# Have I Been Pwned + Keycloak — Pipedream Connect

> Connect a user's Have I Been Pwned and Keycloak accounts and expose tools for both apps directly in your product or your agent.

- Apps: Have I Been Pwned (`have_i_been_pwned`) + Keycloak (`keycloak`)
- This page (HTML): https://pipedream.com/apps/have-i-been-pwned/integrations/keycloak
- One `external_user_id` owns both connected accounts, and each account stays independently revocable.

## One session, both toolsets (recommended)

- Endpoint: `https://remote.mcp.pipedream.net/v3`
- Headers: `Authorization: Bearer <token>` · `x-pd-project-id` · `x-pd-environment` · `x-pd-external-user-id` · `x-pd-app-slug: have_i_been_pwned,keycloak`
- `x-pd-app-slug` takes a comma-separated list, so `have_i_been_pwned,keycloak` is one session on one transport. Both toolsets arrive from a single `listTools()`, and a tool is called exactly as it would be in a single-app session.

```ts
import { Client } from "@modelcontextprotocol/sdk/client/index.js"
import { StreamableHTTPClientTransport } from "@modelcontextprotocol/sdk/client/streamableHttp.js"
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const accessToken = await pd.rawAccessToken

const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": process.env.PIPEDREAM_PROJECT_ID!,
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "have_i_been_pwned,keycloak",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// One list, both toolsets: Have I Been Pwned and Keycloak tools arrive
// together, each keyed by its own app's slug.

// e.g. run Create User:
const result = await mcp.callTool({
  name: "keycloak-create-user",
  arguments: {
    realm: "Realm",
    username: "Username",
  },
})
```

Docs: [MCP guide](https://pipedream.com/docs/connect/mcp/developers.md)

## Both apps from your backend

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const externalUserId = "{external_user_id}" // any stable ID for this user in your system

const [haveIBeenPwnedTools, keycloakTools] =
  await Promise.all([
    pd.components.list({ app: "have_i_been_pwned" }),
    pd.components.list({ app: "keycloak" }),
  ])

// One external user owns both connected accounts, so either app's tools
// run on their behalf with the same externalUserId.
```

Docs: [Managed auth guide](https://pipedream.com/docs/connect/managed-auth/quickstart.md) · [Tools guide](https://pipedream.com/docs/connect/components.md)

## Have I Been Pwned

- API slug: `have_i_been_pwned` (use in MCP headers and tool keys)
- Auth: API key (Pipedream-managed)
- Categories: Data Analytics
- Website: https://haveibeenpwned.com/
- App page (HTML): https://pipedream.com/apps/have-i-been-pwned
- Tools: 0 actions · 0 triggers

Full tool list, API proxy, and SDK quickstart: https://pipedream.com/apps/have-i-been-pwned.md

## Keycloak

- API slug: `keycloak` (use in MCP headers and tool keys)
- Auth: OAuth (Pipedream-managed)
- Categories: Infrastructure & Cloud
- Website: https://www.keycloak.org/
- App page (HTML): https://pipedream.com/apps/keycloak
- Tools: 5 actions · 1 trigger

Full tool list, API proxy, and SDK quickstart: https://pipedream.com/apps/keycloak.md

### Actions (5)

- [Create User](https://pipedream.com/apps/keycloak/actions/create-user.md) — `keycloak-create-user`
- [Delete User](https://pipedream.com/apps/keycloak/actions/delete-user.md) — `keycloak-delete-user`
- [Get User](https://pipedream.com/apps/keycloak/actions/get-user.md) — `keycloak-get-user`
- [List Realm Options](https://pipedream.com/apps/keycloak/actions/list-realm-options.md) — `keycloak-list-realm-options`
- [Update User](https://pipedream.com/apps/keycloak/actions/update-user.md) — `keycloak-update-user`

### Triggers (1)

- [New Event Created](https://pipedream.com/apps/keycloak/triggers/new-event-created.md) — `keycloak-new-event-created`

---

- Have I Been Pwned: https://pipedream.com/apps/have-i-been-pwned.md · Keycloak: https://pipedream.com/apps/keycloak.md
- All apps: https://pipedream.com/apps — index: https://pipedream.com/llms.txt
- Pipedream docs for agents: https://pipedream.com/docs/llms.txt
