Gestion d'identité et SSO
Find a file
Giuseppe Graziano ed3fc2fcfb Fix duplicate address claim in IDToken (#45423)
Closes #45250

Signed-off-by: Giuseppe Graziano <g.graziano94@gmail.com>
(cherry picked from commit db1f75a1cf)
2026-01-15 11:02:31 +01:00
.github Bump github/codeql-action (#45141) 2026-01-05 13:04:59 +00:00
.idea Add Intellij project icon 2023-09-18 12:39:16 +02:00
.mvn Update custom Maven build cache configuration for js directory 2024-12-10 10:07:02 +00:00
adapters Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
authz Make sure group permissions on view scope are not processed when querying users 2025-12-08 14:39:40 +01:00
boms Add Spotless plugin with removeUnusedImports check enabled 2025-10-13 13:32:01 +02:00
common Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
core Fix duplicate address claim in IDToken (#45423) 2026-01-15 11:02:31 +01:00
crypto Removing SdJwtFacade 2025-11-27 14:19:27 +01:00
dependencies Add missing artifact descriptions to allow Maven Central Portal Publisher pass validation process. (#40822) 2025-08-12 16:50:17 +02:00
distribution Apply Spotless to docs, distribution, and operator (#44826) 2025-12-11 08:50:54 +01:00
docs Clarify documentation. 2026-01-13 16:23:29 -03:00
federation Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
integration Javadoc of Keycloak-admin-client for Keycloak server 26.5 release 2026-01-08 08:59:43 +01:00
js fix(admin-ui): admin events for dedicated user now show all user related events (#45333) (#45414) 2026-01-14 10:41:19 -03:00
misc Avoid un-escaped strings in the login templates for HTML entities 2025-11-26 07:55:35 -03:00
model Fix charset of ORG.ID for mysql/mariadb 2026-01-13 07:12:25 -03:00
operator fix: updating test crdtest expectation 2025-12-19 08:15:12 +01:00
quarkus fix: changing how scripts are loaded from the classpath (#45358) (#45399) 2026-01-14 08:12:27 +01:00
rest [admin-api-v2] Incorrect DTO/DAO mapping (#44587) 2025-12-03 09:41:18 +01:00
saml-core Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
saml-core-api Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
server-spi Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
server-spi-private Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
services Fix duplicate address claim in IDToken (#45423) 2026-01-15 11:02:31 +01:00
test-framework Use MIME decoder instead of the default one to replace deprecated Base64 class (#45325) 2026-01-11 17:29:34 +01:00
tests Allow admins with any admin role to map roles if the constraints apply 2026-01-13 13:49:48 +01:00
testsuite Fix duplicate address claim in IDToken (#45423) 2026-01-15 11:02:31 +01:00
themes Remove unnecessary closing div in webauthn-authenticate template 2026-01-09 19:06:00 +00:00
util Remove log4j 1.x from util/embedded-ldap (#44806) 2025-12-10 16:02:55 +01:00
.editorconfig Proposed import order (#43432) 2025-11-14 09:34:49 +01:00
.gitattributes Use lf as line-ending for sh files 2022-07-19 08:57:57 +02:00
.gitignore [OID4VCI] Credential Offer must be created by Issuer not Holder (#44255) 2025-11-27 16:07:10 +01:00
.gitleaks.toml Updated .gitleaks.toml to ignore false positive in RedirectUtilsTest (#33346) 2024-09-27 14:32:36 +02:00
ADOPTERS.md Add Xata to ADOPTERS.md (#40802) 2025-06-30 19:32:32 +02:00
CONTRIBUTING.md Add Spotless plugin with removeUnusedImports check enabled 2025-10-13 13:32:01 +02:00
get-version.sh Use Maven wrapper instead of platform dependent Maven version (#29988) 2024-06-03 15:45:39 +02:00
GOVERNANCE.md Update governance model around changes in maintainership (#29292) 2024-05-22 08:24:10 +02:00
LICENSE.txt Added text version of ASL2 license 2019-11-08 12:43:10 +01:00
MAINTAINERS.md Add Steven Hawkins as a maintainer (#45144) 2026-01-05 16:32:14 +01:00
maven-settings.xml [KEYCLOAK-11764] Upgrade to Wildfly 19 2020-04-24 08:19:43 -03:00
mvnw Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
mvnw.cmd Upgrade Maven and wrapper to latest version 2024-06-19 10:42:33 +02:00
pom.xml fix: updating owasp.html.sanitizer.version to addresss CVE-2025-66021 2026-01-05 08:53:00 +01:00
PR-CHECKLIST.md Introduce CODEOWNERS (#16637) 2023-01-30 13:05:45 +01:00
README.md Add CLOMonitor Badge to the README 2025-02-20 12:31:58 -03:00
SECURITY-INSIGHTS.yml Provide an OpenSSF security insights manifest file 2024-02-15 11:02:33 -03:00
set-version.sh Remove Keycloak JS from repository (#37057) 2025-02-12 16:31:21 +00:00

Keycloak

GitHub Release OpenSSF Best Practices CLOMonitor OpenSSF Scorecard Artifact Hub GitHub Repo stars GitHub commit activity Translation status

Open Source Identity and Access Management

Add authentication to applications and secure services with minimum effort. No need to deal with storing users or authenticating users.

Keycloak provides user federation, strong authentication, user management, fine-grained authorization, and more.

Help and Documentation

Reporting Security Vulnerabilities

If you have found a security vulnerability, please look at the instructions on how to properly report it.

Reporting an issue

If you believe you have discovered a defect in Keycloak, please open an issue. Please remember to provide a good summary, description as well as steps to reproduce the issue.

Getting started

To run Keycloak, download the distribution from our website. Unzip and run:

bin/kc.[sh|bat] start-dev

Alternatively, you can use the Docker image by running:

docker run quay.io/keycloak/keycloak start-dev

For more details refer to the Keycloak Documentation.

Building from Source

To build from source, refer to the building and working with the code base guide.

Testing

To run tests, refer to the running tests guide.

Writing Tests

To write tests, refer to the writing tests guide.

Contributing

Before contributing to Keycloak, please read our contributing guidelines. Participation in the Keycloak project is governed by the CNCF Code of Conduct.

Joining a community meeting is a great way to get involved and help shape the future of Keycloak.

Other Keycloak Projects

License