Upgrade to Pro — share decks privately, control downloads, hide ads and more …

What Is New and Coming for Managing Cloud-Nativ...

What Is New and Coming for Managing Cloud-Native Identities in Keycloak

Identities are the key to accessing applications and their data, and Keycloak is a leading tool to meet the needs of the cloud-native ecosystem.

This talk highlights how to use the features Keycloak already supports, what’s new, and what we are working on.

This ranges from machine identities and how to leverage SPIFFE/SPIRE or Kubernetes service account tokens, authenticating humans with strong authentication like Passkeys, or synchronizing user and groups across domains and applications via SCIM.

Join this session to see hear about Keycloak's features and how they can help you building a capable cloud-native platform for your organization!

Avatar for Alexander Schwartz

Alexander Schwartz PRO

July 26, 2026

More Decks by Alexander Schwartz

Other Decks in Technology

Transcript

  1. What Is New and Coming for Managing Cloud-Native Identities in

    Keycloak Alexander Schwartz | Keycloak Maintainer KeycloakCon (Yokohama, JP) | 2026-07-28
  2. Making Keycloak great for human users 🔑 Seamless Passkeys, and

    how to recover when you lose your phone New in 26.4: Fully supported; with enhancements in each release ⚙ Automate all stages of the user lifecycle management with workflows New in 26.6: Fully supported, and you can extend it with your own workflow steps 🗂 SCIM to pre-provision users and groups SCIM service is preview in 26.7 ⛱ Delegate administration access to resource owners New in 26.6: Delegate managing organizations Plus EUID Wallet (OID4VCI, OID4VP), …
  3. AI and autonomous workloads as first-class citizens 🔑 Zero-Trust ephemeral

    credentials for machines JWT Authorization Grant to leverage SPIFFE, Kubernetes Service Account Tokens ⚙ Token Exchange to capture the user and the agent Fully supported since 26.2, with delegation in the works (#38279) 🛂 AuthZEN to use Keycloak as a PDP Experimental in 26.7, and we would love to see feedback on this one 🛑 Shared Signals emit notifications on changed credentials and ended sessions Experimental in 26.7: Use it to terminate autonomous agent activities Plus MCP, CIMD, ID-JAG, parameterized scopes, …
  4. Simpler life for admins ♻ Split-brain detection, rolling updates, proxy

    blueprints Rolling updates patches in 26.6, also graceful shutdown. 26.7 added proxy blueprints. 🔑 Simplified import of Kubernetes cluster certificates Automatically picked up since 26.6 by the image 💫 Stateless feature for simpler multi-cluster setups Multiple Keycloak clusters connect only via a shared database for HA (26.7 preview) 🔭 OpenTelemetry everywhere 26.1 added tracing (supported), 26.5 added logging (experimental) and metrics (preview)