Access Management Extensions

Extend Keycloak with Advanced Authentication

Enhance Keycloak with a collection of extensions that add modern authentication capabilities, improve the user experience, and simplify integration for both web and native applications.

Native app sign-in screen with Continue with Passkey

Get Started

Keycloak Advanced Authentication

Build seamless sign-in experiences without browser redirects. Applications communicate directly with Keycloak through a secure authentication API, allowing each sign-in step to be completed natively inside the app. In addition to native authentication, the extension pack provides advanced authentication features that extend Keycloak's built-in capabilities for both browser and native application experiences.

See It In Action

Secure Sign-In in Seconds

See how users can securely sign in with a single biometric confirmation. No passwords. No browser redirects. Just a fast, seamless experience.

1
App login screen with a Continue with Passkey button

Tap Continue with Passkey

2
Device biometric prompt asking the user to confirm with their fingerprint

Face ID / fingerprint

App home screen confirming the user is securely signed in

Signed in. Done.

Advanced Authentication Pack

Supported Authentication Mechanisms

Modern authentication options that integrate seamlessly with Keycloak for both browser and native applications. Each method can be used for sign-in, step-up authentication, or passwordless experiences, depending on your authentication flow.

Passkeys (WebAuthn)

Passwordless, phishing-resistant authentication using the device's built-in biometrics or a security key. Supports Touch ID, Face ID, Windows Hello, and FIDO2 security keys.

Browser ✓ Native ✓
OTP by SMS

One-time password delivered via SMS. Simple, widely supported, and compatible with any mobile device. Works for both primary login and step-up authentication scenarios.

Browser ✓ Native ✓
OTP by Email

One-time password delivered via email. No external SMS provider required. Ideal for users without reliable mobile access and for low-friction passwordless login flows.

Browser ✓ Native ✓
Trusted Devices

Securely register user devices so they can be recognized during future sign-ins. Device trust can be used to improve the user experience, reduce repeated verification, and support adaptive authentication policies.

Browser ✓ Native —

Native Authentication

Your App Controls the Sign-In Experience

Keep users inside your application from start to finish. Instead of redirecting users to a browser, the app guides them through each step using instructions provided by Keycloak. Whether users sign in with passkeys, email verification codes, or other authentication methods, the entire experience remains native, secure, and seamless.

Application controls the sign-in experience No browser redirects Authentication flow driven by Keycloak Works with any supported authenticator Built on open OAuth 2.0 standards
Show the full step-by-step flow
OAuth 2.0 Native Authentication FlowUserHumanApplicationControls the journeyIdentity ProviderDrives the flowloginAuth Request (API-native)no browser redirectStep Metadata { type, challenge, … }loop[per IdP-defined authentication step]Native UI Promptpasskey · OTP · biometric · …user completes stepStep ResponseNext Step OR authorization_codedirect token exchange — no redirectToken RequestAccess Token + ID Token ✓

Deploy the Extensions.

The Keycloak extensions are a library that includes several Service Provider Interfaces (SPIs) to enhance Keycloak's functionality.

  • Step 1: Download

    Download the extension pack from our private GitHub repository with an active subscription.

  • Step 2: Add the extensions

    Copy the extension JARs into your Keycloak installation and restart the server.

  • Step 3: Configure your journey

    Create your authentication flow using the authentication methods you need for browser applications, native applications, or both.

  • Ready!

Keycloak Advanced Authentication

Our authentication capabilities are continuously evolving to support the latest identity standards. We believe open standards are the foundation of secure, interoperable, and future-ready authentication, enabling organizations to adopt new technologies with confidence.