Keycloak signs users in against a realm you or a customer runs. The directory stays on that server. Authdog fronts the application. Create a confidential client in the realm, then paste its credentials and the realm base URL into the environment.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Keycloak**, and click **Enable**. Copy the redirect URI:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the realm client

1. Open the Keycloak admin console and select the realm.
2. Under **Clients**, create a client with **Client authentication** on (a confidential client).
3. Enable the **Standard flow** (authorization code).
4. Under **Valid redirect URIs**, add the redirect URI from Authdog.
5. Save, then copy the **Client ID** and the secret from the **Credentials** tab.
6. Note the realm base URL. That is the Domain URI, for example `https://keycloak.example.com/realms/acme`.

Use the realm base URL, not the admin console URL and not the authorize endpoint.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The client identifier |
| **Client Secret** | The secret from the Credentials tab |
| **Domain URI** | `https://host/realms/<realm>` |

Save, then toggle the connection **active**. Authdog requests `openid email profile` and reads the profile from the ID token. Protocol mappers on the realm control extra claims.

## Test it

1. Open hosted sign-in, or `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Keycloak button and complete the flow.
3. Confirm the user appears under **Users** with a Keycloak identity.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `invalid_client` | The client is public, so it has no secret |
| `Invalid parameter: redirect_uri` | The URI is missing from the client's valid redirect URIs |
| 404 on authorize | The Domain URI is not the realm base |
| Works in one environment only | Each environment has its own `connectionId` and redirect URI |

## Related

| Read | To learn how to |
| --- | --- |
| [Keycloak connector](/docs/connectors/keycloak) | The same setup in the connector catalog |
| [Enterprise SSO](/docs/sso) | Connect Keycloak as a generic OIDC enterprise connection with domain routing |
| [Marketplace](/marketplace/keycloak) | The listing for this integration |
