Admin REST API
Keycloak provides a comprehensive REST API for managing all aspects of the server programmatically. The Admin REST API supports the same operations available through the Admin Console.
TOC
API Base URLAuthenticationMethod 1: Username and PasswordMethod 2: Service AccountUse the TokenCommon API OperationsRealmsUsersClientsRolesGroupsIdentity ProvidersEventsPaginationError HandlingFull API ReferenceAPI Base URL
All Admin REST API endpoints are relative to this base URL.
Authentication
All API requests require a valid access token with admin privileges. There are two methods to obtain one.
Method 1: Username and Password
Authenticate with an admin user's credentials:
Method 2: Service Account
Use a confidential client with service account roles:
-
Create a confidential client in the
masterRealm (or the target Realm). -
Enable Service accounts roles.
-
Assign the appropriate admin roles to the service account (for example,
realm-admin). -
Obtain a token using the
client_credentialsgrant:
Service accounts are recommended for automation and CI/CD pipelines.
Use the Token
Include the access token in the Authorization header:
Common API Operations
Realms
Users
Clients
Roles
Groups
Identity Providers
Events
Pagination
Most list endpoints support pagination via first (offset) and max (page size) query parameters:
Error Handling
The API returns standard HTTP status codes:
Full API Reference
For the complete API specification, refer to the upstream Keycloak REST API documentation:
- Official REST API Reference: https://www.keycloak.org/docs-api/latest/rest-api/index.html
Keycloak does not expose a runtime OpenAPI/Swagger endpoint. The official OpenAPI definitions are published as static files on the Keycloak documentation site, versioned per release (for example, /docs-api/26.1.4/rest-api/index.html).