CONNECT APP
Build with Keycloak
Infrastructure & Cloud
- OAuth
MCP
Give your agent Keycloak tools
Every Keycloak action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Keycloak account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "keycloak",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run Create User:
const result = await mcp.callTool({
name: "keycloak-create-user",
arguments: {
realm: "Realm",
username: "Username",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "keycloak",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run Create User:
result = await session.call_tool("keycloak-create-user", {
"realm": "Realm",
"username": "Username",
})API PROXY
Call the Keycloak API directly
For an endpoint with no pre-built tool, the Connect proxy forwards your request to the Keycloak API with the connected user's credentials attached. You store no tokens and write no refresh logic.
const resp = await pd.proxy.get({
externalUserId: "{external_user_id}", // any stable ID for this user in your system
accountId: "apn_xxxxxxx",
url: "https://api.example.com/v1/me",
})
// Any allowed Keycloak endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.# The path segment is the target URL, URL-safe base64 encoded:
# https://api.example.com/v1/me
curl "https://api.pipedream.com/v1/connect/{project_id}/proxy/aHR0cHM6Ly9hcGkuZXhhbXBsZS5jb20vdjEvbWU?external_user_id={external_user_id}&account_id=apn_xxxxxxx" \
-H "Authorization: Bearer {access_token}" \
-H "x-pd-environment: production"SDK
Run Keycloak actions from your backend
Connect a user's Keycloak account once, then run Create User on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "keycloak-create-user",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
keycloak: { authProvisionId: "apn_xxxxxxx" },
realm: "Realm",
username: "Username",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="keycloak-create-user",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"keycloak": {"authProvisionId": "apn_xxxxxxx"},
"realm": "Realm",
"username": "Username",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "keycloak-create-user",
"configured_props": {
"keycloak": { "authProvisionId": "apn_xxxxxxx" },
"realm": "Realm",
"username": "Username"
}
}'TOOLS
Keycloak actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
Create User
actionCreate a new user in Keycloak. The username must be unique. See the documentationWritev0.0.2 -
Delete User
actionDelete a user from Keycloak. See the documentationWritev0.0.2 -
Get User
actionRetrieve the representation of the user. See the documentationRead-onlyv0.0.2 -
List Realm Options
actionRetrieves available options for the Realm field.Read-onlyv0.0.1 -
Update User
actionUpdates a user in Keycloak. See the documentationWritev0.0.2
EVENTS
Keycloak triggers
Event sources your backend can deploy for users and receive through a webhook.
MULTI-APP
Use Keycloak with other popular apps
Most products don't stop at one integration. Pair Keycloak with the other apps your users rely on, and ship use cases that span both.
- App slug
- keycloak
- Authentication
- OAuth
- Categories
- Infrastructure & Cloud
- Actions
- 5
- Triggers
- 1
- API proxy
- Available