Keycloak
Keycloak
Beginner
Q1: What is Keycloak?
Keycloak is an open-source identity and access management solution for modern applications and services.
Q2: Why use Keycloak?
It centralizes authentication, authorization, user management, and federation for applications.
Q3: What is identity management?
Identity management is the process of managing users, credentials, identity attributes, roles, and access.
Q4: What is authentication?
Authentication is the process of verifying who a user is.
Q5: What is authorization?
Authorization decides what an authenticated user is allowed to do.
Q6: What is OAuth 2.0?
OAuth 2.0 is a delegated authorization framework that allows an app to access a resource on behalf of a user.
Q7: What is OpenID Connect (OIDC)?
OIDC is an identity layer built on top of OAuth 2.0. It adds authentication and user identity information.
Q8: What is a realm in Keycloak?
A realm is a logical space where users, clients, roles, and groups are managed.
Q9: Why are realms useful?
They allow separation between environments, tenants, or application domains.
Q10: What is a user in Keycloak?
A user is an identity that can log in and receive tokens or access resources.
Q11: What is a client in Keycloak?
A client is an application or service that delegates authentication or authorization to Keycloak.
Q12: What is a client ID?
A client ID identifies the client application in Keycloak.
Q13: What is a client secret?
A client secret is a credential used by confidential clients to authenticate to Keycloak.
Q14: What is a public client?
A public client runs on the frontend and does not have a secret, such as a SPA.
Q15: What is a confidential client?
A confidential client can securely hold credentials such as a client secret, such as a backend server.
Q16: What is a role?
A role defines permissions or groups of permissions that can be assigned to users or clients.
Q17: What is a realm role?
A realm role applies within a realm.
Q18: What is a client role?
A client role applies to a specific client application.
Q19: What is a user role?
A user role is a role assigned to a particular user.
Q20: What is a group in Keycloak?
A group is a collection of users that can share common roles and attributes.
Q21: Why are groups useful?
They simplify permission assignment across many users.
Q22: What is a federated identity?
A federated identity refers to users or identities coming from an external identity provider or directory.
Q23: What is identity brokering?
Identity brokering lets Keycloak delegate authentication to external providers like Google, GitHub, or LDAP.
Q24: What is SSO?
SSO (Single Sign-On) allows the same login to work across multiple applications.
Q25: Why use SSO?
It reduces repeated logins and centralizes identity management.
Q26: What is an access token?
An access token is a token presented to a resource server to authorize a request.
Q27: What is an ID token?
An ID token contains user identity claims as part of OIDC.
Q28: What is a refresh token?
A refresh token allows a client to get a new access token without re-authenticating the user.
Q29: What is a token claim?
A token claim is a piece of data embedded in the token, such as sub, email, or role.
Q30: What is JWT?
JWT (JSON Web Token) is a compact, self-contained token format used by OAuth/OIDC.
Q31: What is a signing key?
A signing key is used to sign tokens produced by Keycloak.
Q32: What is token validation?
Token validation checks whether a token is valid, signed correctly, and still active.
Q33: What is a user session?
A user session represents an authenticated user session in Keycloak.
Q34: What is a logout flow?
Logout invalidates a user session and tokens, ending the authentication context.
Q35: What is the Keycloak admin console?
The Keycloak admin console provides a UI for managing realms, users, roles, clients, and policies.
Q36: What is Keycloak theme?
A Keycloak theme customizes the look and feel of login pages and admin pages.
Q37: Why use Keycloak themes?
To match the brand and user experience of your application.
Q38: What is an authentication flow?
An authentication flow is a sequence of steps that a user must complete to log in.
Q39: What is a browser flow?
A browser flow is the sequence used for login in a browser-based app.
Q40: What is a direct grant flow?
A direct grant flow is used for username/password authentication to obtain tokens directly.
Q41: Why avoid direct grant in production for browser apps?
Because it is less appropriate for browser apps and often better replaced by OIDC flows like Authorization Code + PKCE.
Q42: What is Authorization Code Flow?
Authorization Code Flow is a browser-based OIDC flow where the client receives an auth code and exchanges it for tokens.
Q43: What is PKCE?
PKCE (Proof Key for Code Exchange) prevents authorization code interception and is recommended for public clients.
Q44: What is implicit flow?
Implicit flow was an older OAuth flow for browser apps, but it is discouraged in modern security design.
Q45: What is client credentials flow?
Client Credentials Flow is used for machine-to-machine authentication where no user context is involved.
Q46: What is password grant?
Password grant is an older OAuth flow for obtaining tokens using user credentials directly from the client.
Q47: Why is password grant often discouraged?
It requires the client to handle user credentials and is less secure than more modern flows.
Q48: What is a resource server?
A resource server protects APIs and validates access tokens.
Q49: What is a protected API?
A protected API requires valid access tokens before serving requests.
Q50: What is a scope?
A scope is a permission or claim group that a client may request from the user.
Q51: What is a permission?
Permission is a granted right to access a resource or action.
Q52: What is a policy in Keycloak?
A policy defines conditions under which a permission is granted.
Q53: What is authorization in Keycloak?
Keycloak can enforce fine-grained permissions on resources and actions via UMA or policies.
Q54: What is UMA?
UMA (User-Managed Access) allows users to manage access to resources and permissions.
Q55: What is a resource in Keycloak?
A resource is something protected by authorization policies, like an API or feature.
Q56: What is an audience?
An audience identifies the intended recipient of a token, usually the API or resource server.
Q57: What is a JWT claim `aud`?
`aud` tells the recipient which resource the token is for.
Q58: What is a JWT claim `iss`?
`iss` is the issuer of the token.
Q59: What is a JWT claim `sub`?
`sub` is the subject, usually the user identifier.
Q60: What is a JWT claim `exp`?
`exp` is the expiration time of the token.
Q61: Why does Keycloak use signed tokens?
To ensure authenticity and integrity of token data.
Q62: What is a public key?
A public key is used by clients and resource servers to validate token signatures.
Q63: What is a private key?
A private key is used by the identity provider to sign tokens.
Q64: What is Keycloak adapter?
A Keycloak adapter is a library that makes integrating applications with Keycloak easier.
Q65: What is the Keycloak JavaScript adapter?
It helps browser SPAs or frontend apps integrate with Keycloak using OIDC.
Q66: What is a frontend app login flow?
Usually an OIDC Authorization Code flow with PKCE for browser applications.
Q67: What is a backend app login flow?
Usually a confidential client using client credentials or authorization code flow with a server-side session.
Q68: What is a custom identity provider?
A custom identity provider is a custom external auth system integrated into Keycloak.
Q69: What is Keycloak federation?
Federation allows Keycloak to connect to LDAP, Active Directory, or other identity stores.
Q70: What is a social login?
A social login uses a third-party identity provider such as GitHub, Google, or Facebook.
Q71: What is a login page?
A login page is the UI where users authenticate to Keycloak.
Q72: What is a registration page?
A registration page allows new users to create accounts.
Q73: What is password policy?
A password policy defines minimum password length, complexity, or expiration requirements.
Q74: Why use password policies?
To reduce the risk of weak or reused credentials.
Q75: What is account console?
Account console is the user-facing UI where a user can manage their profile, sessions, and credentials.
Q76: What is a user attribute?
A user attribute stores profile data like email, phone, or custom fields.
Q77: What is a mapper?
A mapper translates identity data from the external provider or source into Keycloak user attributes or token claims.
Q78: Why are mappers important?
Because they map identity information from external sources into claims used by applications.
Q79: What is a consent screen?
A consent screen asks the user to approve the application’s access to their identity and profile information.
Q80: What is user consent?
User consent is the permission granted by the user to share identity data with a client application.
Q81: What is a resource ownership model?
It defines who owns or manages access to a particular resource.
Q82: What is a session timeout?
A session timeout is the period after which an inactive user session expires.
Q83: Why are session timeouts useful?
They reduce the risk of stale or forgotten sessions.
Q84: What is a brute-force detection?
Brute-force detection detects repeated failed login attempts and may temporarily block access.
Q85: Why use brute-force protection?
To reduce password guessing and unauthorized access attempts.
Q86: What is a login theme?
A login theme customizes the UI used for authentication screens.
Q87: Why might a team customize the Keycloak UI?
To align with corporate branding or a product-specific experience.
Q88: What is Keycloak `docker-compose`?
It is a common way to run Keycloak in development or small deployments with Docker Compose.
Q89: What is Keycloak `realm-export`?
It exports realm configuration to a JSON file for backup or migration.
Q90: What is a Keycloak import?
Importing a realm restores the configuration into a new Keycloak instance.
Q91: What is admin REST API?
The admin REST API lets automation manage realms, users, clients, and flows.
Q92: Why use the admin API?
Because it enables automation and infrastructure-as-code for identity configuration.
Q93: What is a realm JSON file?
A realm JSON file contains the realm definition and configuration.
Q94: Why use infrastructure as code for Keycloak?
Because it makes identity configuration reproducible and version-controlled.
Q95: What is a Keycloak realm role assignment?
It assigns a role to a user or group within a realm.
Q96: What is a client role mapping?
It assigns a role to a user or group within a specific client.
Q97: What is a user claim?
A claim is data inside a token that identifies or describes a user, such as email or groups.
Q98: What is a group claim?
A group claim includes group membership information in tokens.
Q99: Why use group claims?
Because applications can enforce authorization based on group membership.
Q100: What is a user profile?
A user profile is the set of attributes and metadata associated with a user.
Intermediate
Q101: What is OIDC Discovery document?
The discovery document provides metadata about the OIDC provider, including issuer and token endpoints.
Q102: What is well-known configuration?
It is the standard `/.well-known/openid-configuration` endpoint.
Q103: What is OAuth 2.0 Authorization Code Flow with PKCE?
It is the recommended flow for browser apps and public clients.
Q104: Why is PKCE recommended for SPAs?
Because SPAs cannot securely keep a client secret and are exposed in the browser.
Q105: What is token exchange?
Token exchange is the process of exchanging one token for another token with different claims or audience.
Q106: What is an identity token vs access token?
ID token describes user identity. Access token authorizes access to APIs.
Q107: What is refresh token rotation?
Refresh rotation ensures a token cannot be reused indefinitely and improves security.
Q108: What is token revocation?
Token revocation invalidates a token before its expiration time.
Q109: Why use revocation?
To quickly shut down a token if it is suspected to be compromised.
Q110: What is logout and token invalidation?
Logout ends the user session and often invalidates access and refresh tokens.
Q111: What is session management?
It manages the active user sessions, their validity, and timeouts.
Q112: What is an identity provider alias?
It is the name Keycloak uses to reference an external provider.
Q113: What is social login integration?
It connects Keycloak to external identity providers such as Google or GitHub.
Q114: What is LDAP integration?
LDAP integration allows Keycloak to authenticate users against an enterprise directory.
Q115: What is Active Directory integration?
Keycloak can integrate with Microsoft Active Directory or AD FS for enterprise identity.
Q116: What is an identity broker?
An identity broker routes authentication requests to configured external identity providers.
Q117: What is a custom login flow?
It is a custom sequence of authentication actions for a realm or client.
Q118: What is a first broker login flow?
It is the login flow used when a user logs in with an external identity provider for the first time.
Q119: What is a required action?
A required action is an additional step a user must complete after login, such as password update or profile verification.
Q120: What is a password update action?
It prompts the user to change or confirm a password.
Q121: What is a user profile provider?
It defines the attributes and validation rules for user profiles.
Q122: What is user federation?
User federation connects Keycloak to an external user store.
Q123: Why use federation?
To avoid duplicating user identities in multiple systems.
Q124: What is a realm role mapping?
It assigns a realm role to a user or group.
Q125: What is a client scope?
A client scope allows a client to request a set of claims or roles in an access token.
Q126: Why use client scopes?
Because applications often need specific token claims or roles without polluting all tokens.
Q127: What is a protocol mapper?
A protocol mapper transforms user data into a JWT claim or OIDC claim.
Q128: What is a built-in protocol mapper?
A built-in mapper, like `group-membership` or `email`, automatically adds common claims.
Q129: What is a custom protocol mapper?
A custom mapper adds app-specific claims to tokens.
Q130: What is a user info endpoint?
The user info endpoint returns user identity information to authorized clients.
Q131: What is a token introspection endpoint?
It lets resource servers validate token validity and metadata.
Q132: What is a revocation endpoint?
It allows clients or systems to revoke tokens.
Q133: What is a JWK set?
A JWK set contains public keys used to validate JWT signatures.
Q134: Why do resource servers fetch JWKs?
Because they need the public keys to verify JWT signatures.
Q135: What is TLS?
TLS secures traffic between clients, Keycloak, and APIs.
Q136: Why is TLS important for Keycloak?
Because identity data, tokens, and secrets must be protected in transit.
Q137: What is a secure cookie?
A secure cookie is used to store session-related info and should only be transmitted over HTTPS.
Q138: What is a SameSite cookie?
A SameSite cookie restricts when a browser sends cookies to third-party sites.
Q139: Why is cookie security important?
Because session hijacking or CSRF attacks may use cookies if not protected properly.
Q140: What is CSRF?
CSRF (Cross-Site Request Forgery) is a web attack where a malicious site tricks a browser into making authenticated requests.
Q141: What is a logout redirect URI?
It is the URL the user is redirected to after logout.
Q142: What is a redirect URI?
It is the callback URI used by OAuth/OIDC after login.
Q143: Why is redirect URI validation important?
Because redirect URIs are a common OAuth security check and must match exactly or appropriately.
Q144: What is a trusted client?
A trusted client is expected to handle security and identity correctly.
Q145: What is a public client redirect issue?
A public client cannot safely keep a secret and must use flows like PKCE.
Q146: What is a confidential client redirect issue?
Confidential clients can use server-side secure credential storage.
Q147: What is an authorization server?
An authorization server issues tokens and manages identity and authorization decisions.
Q148: What is a resource owner?
A resource owner is the person or system that owns the protected resource.
Q149: What is delegated authorization?
Delegated authorization means an app acts on behalf of a user with their consent.
Q150: What is client configuration?
Client configuration includes redirect URIs, grant types, scopes, and credentials.
Q151: What is an audience claim in API tokens?
It tells the API which client or resource should accept the token.
Q152: What is an access token audience mismatch?
It happens when the API expects a different audience than the token provides.
Q153: Why is audience validation important?
Because otherwise an API might accept a token meant for another service.
Q154: What is Keycloak multi-tenancy?
It is the support for multiple isolated realms or clients in the same deployment.
Q155: What is realm isolation?
Realm isolation keeps users, roles, and clients separate between realms.
Q156: Why is realm isolation useful?
It supports separate domains, tenants, or business units.
Q157: What is a user federation mapper?
It maps external user attributes or groups into Keycloak identity information.
Q158: What is an event listener?
An event listener can react to login, logout, or registration events.
Q159: Why use event listeners?
To trigger audits, metrics, or external notifications.
Q160: What is a theme provider?
A theme provider allows custom pages or styling for authentication flows.
Q161: What is a realm export or import strategy?
It is how a realm configuration is moved between environments or instances.
Q162: Why is version control important for Keycloak config?
Because identity configs can drift over time without proper governance.
Q163: What is a default role?
A default role is assigned to every user or group automatically.
Q164: Why use default roles?
To avoid repetitive role mapping for common access.
Q165: What is a composite role?
A composite role contains other roles and can simplify permissions.
Q166: Why use composite roles?
They make role management easier and more scalable.
Q167: What is feature flag or preview feature?
Keycloak includes some experimental features behind configuration flags.
Q168: What is a `client-scopes` configuration?
It defines which claims and roles are included by default in tokens for clients.
Q169: What is fine-grained authorization?
It allows detailed permissions per resource, action, and user or policy.
Q170: What is an authorization policy?
It combines conditions and permissions to decide who can access a resource.
Q171: What is a permission ticket?
A permission ticket is part of UMA flows and represents a request for access to a resource.
Q172: What is an UMA flow?
It allows resource owners to manage and grant access to resources.
Q173: What is realm-level security?
It ensures security controls and login settings are applied consistently within a realm.
Q174: Why is Keycloak valuable for enterprise identity?
Because it supports federation, roles, SSO, MFA, and policy enforcement across many apps.
Q175: What is a group membership claim?
It contains the user’s group memberships in a token.
Q176: Why does authorization often rely on claims?
Because resource servers can make decisions based on roles, scopes, or group claims.
Q177: What is a token audience mismatch error?
It means the API is rejecting a token because it is not meant for that service.
Q178: Why handle tokens carefully in APIs?
Because they are security-sensitive and often grant access to protected actions.
Q179: What is a login redirect with `code`?
The browser receives an authorization code and exchanges it for tokens in the backend.
Q180: What is the relationship between Keycloak and OAuth/OIDC?
Keycloak implements both OAuth 2.0 and OIDC and acts as an identity provider and authorization server.
Advanced / Expert
Q181: What is multi-factor authentication (MFA)?
MFA requires more than one factor, such as password and TOTP, to authenticate.
Q182: Why is MFA important?
It reduces the chance of account compromise even if a password is stolen.
Q183: What is OTP?
OTP (One-Time Password) is a transient code often generated via TOTP or HOTP.
Q184: What is TOTP?
TOTP (Time-based One-Time Password) is a common MFA method.
Q185: What is WebAuthn?
WebAuthn is a passkey or FIDO-based authentication mechanism that avoids static secrets.
Q186: Why is WebAuthn important?
It provides stronger user authentication and better phishing resistance.
Q187: What is passkey?
A passkey is a passwordless or FIDO-based credential stored on a device.
Q188: What is a custom authenticator?
A custom authenticator can implement special authentication logic or enforce custom user checks.
Q189: What is a required action provider?
It enforces an action after login, such as password update, email verification, or profile completion.
Q190: What is a custom identity provider SPI?
SPI (Service Provider Interface) allows custom logic for identity or protocol features.
Q191: What is an event listener SPI?
It enables integration with external systems when significant authentication or account events occur.
Q192: What is a custom theme provider?
It allows custom UI and behavior at the Keycloak authentication boundary.
Q193: What is a User Storage SPI?
It enables custom user storage integration, including databases or external directories.
Q194: Why use custom user storage?
For integrating with legacy or non-standard identity systems.
Q195: What is policy enforcement in Keycloak?
It decides whether a request to a resource is allowed based on the user, resource, and rules.
Q196: What is an UMA resource permission ticket?
It is the request object that a client creates when asking for a permission.
Q197: What is a Keycloak admin event?
It is an event tracking administrative actions like user creation or client configuration changes.
Q198: What is an account event?
It is a user-related event such as login, logout, or failed authentication.
Q199: What is the core security principle behind Keycloak?
Keycloak centralizes identity, strongly enforces protocols like OAuth/OIDC, and reduces per-application security complexity.
Q200: What is the single most important lesson about Keycloak?
The real value of Keycloak is not just login pages; it is centralized identity, strong token handling, policy enforcement, and scalable user management across many applications.