RPO "No data loss" conflicts with default async commit of ephemeral data docs
- #52664 Password denylist can be bypassed under Turkish locale authentication
- #52665 Same-name client role authorizes victim-targeted credential offers via role namespace confusion oid4vc
- #52666 Reusing a rotated OID4VCI refresh token repeatedly reissues credential authority oid4vc
- #52667 User-editable mapped attribute can extend an SD-JWT credential beyond the issuer-configured lifetime oid4vc
- #52668 Credential issuance ignores the administrator-approved attribute snapshot docs
- #52669 Unauthenticated credential requests trigger private-key JWE decryption before bearer authentication oid4vc
- #52670 Refreshing a stolen targeted offer lets another user bypass offer-required issuance oid4vc
- #52671 OID4VCI SD-JWT issuance makes array claims all-or-nothing disclosures oid4vc
- #52681 kcadm preserves world-readable permissions on existing config files admin/api-v2
- #52684 SCIM search writes raw filter values to debug logs scim
- #52691 Token exchange provider routing allows delegation tokens to bypass actor validation via standard exchange token-exchange
- #52696 Recovered sites can enforce stale security configuration for up to one hour storage
- #52732 [OID4VCI] Make sure that OID4VCI access token usable just for credential endpoint oid4vc
- #52919 OID4VCI: Preventing memory leak and adding decompression limit oid4vc
- #53166 Realm import resets organization-IdP link policy to permissive defaults identity-brokering
- #53307 Identity-provider reads disclose organization links outside the caller's scope identity-brokering
Deprecated features
- #44062 Should Kerberos Credential delegation be deprecated?
- #51921 Deprecate legacy OIDC client switches from 'OpenID Connect Compatibility Modes' oidc
- #52121 Deprecate volatile sessions and allow opting out of session caching
- #52923 Deprecate 'Full scope allowed' client switch oidc
- #53219 Deprecate other client registration providers than OIDC
Removed features
- #51897 Deprecate route from AUTH_SESSION_ID cookie for sticky sessions
- #52130 Deprecate clusterless feature
- #52480 EOL Keycloak Realm Operator
New features
- #16738 Supported client secret rotation
- #48899 SSF: Add support for RiscAccountPurged event ssf
- #50644 [OID4VP] Support direct_post.jwt (encrypted) response mode authentication
- #50876 update admin client tests to use sort and filter
Enhancements
- #16947 group.spec.ts does not contain example of how to add attributes while creating groups admin/client-js
- #22524 Improve WebAuthn error messages translations
- #22962 SAML Responses with Invalid Signatures saml
- #27437 Accept encrypted PEM TLS certificate key
- #32080 Infinispan: LoginFailures cache should not be unbounded
- #40211 Add link to clients in UsedBy hint for auth-flows listing in admin ui admin/ui
- #40246 Selecting value in combobox not default listed admin/ui
- #43741 Parametrized client_id in the organization invite link and invite token organizations
- #44605 Infinispan metrics should not contain a dynamic node label
- #44963 PassKey "User verification requirement" error's are not translated translations
- #46555 Concurrent Index creation on PostgreSQL and other databases for DB migrations storage
- #47921 Account Console: Add per-application session termination on the Applications page account/ui
- #47945 Good proxy instructions for a production ready Keycloak setup
- #48063 refresh_expires_in is 0 for offline tokens when Offline Session Max Limited is disabled, but server enforces Offline Session Idle oidc
- #48216 KeyCloak Admin Client - Support Jackson 3 dist/quarkus
- #48349 Upgrade FreeMarker to the most recent version
- #48448 DNS Rebinding attacks to create bling SSRF docs
- #48847 Update Vale
- #49039 Signed JWT - Federated: support managed Kubernetes (EKS, GKE, AKS) via dynamic OIDC issuer discovery identity-brokering
- #49044 Better memory management with argon2 dist/quarkus
- #49056 Make the Roles field optional on the client Authorization Evaluate tab
- #49297 Add `invite-user` workflow step workflows
- #49493 [SAST] Restrict direct access to `issuedFor` variable
- #49549 Upgrade to Quarkus 3.40 LTS
- #49767 Refactor SSF to use keycloak-admin-client and react hook form
- #49874 How to create a JFR recording with JDK standard tools observability
- #49968 Switch internal HTTP client from Apache to Vert.x/Netty
- #50159 Make UuidUnmodified more generic so that we can use it on multiple fields admin/api-v2
- #50221 Add default non-endpoint methods to the admin api v2 interfaces as needed for typing
- #50695 [OID4VCI] Implement missing HAIP conformance tests oid4vc
- #50803 Document the Password Policy SPI in the Server Developer Guide
- #50911 Ensure consistent transaction rollback across all error response paths core
- #50948 Sorting Applications in Account Console
- #50970 Missing index on WORKFLOW_STATE.SCHEDULED_STEP_TIMESTAMP causes full filter scan in getDueScheduledSteps workflows
- #50992 Redesign identity provider buttons on the login page login/ui
- #51214 Improve runtime when building user representations via User Profile user-profile
- #51263 Organization group-by-path endpoint returns a brief representation instead of a full representation organizations
- #51273 Upgrade to Quarkus 3.37.4
- #51305 Token Exchange Delegation for Clients token-exchange
- #51310 Upgrade to Quarkus 3.38
- #51359 Complete Identity Provider support in the Test Framework Realm DSL test-framework
- #51400 SCIM user serialization creates ~200x more UserProfile instances than necessary
- #51402 SCIM search/list executes unconditional COUNT(*) query on every request
- #51403 SCIM filter string is parsed twice through ANTLR4 grammar per request
- #51413 [CIMD] Resource Indicators with CIMD
- #51428 Ensure consistent transaction rollback in SCIM error response paths scim
- #51432 Upgrade to Quarkus 3.38.1
- #51450 Unify QR code and divider components in the login theme login/ui
- #51451 [OID4VP] Improve cross-device login page layout oid4vc
- #51455 Unify OTP setup buttons to use shared `buttons` macro login/ui
- #51481 Introduce dedicated delegation permission for token exchange delegation token-exchange
- #51489 Add actor to impersonation tokens and details to event logs core
- #51506 Skip unnecessary provider initialization for non-server commands dist/quarkus
- #51528 Authentication events should distinguish primary vs rotated client secret
- #51537 Improve help text for admin permissions (FGAP) fields authorization-services
- #51676 Distinguish between Login Theme and Account Console for an already existing Mail in Keycloak
- #51685 SCIM should also return a forbidden response status for schemas and resourceTypes if the query is present in the request
- #51687 SCIM filtered search should leverage the Infinispan entity cache scim
- #51701 Store provider.jar mtime in seconds in keycloak-persisted.properties for Quarkus re-augmentation
- #51797 Keycloak with jdbc-ping stack failed to create a cluster after the MariaDB restore procedure infinispan
- #51808 Retarget quarkus-next to Quarkus 3.39 branch after 3.x branch was dropped
- #51851 Avoid contention on IDX_USER_SESSION_EXPIRATION_* indexes on MS SQL/MySQL
- #51854 Optimize index sizes for session storage in the database
- #51855 Client configuration changes are not propagated between sites infinispan
- #51900 Avoid updates to IDX_USER_SESSION_EXPIRATION_LAST_REFRESH on every token refresh
- #51938 Upgrade to Quarkus 3.39.0.CR1
- #51968 Don't wrap exceptions when running tests remotely in the new test framework
- #52012 Extend asynchronous commit optimization to SQL Server and Oracle
- #52126 Deprecate in-memory login failures and make persistent login failures the default
- #52127 Upgrade to Quarkus 3.39.1
- #52268 Organization authenticator drops the typed username when falling through to the default identity-provider-redirector (no login_hint)
- #52356 Upgrade to Quarkus 3.39.2 dist/quarkus
- #52722 Upgrade to Infinispan 16.0.15
- #52943 Upgrade to Quarkus 3.40.0.CR1
- #52988 Cache parsed theme resource declarations to avoid re-parsing them on every login page render login/ui
- #52992 Cache the resolved max-length configuration for OIDC request parameters oidc
- #52994 Avoid building the WebAuthn trust verifier on every login login/ui
- #53010 MCP Documentation for 26.8
- #53211 Add session bucket and coarse-grained timestamp to ROOT_AUTH_SESSION for reduced index contention storage
- #53242 SAML broker: IdP-initiated logout fails with HTTP 500 and is rolled back when the IdP has no single logout service URL identity-brokering
Bugs
- #41394 Flow steps back when changing locale or refreshing page (Regression of #30520 / #30644) authentication
- #41433 After update from 26.0 to 26.1 extent account theme keycloak.v3 is not working for custom components account/ui
- #44832 User creation problem with default groups defined, with identity provider and federated openldap ldap
- #47482 [quarkus-next] ConcurrentModificationException in parallel Quarkus build steps dist/quarkus
- #48043 [OID4VCI] c_nonce Replay oid4vc
- #48188 [OID4VCI] Issuance with Authorization Code Flow assumes same client_id for offer creation and redemption oid4vc
- #48858 'view-clients' bypasses 'view-users' restriction via 'client-scoped' endpoints admin/fine-grained-permissions
- #49077 NullPointerException in ResourceIndicatorsPostProcessor when access token audience is null oidc
- #49236 SSF: Client scopes ssf.read and ssf.manage not created when SSF enabled for existing realm ssf
- #49731 Creating a new realm from json using kcadm gives a PK violation on KEYCLOAK_ROLE despite it only being defined once in the JSON. storage
- #49891 [OID4VCI] CNF is not included in sd-jwt when number_of_decoys is not explicitly configured oid4vc
- #49964 Malformed Content-Type header causes HTTP 500 on token endpoints instead of RFC 6749 §5.2 compliant 400 authorization-services
- #50110 Keycloak doesn't honor `--https-trust-store-type` when automatically creating the Trust Store core
- #50178 Scope-based permission accepts a scope not associated with the selected resource (Admin REST API) authorization-services
- #50190 Admin Console: saving attributes fails when the attribute key is "constructor", "toString", or another Object.prototype name admin/ui
- #50209 LifeSciences Login does not work anymore in Keycloak version 26.6.3 authentication
- #50228 SearchQuery.getFields() exceptions admin/api
- #50362 [CIMD] Claude Desktop authentication rejected by Keycloak: jwt-bearer grant type incompatible with public client oidc
- #50535 Admin UI: Resource search does not work in Authorization Evaluate “Resources and Scopes - Key” selector admin/ui
- #50590 ConcurrentModificationException in OrganizationAdapter.setAttributes on concurrent PUT /organizations/{id} organizations
- #50596 User federation synchronizations will always evict all users of a realm from the users cache storage
- #50629 REVOKE_GRANT_ERROR prevents logout except when account console is open in another tab oidc
- #50684 SAML broker artifact binding fails to validate signed nested Response inside ArtifactResponse: Cannot resolve element with ID saml
- #50687 UI shows inherited role as non-inherited when the same role is also assigned manually admin/ui
- #50691 Email not lowercased in "Always Read Value From LDAP" delegate (incomplete fix from #43254) ldap
- #50694 Nightly Conformance tests are failing oid4vc
- #50700 Exporting a realm with users says it needs file parameter, which is provided admin/cli
- #50720 Trusted SSF event emission persists verbatim event payload in admin events ssf
- #50788 Putting --optimized before command gives confusing error message dist/quarkus
- #50791 NPE thrown on null secret in AbstractOauth2IdentityProdivder authentication
- #50796 ClientManager.isInternalClient checks only for "master" realm core
- #50800 SCIM: query-users role returns empty Resources array despite correct totalResults scim
- #50807 Dynamic client registration: "scope" member in the request suppresses realm default client scopes on the created client oidc
- #50812 Synthetic SSF emit accepts mismatched user and tenant subjects when only the tenant is subscribed ssf
- #50813 Keycloak does not apply connect timeout when Oracle runs in XA mode dist/quarkus
- #50845 Duplicate of #46382, #46178, #46433 : reporting because none were actually fixed for this case. admin/client-js
- #50854 NPE in executor configuration validation
- #50860 Empty or null description causes duplicate "Allowed field:" admin/api
- #50877 [DOC] FGAPv2: Clarify that manage scope on users and manage-members on group include creating users admin/fine-grained-permissions
- #50907 [kcw] `kcw dev` greps incorrect Keycloak version
- #50944 Flaky Admin UI E2E test: `initial-access.spec.ts` ci
- #50975 Admin UI E2E test failures - SSF Stream ssf
- #50994 Flaky admin UI tests admin/ui
- #51004 Legacy OIDC broker token exchange accepts ID tokens issued to a different audience identity-brokering
- #51018 Typo in "Integrating with Model Context Protocol (MCP)" (mcp-authz-server.adoc) docs
- #51064 Flaky test: org.keycloak.testsuite.forms.BrowserFlowTest#testUserWithOneAdditionalFactorOtpSuccess ci
- #51073 Flaky test: org.keycloak.testsuite.forms.MultipleTabsLoginTest#multipleTabsParallelLoginTestWithAuthSessionExpiredAndRequiredAction ci
- #51074 Flaky test: org.keycloak.testsuite.forms.MultipleTabsLoginTest#multipleTabsParallelLoginTestWithAuthSessionExpiredInTheMiddle ci
- #51075 Flaky test: org.keycloak.testsuite.forms.MultipleTabsLoginTest#multipleTabsParallelLoginTestWithAuthSessionExpiredAndRefreshInTab1 ci
- #51076 Flaky test: org.keycloak.testsuite.forms.MultipleTabsLoginTest#multipleTabsParallelLoginTest ci
- #51100 Recovery codes have numeric input field despite alphanumeric codes being generated login/ui
- #51113 Usage of second class configuration may not be masked in show-config dist/quarkus
- #51123 Logout fails when IdP is disabled identity-brokering
- #51128 PreparedStatement can have at most 65,535 parameters storage
- #51137 Token exchange and JWT grants ignore use-lightweight-access-token policy token-exchange
- #51146 Test Authentication fails after correcting LDAP connection URL until configuration is saved ldap
- #51153 SCIM filter parentPath not saved/restored in visitValuePath, breaks nested valuePath scim
- #51155 SCIM PATCH does not enforce attribute mutability scim
- #51156 SCIM PATCH NPE when request body contains "schemas": null scim
- #51169 Flaky test: org.keycloak.testsuite.forms.RecoveryAuthnCodesAuthenticatorTest#test09recoveryAuthnCodesWithThresholdConfigured ci
- #51187 [OID4VCI] Handling of realm optional client scopes oid4vc
- #51191 OID4VPVerifierTestBase failure in CI testsuite
- #51201 Labeler fails to set the version in the main branch ci
- #51213 Admin API v2: SAML string-attribute mapper does not remove attributes on explicit null or omission saml
- #51253 Do not pass the client for Delegation parameterized scope type admin/fine-grained-permissions
- #51256 Flaky test: org.keycloak.testsuite.webauthn.registration.passwordless.PwdLessOtherSettingsTest#apiInvalidStateErrorMessage ci
- #51262 Unable to select authorization scopes beyond the first 100 in Scope-Based Permissions admin/ui
- #51269 LDAP Enabled switch remains interactive for users with view-realm only admin/ui
- #51330 Account already existed page button has no gap and no hover on effect account/ui
- #51347 [OID4VCI] Incorrect metadata for key_attestations_required oid4vc
- #51352 Better server error message and handling if email sender is disabled in configuration admin/api
- #51361 InvalidPathException when running test cases in embedded mode on Windows dist/quarkus
- #51372 Admin Console: changing the search term while on a later page keeps the old page offset and shows no results admin/ui
- #51396 `truststore-paths` certificates are ignored by `FileTruststoreProviderFactory`: it silently falls back to the JDK `cacerts` because it is initialized before `TruststoreBuilder` dist/quarkus
- #51398 Pin resolved identity to prevent consent transfer on user recreation token-exchange
- #51401 SCIM filter predicates handle case-insensitive matching incorrectly scim
- #51415 Workflow add-required-action does not allow all available required actions workflows
- #51423 [UX] account console nav on mobile not closing after selecting a page account/ui
- #51437 Enabling parameterized-scopes breaks the built-in organization: scope oidc
- #51496 Deleting a user attribute deletes all custom message localizations of default language en admin/ui
- #51498 Admin console Realm Settings delete uses display name instead of realm name (regression from #48084) admin/ui
- #51512 Flaky test: org.keycloak.testsuite.webauthn.registration.AuthAttachmentRegisterTest#authenticatorAttachmentPlatform ci
- #51525 SCIM filtered PATCH remove deletes all values for multivalued extension attributes scim
- #51527 Admin v2 API PATCH bypasses client secret rotation policy admin/api-v2
- #51531 Composite realm role mappings endpoint does not scale with the number of realm roles — the #47157 fix was applied only to the client variant admin/api
- #51536 TypeError crash in Evaluation tab when selecting "Group" resource type authorization-services
- #51550 @InjectSysLogServer from test-framework does not work with defaults anymore testsuite
- #51552 Refresh Token Introspection oidc
- #51559 SPNEGO mutual authentication response token is not returned after successful login authentication
- #51571 SSF: Missing event details during user logout trigger NPE ssf
- #51590 SCIM: organization groups exposed via the groups attribute on Users scim
- #51600 Flaky test: org.keycloak.testsuite.broker.KcOidcBrokerTest#loginWithExistingUserWithBruteForceEnabled testsuite
- #51614 SCIM Users groups filter does not exclude organization groups scim
- #51620 Migrate remaining login pages have no override in the keycloak.v2 theme account/ui
- #51674 Keycloak's password length policy isn't triggered when changing password in FIPS mode authentication
- #51682 Exceptions in Kubernetes federated-client-authentication signature verification are silently swallowed with no default-level log trace identity-brokering
- #51690 [OID4VCI] Labels for OID4VCI events missing in the admin console oid4vc
- #51692 [OID4VCI] Some error events not reported oid4vc
- #51757 Base implementation of AbstractModelSchema.getAttributeMappers is keyed by model attribute name scim
- #51769 Dutch translation for linkExpirationFormatter produces duplicated value ("12 12 uur") translations
- #51796 Scim complex type attributes are forced to be case-insenitive scim
- #51853 Keycloak Admin Client fails on JS CI testsuite
- #51913 [quarkus-next] Helm chart CI jobs fail due to missing Quarkus snapshot cache restore dist/quarkus
- #51934 EXECUTE_ACTION_TOKEN : event impossible to save workflows
- #51943 AdditionalHelmTemplateBuildItem class is sometimes missing thought to random order of Helm dependencies operator
- #52041 [OID4VCI] mdoc not properly configurable in admin console client scope tab oid4vc
- #52087 Regression: resource_access claim becomes empty {} when populated via User Attribute mapper with JSON value (since 26.7.1) core
- #52103 Log injection via unsanitized client_id in OIDC logout endpoint oidc
- #52147 SCIM resource ID phishing scim
- #52157 Organization invitation fails with invalid_redirect_uri when the organization has no Redirect URL configured organizations
- #52166 Client-side password policy validation does not treat underscore _ as a special character authentication
- #52167 Securing Client Cluster Node Registration via Client Policy Executor authentication
- #52181 Organization invitation is lost when the invitee signs up with a realm-level identity provider organizations
- #52186 Fix missing arguments in HardcodedLDAPRoleStorageMapper warning log ldap
- #52188 Fine-Grained Admin Permissions v2: Cannot view a user who belongs to a group without "view" permission on that group admin/fine-grained-permissions
- #52190 [OID4VCI] Cannot unset values when configuring OID4VCI credential scope oid4vc
- #52197 Admin API v2 returns plaintext client secret to view-clients role holders admin/api
- #52206 User Profile settings allow mapping multiple attributes to the same SCIM attribute scim
- #52207 User creation via SCIM API does not enforce User Profile "required" validation for core user schema attributes scim
- #52208 SCIM User Partial Update Allows Removing Required User Profile Attributes scim
- #52219 Duplicate English text in generateKeysDescription message key admin/ui
- #52223 SCIM API allows updating username even when the Edit username setting is disabled scim
- #52224 SCIM API allows removing username despite it being required scim
- #52229 SCIM API does not enforce User Profile validators scim
- #52230 Missing detailed audit information in group / relam role operatons admin/ui
- #52285 Unsafe workflow pattern in labeler ci
- #52287 Workflows: notify-user email template hardcodes English text, so notifications cannot be fully translated workflows
- #52338 DatabaseIndexCheckerTest.testDetectsAndRecreatesInvalidIndexOnPostgresql fails on Aurora testsuite
- #52378 Admin REST OpenAPI schema types groups-in-role responses as UserRepresentation admin/api
- #52396 Organization missing from the login form model on the invitation confirm-membership page organizations
- #52421 [OID4VCI] Server-side validations for "Supported proof types" and "Cryptographic binding methods" oid4vc
- #52441 DPoPBindEnforcerExecutor requires DPoP on client create/update, defeating its own refresh-token-only binding option oidc
- #52475 Admin console crashes with a raw TypeError when a group request returns 404 admin/ui
- #52491 Integer overflow in OIDC re-auth max_age comparison (OIDCLoginProtocol) oidc
- #52497 Flaky operator test: KeycloakDeploymentTest.testDeploymentDurability fails with "already exists" operator
- #52502 Flaky test: org.keycloak.testsuite.forms.BruteForceTest#testExceedMaxTemporaryLockouts authentication
- #52506 Operator CI jobs missing Maven cache restore — dependency download failures ci
- #52568 ResourceIndicatorsPostProcessor error does not log appropriate error event oidc
- #52574 Regression in 26.7.0: DefaultClientSessionContext.getScopeString() no longer attaches "openid" scope on token refresh when the client omits it from the request oidc
- #52580 ClosingStream does not close underlying stream when terminal operation throws an exception core
- #52583 HHH90010101 warning logged during SCIM concurrent requests due to orphaned Hibernate before-completion callbacks scim
- #52586 HHH100503 INFO message logged during concurrent SCIM requests after constraint violation core
- #52587 Organization group: removeMember should fail when user is not a member organizations
- #52610 Stateless JPA providers: race condition between INSERT ON CONFLICT DO NOTHING and concurrent DELETE storage
- #52611 Cluster event poller: uncaught ClassCastException on malformed event data storage
- #52612 JpaRevokedTokenProvider uses deprecated Time.currentTime() (int) instead of Time.currentTimeSeconds() (long) storage
- #52647 First cluster-readiness probe returns UP before asynchronous CP check completes
- #52654 Unable to re login after deleting the Identity Provider configurations identity-brokering
- #52659 BruteForceTest.testCacheExpiryForTemporaryLockout test is failing after switch to persistent login failures authentication
- #52673 SCIM Group PUT overwrites externalId despite schema declaring it immutable scim
- #52675 SCIM Groups endpoints expose and modify service-account membership scim
- #52676 CVE-2026-4633 User enumeration via identity-first login when Organizations feature is enabled organizations
- #52706 NO_PROXY entries with leading dots or spaces after commas silently fail dist/quarkus
- #52710 Test framework silently ignores database reuse when testcontainers reuse is not enabled test-framework
- #52714 Flaky operator tests: testDeploymentDurability and testDeploymentUpgrade fail with 409 due to leftover StatefulSet operator
- #52720 JWT Authorization Grant cannot be configured with Organization-linked IdPs admin/ui
- #52761 Consent screen returns HTTP 500 for a user in more than one organization (regression in 26.7.0) organizations
- #52767 Admin Console: Client scopes Evaluate tab does not refresh generated tokens when the user changes admin/ui
- #52785 Device flow does not throw error if scope parameter contains a scope not permitted for client oidc
- #52798 NullPointerException when POSTing null payload to /admin/realms/{realm}/groups admin/api
- #52804 Flaky test: org.keycloak.tests.webauthn.registration.passwordless.PwdLessOtherSettingsTest#apiNotAllowedErrorMessage authentication/webauthn
- #52831 Disabled organization set on session context during broker login callback organizations
- #52913 [quick-theme] Login Page Preview stylesheet URL omits the http-relative-path prefix admin/ui
- #52915 #46367 regression in user provider sync behavior storage
- #52938 Admin UI: IdP organization login switches always persisted as false organizations
- #53002 Client roles are not displayed in "Effective role scope mappings" in Client Scope Evaluate admin/ui
- #53013 FGAP v2: creating a user into a group via manage-members + manage-membership also requires the undocumented "view" scope on that group docs
- #53034 GrantTypeCondition misses some event types authentication
- #53100 Organizations: malformed domain in login username (e.g. user@example;com) causes unhandled ModelValidationException ('Invalid domain format') organizations
- #53106 WARN [io.quarkus.deployment.index.IndexWrapper] (build-44) Failed to index void: Class does not exist in ClassLoader QuarkusClassLoader:Deployment Class Loader: PROD for keycloak@66ce957f dist/quarkus
- #53107 SSF discovery document (.well-known/ssf-configuration) omits /realms/{realm} path when realm frontendUrl is set ssf
- #53117 signingCertificate handling in v2 admin/api
- #53138 MayAct executor rejects valid delegation when the scope parameter is not the exact stored username token-exchange
- #53140 Skips the ClientID binding checks when the claim is not a string token-exchange
- #53154 prompt=none returns login_required for organization members without local credentials when the broker has "Redirect when email domain matches" organizations
- #53163 Upgrade migration can attach a stale IdP route to another organization's domain identity-brokering
- #53176 Missing manage-organizations permission check for org group mappers organizations
- #53188 Single-valued organization mapper emits an attacker-selected non-member organization identity-brokering
- #53220 Admin Console user picker (UserSelect) sends username= contains search, producing leading-wildcard LDAP filters that time out on large directories admin/ui
- #53252 Admin UI IdP mapper tests are flaky: clickSaveMapper clicks Cancel before the save request is sent admin/ui
- #53253 IdentityProviderModel removed getOrganizationId() method organizations
- #53290 Organization group representations leak client/realm role metadata to unauthorized admins organizations
- #53335 SCIM user PUT/PATCH bypass the user cache: active=false via SCIM does not disable the user for logins scim