Authdog

Keycloak

Last updated Sep 30, 2026
View as Markdown

Keycloak signs users in against a realm you or a customer runs. The directory stays on that server. Authdog fronts the application. Create a confidential client in the realm, then paste its credentials and the realm base URL into the environment.

Copy the redirect URI

In the Authdog console, select the project and environment, open Authentication > Providers, find Keycloak, and click Enable. Copy the redirect URI:

https://identity.authdog.com/api/v1/callback/<connectionId>

Create the realm client

  1. Open the Keycloak admin console and select the realm.
  2. Under Clients, create a client with Client authentication on (a confidential client).
  3. Enable the Standard flow (authorization code).
  4. Under Valid redirect URIs, add the redirect URI from Authdog.
  5. Save, then copy the Client ID and the secret from the Credentials tab.
  6. Note the realm base URL. That is the Domain URI, for example https://keycloak.example.com/realms/acme.

Use the realm base URL, not the admin console URL and not the authorize endpoint.

Configure Authdog

Field Value
Client ID The client identifier
Client Secret The secret from the Credentials tab
Domain URI https://host/realms/<realm>

Save, then toggle the connection active. Authdog requests openid email profile and reads the profile from the ID token. Protocol mappers on the realm control extra claims.

Test it

  1. Open hosted sign-in, or https://identity.authdog.com/api/v1/signin/<connectionId>.
  2. Select the Keycloak button and complete the flow.
  3. Confirm the user appears under Users with a Keycloak identity.

Troubleshooting

Symptom Cause
invalid_client The client is public, so it has no secret
Invalid parameter: redirect_uri The URI is missing from the client's valid redirect URIs
404 on authorize The Domain URI is not the realm base
Works in one environment only Each environment has its own connectionId and redirect URI
Read To learn how to
Keycloak connector The same setup in the connector catalog
Enterprise SSO Connect Keycloak as a generic OIDC enterprise connection with domain routing
Marketplace The listing for this integration