Upgrade to Pro — share decks privately, control downloads, hide ads and more …

What Is New and Coming for Managing Cloud-Nativ...

What Is New and Coming for Managing Cloud-Native Identities in Keycloak

Identities are the key to accessing applications and their data, and Keycloak is a leading tool to meet the needs of the cloud-native ecosystem.

This talk highlights how to use the features Keycloak already supports, what’s new, and what we are working on.

This ranges from machine identities and how to leverage SPIFFE/SPIRE or Kubernetes service account tokens, authenticating humans with strong authentication like Passkeys, or synchronizing user and groups across domains and applications via SCIM.

Join this session to see hear about Keycloak's features and how they can help you building a capable cloud-native platform for your organization!

Avatar for Alexander Schwartz

Alexander Schwartz PRO

July 26, 2026

More Decks by Alexander Schwartz

Other Decks in Technology

Transcript

  1. What Is New and Coming for Managing Cloud-Native Identities in

    Keycloak Alexander Schwartz | Keycloak Maintainer KeycloakCon (Yokohama, JP) | 2026-07-28
  2. Improvements for users, admins, and agents 🔑 Passkeys and credential

    recovery (since 26.6) ⚙ User lifecycle management with workflows (since 26.6, extendable) 🗂 SCIM to pre-provision users and groups (preview in 26.7) 💫 Stateless Keycloak for multi-cluster (preview in 26.7) 🛂 Zero-Trust ephemeral credentials for machines (JWT Authorization grant, SPIFFE, KSA, 26.6+) 🛑 Shared Signals (terminate sessions on RISC/CAEP signals) ♻ Split-brain detection and rolling updates (since 26.6 for patch releases) 🦋 Graceful shutdown and proxy documentation (Avoiding 503 error when instances shut down)