Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

FastAPI Keycloak Integration

Py3.10 Py3.11 Py3.12 Py3.13

Introduction

Welcome to fastapi-keycloak. This projects goal is to ease the integration of Keycloak (OpenID Connect) with Python, especially FastAPI. FastAPI is not necessary but is encouraged due to specific features. Currently, this package supports only the password and the authorization_code. However, the get_current_user() method accepts any JWT that was signed using Keycloak´s private key.

Installation

pip install fastapi_keycloak

Usage

from fastapi import FastAPI, Depends
from fastapi_keycloak import FastAPIKeycloak, OIDCUser

app = FastAPI()
idp = FastAPIKeycloak(
    server_url="https://auth.some-domain.com/auth",
    client_id="some-client",
    client_secret="some-secret",
    admin_client_secret="some-admin-cli-secret",
    realm="some-realm-name",
    callback_uri="http://localhost:8081/callback",
)
idp.add_swagger_config(app)


@app.get("/protected")
def protected(user: OIDCUser = Depends(idp.get_current_user())):
    return f"Hi {user}"

If your service only needs to authenticate requests (no user/role/group management), use FastAPIKeycloakAuth instead — it requires no admin_client_secret:

from fastapi_keycloak import FastAPIKeycloakAuth

idp = FastAPIKeycloakAuth(
    server_url="https://auth.some-domain.com/auth",
    client_id="some-client",
    client_secret="some-secret",
    realm="some-realm-name",
    callback_uri="http://localhost:8081/callback",
)

FastAPIKeycloak extends FastAPIKeycloakAuth with the full admin API, so existing code keeps working unchanged.

Docs

Docs are available at https://fastapi-keycloak.readthedocs.io/.

TLDR

FastAPI Keycloak enables you to do the following things without writing a single line of additional code:

  • Verify identities and roles of users with Keycloak
  • Get a list of available identity providers
  • Create/read/delete users
  • Create/read/delete roles
  • Create/read/delete/assign groups (recursive). Thanks to @fabiothz
  • Assign/remove roles from users
  • Implement the password or the authorization_code flow (login/callback/logout)

Contributions

We would like encourage anyone using this package to contribute to its improvement, if anything isn't working as expected or isn't well enough documented, please open an issue or a pull request. Please note that for any code contribution tests are required. See AGENTS.md for the full contributor guide, including how to run the test suite, lint/format the code, and build the docs locally.

Original authors

Shoutout to the original authors of this project:

  • Yannic Schröer @yannicschroeer
  • Jonas Scholl @JonasScholl

This project was in the Code Specialist organization before being moved here.

Metadata

Release files for fastapi-keycloak 2.0.0rc1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for fastapi-keycloak 2.0.0rc1
File Size Uploaded
fastapi_keycloak-2.0.0rc1.tar.gz 21.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for fastapi-keycloak 2.0.0rc1
File Interpreter ABI Platform
fastapi_keycloak-2.0.0rc1-py3-none-any.whl Python 3 none any Details

Total release size: 41.8 kB

Release files / fastapi_keycloak-2.0.0rc1.tar.gz

Download URL fastapi_keycloak-2.0.0rc1.tar.gz
Size 21.4 kB
Tags Source
SHA-256 checksum
How to use checksums
08d6739987b8283fa663aae66cd92140848714a633af91bbd812115d5c7879bb
BLAKE2b-256 checksum
How to use checksums
ce5eea7cf491d6551966dbe373a9ae0445366b97d2105c9b902f2aaaa77a4371
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.

Transparency log

Release files / fastapi_keycloak-2.0.0rc1-py3-none-any.whl

Download URL fastapi_keycloak-2.0.0rc1-py3-none-any.whl
Size 20.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0aad7161a2c4e5254eaa3f51fe55401c6d19814da988d51d7177b4e55a73a76f
BLAKE2b-256 checksum
How to use checksums
f37f35cba4955e72034a9a47f88e120cb802e4f27d0f38dab40cb5afc704f896
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 28, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page