This release is a pre-release and may not be stable for production use.
FastAPI Keycloak Integration
Introduction
Welcome to fastapi-keycloak. This projects goal is to ease the integration of Keycloak (OpenID Connect) with Python, especially FastAPI. FastAPI is not necessary but is
encouraged due to specific features. Currently, this package supports only the password and the authorization_code. However, the get_current_user() method accepts any JWT
that was signed using Keycloak´s private key.
Installation
pip install fastapi_keycloak
Usage
from fastapi import FastAPI, Depends
from fastapi_keycloak import FastAPIKeycloak, OIDCUser
app = FastAPI()
idp = FastAPIKeycloak(
server_url="https://auth.some-domain.com/auth",
client_id="some-client",
client_secret="some-secret",
admin_client_secret="some-admin-cli-secret",
realm="some-realm-name",
callback_uri="http://localhost:8081/callback",
)
idp.add_swagger_config(app)
@app.get("/protected")
def protected(user: OIDCUser = Depends(idp.get_current_user())):
return f"Hi {user}"
If your service only needs to authenticate requests (no user/role/group management), use FastAPIKeycloakAuth
instead — it requires no admin_client_secret:
from fastapi_keycloak import FastAPIKeycloakAuth
idp = FastAPIKeycloakAuth(
server_url="https://auth.some-domain.com/auth",
client_id="some-client",
client_secret="some-secret",
realm="some-realm-name",
callback_uri="http://localhost:8081/callback",
)
FastAPIKeycloak extends FastAPIKeycloakAuth with the full admin API, so existing code keeps working unchanged.
Docs
Docs are available at https://fastapi-keycloak.readthedocs.io/.
TLDR
FastAPI Keycloak enables you to do the following things without writing a single line of additional code:
- Verify identities and roles of users with Keycloak
- Get a list of available identity providers
- Create/read/delete users
- Create/read/delete roles
- Create/read/delete/assign groups (recursive). Thanks to @fabiothz
- Assign/remove roles from users
- Implement the
passwordor theauthorization_codeflow (login/callback/logout)
Contributions
We would like encourage anyone using this package to contribute to its improvement, if anything isn't working as expected or isn't well enough documented, please open an issue or a pull request. Please note that for any code contribution tests are required. See AGENTS.md for the full contributor guide, including how to run the test suite, lint/format the code, and build the docs locally.
Original authors
Shoutout to the original authors of this project:
- Yannic Schröer @yannicschroeer
- Jonas Scholl @JonasScholl
This project was in the Code Specialist organization before being moved here.
Metadata
Release files for fastapi-keycloak 2.0.0rc1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fastapi_keycloak-2.0.0rc1.tar.gz | 21.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fastapi_keycloak-2.0.0rc1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 41.8 kB
Release files / fastapi_keycloak-2.0.0rc1.tar.gz
| Download URL | fastapi_keycloak-2.0.0rc1.tar.gz |
|---|---|
| Size | 21.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
08d6739987b8283fa663aae66cd92140848714a633af91bbd812115d5c7879bb
|
|
BLAKE2b-256 checksum How to use checksums |
ce5eea7cf491d6551966dbe373a9ae0445366b97d2105c9b902f2aaaa77a4371
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.
Transparency logRelease files / fastapi_keycloak-2.0.0rc1-py3-none-any.whl
| Download URL | fastapi_keycloak-2.0.0rc1-py3-none-any.whl |
|---|---|
| Size | 20.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0aad7161a2c4e5254eaa3f51fe55401c6d19814da988d51d7177b4e55a73a76f
|
|
BLAKE2b-256 checksum How to use checksums |
f37f35cba4955e72034a9a47f88e120cb802e4f27d0f38dab40cb5afc704f896
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.
Transparency log