$npx skillfedfor your agent

fastapi-keycloak-middleware

Middleware for FastAPI to authenticate a user against keycloak

With conditionsPyPI SecurityReleased Jan 202678.0K downloads / moPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — fastapi_keycloak_middleware-1.6.0-py3-none-any.whl
v1.6.0 · released 2026-01-11 · Python <4,>=3.11 · 2 runtime deps: fastapi, python-keycloak

Yes, if you are already using Keycloak and FastAPI. The package significantly reduces boilerplate for token validation and role enforcement. However, verify the license before use in commercial settings, and note that maintenance is aging (215 days since last release)—acceptable for stable middleware but monitor for security updates or breaking changes in FastAPI or Keycloak.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a running Keycloak server and valid OIDC client credentials (server URL, client ID, realm name).
  • Low install friction; depends only on fastapi and python-keycloak.
  • Maintenance status is aging—last release was 215 days ago—so expect slower response to issues, though no known vulnerabilities are recorded.

License · maintenance · safety

(unclear) — License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before adopting in a commercial or restricted-license context.

last release 2026-01-11 (215 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 78,032 downloads/mo, #14,474 on PyPI

Verify before relying

pip install fastapi-keycloak-middleware

from fastapi import FastAPI, Depends
from fastapi_keycloak_middleware import FastAPIKeycloakMiddleware

app = FastAPI()
app.add_middleware(FastAPIKeycloakMiddleware, server_url="https://keycloak.example.com", client_id="my-app", realm="my-realm")

@app.get("/protected")
async def protected(request):
    return {"user": request.user}
  • Whether the package supports fine-grained authorization via Keycloak Authorization services (mentioned as a future plan in the description).
  • Current state of the repository (archived status, commit history, community activity) to assess true maintenance health beyond release date.
Same gist for agents: .md · .json

What it is and what it does

fastapi-keycloak-middleware is a FastAPI middleware that bridges your application to Keycloak for user authentication and authorization. It handles OIDC token validation (either locally using Keycloak's public key or via the token introspection endpoint), stores user identity and authorization scopes in the request context, and provides decorators and dependencies to enforce role or permission checks on individual endpoints. The package wraps python-keycloak and integrates with Starlette's authentication mechanisms, so it fits naturally into the FastAPI ecosystem.

You use it by installing the middleware into your FastAPI app, configuring it with your Keycloak server details, and then decorating endpoints or using dependency injection to require specific roles or permissions. It supports custom callbacks to fetch user objects from your database and to map Keycloak roles to application-specific permissions, making it flexible for varied authorization schemes.

Use it for

  • Protect FastAPI endpoints with Keycloak authentication, validating bearer tokens on each request.
  • Enforce role-based access control (RBAC) on specific routes using decorators without manual token inspection.
  • Retrieve the authenticated user object or authorization result within endpoint handlers via FastAPI dependencies.
  • Integrate a FastAPI microservice into an existing Keycloak-based identity infrastructure.
  • Map Keycloak roles to application-specific permissions through custom callback functions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are already using Keycloak and FastAPI.

The package significantly reduces boilerplate for token validation and role enforcement. However, verify the license before use in commercial settings, and note that maintenance is aging (215 days since last release)—acceptable for stable middleware but monitor for security updates or breaking changes in FastAPI or Keycloak.

Install

fastapi-keycloak-middleware on PyPI

Before you install

Low install friction; depends only on fastapi and python-keycloak. Maintenance status is aging—last release was 215 days ago—so expect slower response to issues, though no known vulnerabilities are recorded.

Requires a running Keycloak server and valid OIDC client credentials (server URL, client ID, realm name).

License in practice

License treatment is unclear; no SPDX identifier or raw license text is available in the metadata. Verify the actual license before adopting in a commercial or restricted-license context.

Quickstart

pip install fastapi-keycloak-middleware

from fastapi import FastAPI, Depends
from fastapi_keycloak_middleware import FastAPIKeycloakMiddleware

app = FastAPI()
app.add_middleware(FastAPIKeycloakMiddleware, server_url="https://keycloak.example.com", client_id="my-app", realm="my-realm")

@app.get("/protected")
async def protected(request):
    return {"user": request.user}

Verify before relying

  • Whether the package supports fine-grained authorization via Keycloak Authorization services (mentioned as a future plan in the description).
  • Current state of the repository (archived status, commit history, community activity) to assess true maintenance health beyond release date.

Package facts

LicenseNot declared unclear
Python supportSupports the current Python release <4,>=3.11
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
fastapipython-keycloak
MaintenanceAging 215 days since the last release
First released
Downloads78,032 / month, #14,474 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Programming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14

Evidence: fastapi_keycloak_middleware-1.6.0-py3-none-any.whl

Tags

Capabilities
fastapi keycloak authenticationoidc middleware fastapikeycloak token validationrole-based access control fastapifastapi authorization decoratorkeycloak integration pythonfastapi identity provider
Topics
keycloakoidcrbac

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “fastapi keycloak authentication”

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also axioms-fastapi · python-keycloak · keystonemiddleware · pulumi-keycloak · fastapi-azure-auth · apache-airflow-providers-keycloak · aioauth · django-oidc-provider · propelauth-fastapi · dapr-ext-fastapi