Fixes for risky Keycloak settings
Each fix explains one problem realmlint finds, why it matters, and how to fix it in the admin console or in your realm files. Written for Keycloak 26.
- highKeycloak redirect URI wildcards: why "*" is dangerous and what to use instead
A redirect URI of "*" lets anyone send your users' login codes to their own site. Here is how to find the exact callback URLs and lock a Keycloak client down.
- high"You are logged in as a temporary admin user": replacing Keycloak's bootstrap admin
Keycloak 26 creates a temporary admin on first start and asks you to replace it. Here is how to create a permanent admin with a second factor and delete the temporary one safely.
- mediumWho changed this Keycloak setting? Turning on admin events
Keycloak does not record configuration changes by default. Here is how to turn on admin events, read them, and keep them from filling your database.
- mediumTurning on brute force detection in Keycloak without locking out real users
New Keycloak realms allow unlimited password guesses. Here is how to choose a lockout mode and sensible limits, and how to unlock a user who gets caught.
- mediumSecuring Keycloak public clients: require PKCE and turn off the implicit flow
Single-page and mobile apps cannot keep a client secret. Here is how to protect them in Keycloak with PKCE, and which old flows to turn off.