"You are logged in as a temporary admin user": replacing Keycloak's bootstrap admin
Keycloak 26 creates a temporary admin on first start and asks you to replace it. Here is how to create a permanent admin with a second factor and delete the temporary one safely.
Since Keycloak 26, the admin console shows a banner on the master realm: You are logged in as a temporary admin user. To harden security, create a permanent admin account and delete the temporary one.
Many instances never do. This article walks through the replacement without locking yourself out.
What realmlint reports
HIGH Temporary bootstrap admin still exists [temporary-admin-present] - user "admin": temporary bootstrap admin account is still present HIGH Admin account has no second factor [admin-without-mfa] - user "admin": admin user has no OTP or WebAuthn credential
The two usually appear together. realmlint needs a full export that includes users, made with kc.sh export; the admin console's partial export leaves users out.
Why it matters
Keycloak creates the first admin from the KC_BOOTSTRAP_ADMIN_USERNAME and KC_BOOTSTRAP_ADMIN_PASSWORD environment variables and marks it as temporary. In practice the username is often admin, and the password sits in a Docker Compose file, a Helm values file or a CI variable that several people can read. That account has full control of the master realm, and through it every other realm.
Replace it
Do this while logged in as the temporary admin, in the master realm.
- Go to Users and click Add user. Use a personal username, not
admin, and your email address. Click Create. - On the new user's Credentials tab, click Set password. Turn Temporary off and save.
- On the Role mapping tab, click Assign role, choose Filter by realm roles, select
adminand click Assign. - On the Details tab, add Configure OTP to Required user actions and save. You will be asked to set up an authenticator app at your next login.
- Sign out, then sign in to the admin console as the new user and complete the OTP setup.
- Check that you can open another realm and change a setting. Only then go on.
- Go to Users, open the temporary admin, and use the action menu to Delete user.
Finally, remove KC_BOOTSTRAP_ADMIN_USERNAME and KC_BOOTSTRAP_ADMIN_PASSWORD from your deployment files, and rotate wherever that password was stored. Keycloak only uses them to create the first admin, so they do nothing useful once a permanent admin exists.
Locked out? Keycloak 26 can create a new temporary admin from the command line with kc.sh bootstrap-admin user, run against the same database. Use it, then repeat the steps above.
Check it worked
kc.sh export --realm master --file master.json realmlint check master.json
Both temporary-admin-present and admin-without-mfa should be gone. If admin-without-mfa remains for other admins, ask them to add OTP or a security key in the same way.