fastapi-keycloak-middleware
Middleware for FastAPI to authenticate a user against keycloak
Decision gist · record as of 2026-08-14
Yes, if you are already using Keycloak and FastAPI. The package significantly reduces boilerplate for token validation and role enforcement. However, verify the license before use in commercial settings, and note that maintenance is aging (215 days since last release)—acceptable for stable middleware but monitor for security updates or breaking changes in FastAPI or Keycloak.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Keycloak server and valid OIDC client credentials (server URL, client ID, realm name).
- Low install friction; depends only on fastapi and python-keycloak.
- Maintenance status is aging—last release was 215 days ago—so expect slower response to issues, though no known vulnerabilities are recorded.
License · maintenance · safety
(unclear) — License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before adopting in a commercial or restricted-license context.
last release 2026-01-11 (215 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 78,032 downloads/mo, #14,474 on PyPI
Alternatives
Verify before relying
pip install fastapi-keycloak-middleware
from fastapi import FastAPI, Depends
from fastapi_keycloak_middleware import FastAPIKeycloakMiddleware
app = FastAPI()
app.add_middleware(FastAPIKeycloakMiddleware, server_url="https://keycloak.example.com", client_id="my-app", realm="my-realm")
@app.get("/protected")
async def protected(request):
return {"user": request.user}- Whether the package supports fine-grained authorization via Keycloak Authorization services (mentioned as a future plan in the description).
- Current state of the repository (archived status, commit history, community activity) to assess true maintenance health beyond release date.
What it is and what it does
fastapi-keycloak-middleware is a FastAPI middleware that bridges your application to Keycloak for user authentication and authorization. It handles OIDC token validation (either locally using Keycloak's public key or via the token introspection endpoint), stores user identity and authorization scopes in the request context, and provides decorators and dependencies to enforce role or permission checks on individual endpoints. The package wraps python-keycloak and integrates with Starlette's authentication mechanisms, so it fits naturally into the FastAPI ecosystem.
You use it by installing the middleware into your FastAPI app, configuring it with your Keycloak server details, and then decorating endpoints or using dependency injection to require specific roles or permissions. It supports custom callbacks to fetch user objects from your database and to map Keycloak roles to application-specific permissions, making it flexible for varied authorization schemes.
Use it for
- Protect FastAPI endpoints with Keycloak authentication, validating bearer tokens on each request.
- Enforce role-based access control (RBAC) on specific routes using decorators without manual token inspection.
- Retrieve the authenticated user object or authorization result within endpoint handlers via FastAPI dependencies.
- Integrate a FastAPI microservice into an existing Keycloak-based identity infrastructure.
- Map Keycloak roles to application-specific permissions through custom callback functions.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using Keycloak and FastAPI.
The package significantly reduces boilerplate for token validation and role enforcement. However, verify the license before use in commercial settings, and note that maintenance is aging (215 days since last release)—acceptable for stable middleware but monitor for security updates or breaking changes in FastAPI or Keycloak.
Install
fastapi-keycloak-middleware on PyPI
Before you install
Low install friction; depends only on fastapi and python-keycloak. Maintenance status is aging—last release was 215 days ago—so expect slower response to issues, though no known vulnerabilities are recorded.
Requires a running Keycloak server and valid OIDC client credentials (server URL, client ID, realm name).
License in practice
License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before adopting in a commercial or restricted-license context.
Quickstart
pip install fastapi-keycloak-middleware
from fastapi import FastAPI, Depends
from fastapi_keycloak_middleware import FastAPIKeycloakMiddleware
app = FastAPI()
app.add_middleware(FastAPIKeycloakMiddleware, server_url="https://keycloak.example.com", client_id="my-app", realm="my-realm")
@app.get("/protected")
async def protected(request):
return {"user": request.user}
Verify before relying
- Whether the package supports fine-grained authorization via Keycloak Authorization services (mentioned as a future plan in the description).
- Current state of the repository (archived status, commit history, community activity) to assess true maintenance health beyond release date.
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release <4,>=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesfastapipython-keycloak |
| Maintenance | Aging 215 days since the last release |
| First released | |
| Downloads | 78,032 / month, #14,474 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14 |
Evidence: fastapi_keycloak_middleware-1.6.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “fastapi keycloak authentication”
- fastapi-keycloak-middlewareFastAPI middleware that integrates Keycloak for OIDC-based…
- python-keycloakProvides Python bindings to the Keycloak API, supporting both OpenID…
- apache-airflow-providers-keycloakIntegrates Keycloak identity and access management with Apache…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also axioms-fastapi · python-keycloak · keystonemiddleware · pulumi-keycloak · fastapi-azure-auth · apache-airflow-providers-keycloak · aioauth · django-oidc-provider · propelauth-fastapi · dapr-ext-fastapi