World Congress 2025 Aug 20, 2025 Session details

Delegating the chores of authenticating users to Keycloak

Alexander Schwartz

Stop wasting engineering cycles rebuilding custom user authentication. Delegate identity management to Keycloak to handle complex OIDC workflows and focus strictly on your core business logic.

Pause
Mute Enter Fullscreen
#1 about 3 min

Motivations for delegating user authentication frameworks

Understanding the core challenges of building custom login flows rather than relying on established identity solutions.

#2 about 3 min

Key components and history of the Keycloak project

An overview of active authentication actors and Keycloak's evolution into a robust open-source CNCF project.

#3 about 2 min

Discovering standard OpenID Connect capabilities and provider endpoints

How applications query the well-known configuration JSON endpoint to automatically discover available identity provider services.

#4 about 2 min

Determining login status and initiating user registration prompts

Using specific URL prompt parameters to check login state or seamlessly direct users towards account creation.

#5 about 4 min

Executing user login flows and live registration demos

Demonstrating initial parameter configuration for native user signups alongside application integration for token tracking.

#6 about 2 min

Checking active login sessions using isolated hidden iframes

Implementing standard cross-domain Javascript messaging to seamlessly verify if a user's remote tab remains authenticated.

#7 about 2 min

Refreshing access tokens and parsing user endpoint information

Using token endpoints properly to renew application access while populating custom claims mapped directly from backend databases.

#8 about 2 min

Safely logging users out across multiple integrated applications

Preventing malicious logout execution patterns by mandating an ID token hint payload sent directly to end-session destinations.

#9 about 2 min

Enforcing step-up authentication using required second security factors

Configuring connected client frameworks to natively demand multifactor validation for sensitive business actions via designated ACR values.

#10 about 4 min

Managing user profiles explicitly via application initiated actions

Redirecting users to specialized Keycloak UI capabilities to handle autonomous profile updates and seamless email verification workflows.

#11 about 3 min

Enabling incremental user profiling through dynamic custom forms

Customizing external data collection procedures to reliably gather specific profile information only when matching requested scopes apply.

#12 about 2 min

Restricting application access by intercepting early login flows

Intercepting unauthorized network participants early during the core authentication phase to improve broad system authorization security.

#13 about 2 min

Reviewing identity endpoints alongside specific Keycloak preview features

A concluding review analyzing established OpenID Connect conventions paired with opportunities to test upcoming Keycloak integration features.

Matching moments

1:43 min

Exploring the Keycloak open-source identity and access system

Alexander Schwartz Alexander Schwartz · WWC 2025

1:03 min

Offloading identity management to hosted authentication platform providers

Dávid Lévai · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:24 min

Securing cloud deployments by utilizing OpenID Connect mapping

Chris Ayers · LIVE

1:57 min

Managing credential delegation in multi-agent application architectures

Alexander Günsche Alexander Günsche +1 · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

When Agents Became Users: Rearchitecting Identity and Permissions for AI at Scale

Yoav Gal, Dor Cohen

Yoav Gal
Dor Cohen
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

AI Agents are Only as Smart as their Context: Building a Real-Time Context Engine at Intuit

Bharat Patel

Lead Software Engineer at Intuit

Bharat Patel