python-keycloak
python-keycloak is a Python package providing access to the Keycloak API.
Decision gist · record as of 2026-08-14
Yes. The package is actively maintained, has low install friction, carries a permissive MIT license, and is widely used (top 5000 on PyPI). It directly solves Keycloak integration for Python applications. The 'Alpha' classifier is a minor concern given active development and no known vulnerabilities, but verify production readiness for your use case before committing to a critical auth path.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires a running Keycloak server instance; supports Keycloak versions 22.X through 26.X.
- Low friction install with six runtime dependencies.
- Actively maintained with a recent release; supports current Python versions (3.10–3.14) and tracks the latest five major Keycloak versions.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions; suitable for most projects.
last release 2026-02-15 (180 days) · last repo commit 2026-02-15 · 881 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 7,856,130 downloads/mo, #1,687 on PyPI
Alternatives
Verify before relying
pip install python-keycloak
from keycloak import KeycloakOpenID
keycloak_openid = KeycloakOpenID(
server_url="http://localhost:8080/auth/",
client_id="example_client",
realm_name="example_realm",
client_secret_key="secret"
)
token = keycloak_openid.token("user", "password")- Whether async support via aiofiles is fully integrated or only partially available.
- Current stability beyond 'Alpha' classification—whether the library is production-ready despite active maintenance.
What it is and what it does
python-keycloak is a Python client library for Keycloak, an open-source identity and access management platform. It exposes two main interfaces: KeycloakOpenID for OpenID Connect authentication workflows (token acquisition, user info retrieval, logout) and KeycloakAdmin for server-side administrative tasks (user creation, role management). The library wraps HTTP calls to Keycloak's REST API using requests and httpx, with support for both synchronous and asynchronous operations.
The package is designed for applications that need to integrate Keycloak for authentication or for administrators who want to automate user and realm management. It requires a Keycloak server to be running and supports the five most recent major versions, allowing teams to upgrade gradually. Dependencies include httpx, requests, requests-toolbelt for HTTP operations, jwcrypto for token handling, deprecation for API lifecycle management, and aiofiles for async file operations.
Use it for
- Integrate Keycloak OpenID Connect authentication into a Python web application for user login and token management.
- Automate user provisioning and role assignment in Keycloak from a Python backend service.
- Build a Python CLI tool to manage Keycloak realms, clients, and users without manual admin console access.
- Implement token refresh and logout flows in a Python API gateway or middleware.
- Exchange tokens between different Keycloak clients for service-to-service authentication.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
The package is actively maintained, has low install friction, carries a permissive MIT license, and is widely used (top 5000 on PyPI). It directly solves Keycloak integration for Python applications. The 'Alpha' classifier is a minor concern given active development and no known vulnerabilities, but verify production readiness for your use case before committing to a critical auth path.
Install
python-keycloak on PyPI
Before you install
Low friction install with six runtime dependencies. Actively maintained with a recent release; supports current Python versions (3.10–3.14) and tracks the latest five major Keycloak versions.
Requires a running Keycloak server instance; supports Keycloak versions 22.X through 26.X.
License in practice
MIT license permits commercial and private use with minimal restrictions; suitable for most projects.
Quickstart
pip install python-keycloak
from keycloak import KeycloakOpenID
keycloak_openid = KeycloakOpenID(
server_url="http://localhost:8080/auth/",
client_id="example_client",
realm_name="example_realm",
client_secret_key="secret"
)
token = keycloak_openid.token("user", "password")
Verify before relying
- Whether async support via aiofiles is fully integrated or only partially available.
- Current stability beyond 'Alpha' classification—whether the library is production-ready despite active maintenance.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release <4,>=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 6 packagesaiofilesdeprecationhttpxjwcryptorequestsrequests-toolbelt |
| Maintenance | Actively maintained 180 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 7,856,130 / month, #1,687 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaLicense :: OSI Approved :: MIT LicenseOperating System :: MacOSOperating System :: Microsoft :: WindowsOperating System :: UnixProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Topic :: Utilities |
Evidence: python_keycloak-7.1.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “keycloak admin api”
- python-keycloakProvides Python bindings to the Keycloak API, supporting both OpenID…
- pulumi-keycloakA Pulumi resource provider that lets you define and manage Keycloak…
- apache-airflow-providers-keycloakIntegrates Keycloak identity and access management with Apache…
Give your agent the search over MCP, or paste the wish link into any chat.
More Utilities packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Detects and normalizes text encoding from unknown or ambiguous sources, supporting all IANA character sets that Python's core library provides codecs for, with the ability to register custom codecs.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Pygments is a syntax highlighter that colorizes source code and text in over 500 languages and formats, outputting to HTML, LaTeX, RTF, SVG, images, or ANSI terminal sequences.
Install it if you need to display or transform source code.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
See also fastapi-keycloak-middleware · pyop · apache-airflow-providers-keycloak · django-oidc-provider · pulumi-keycloak · flask-oidc · oidc-provider-mock · oauth2-client · Authlib · hellosign-python-sdk