Trending 2026Keycloak 24.x – 26.x

Federated Identity Brokering

SAML · OIDC · App Gallery

Connect enterprise and social identity providers via SAML 2.0 and OpenID Connect. Pre-built connectors for Okta, Azure AD, Google Workspace, and more.

Delivery: 2–4 weeks

How It Works

Login requestBroker redirectSAML/OIDCMap claimsUnified token👤User🔑App Login🔀KC Broker🌐External IdP🗺Token MapAccess

Technical Highlights

SAML 2.0 and OpenID Connect brokeringPre-built connectors for major enterprise and social providersJust-in-time user provisioning from external IdPsProtocol mapper chains for token normalizationFirst-login and post-login broker flows

Brokering Architecture

Keycloak acts as an identity broker that federates authentication to external identity providers via SAML 2.0, OpenID Connect, and OAuth 2.0. The broker translates external tokens into Keycloak sessions, enabling applications to integrate with a single IdP while supporting hundreds of upstream providers transparently.

Identity Provider Gallery

Pre-built connectors for enterprise providers (Okta, Azure AD, PingFederate, ADFS) and social providers (Google, GitHub, Apple, Facebook) are available out of the box. Custom OIDC and SAML providers can be added via configuration without code, supporting any standards-compliant identity provider in minutes.

Token Mapping

Protocol mappers transform external identity claims into a normalized token format that applications consume. Custom mappers can enrich tokens with data from user storage, external APIs, or organization membership, ensuring that downstream services receive consistent, well-structured identity claims regardless of the upstream provider.

Why in 2026

Your customers use different IdPs. Brokering lets you support them all from a single Keycloak deployment.

Related service package: Full CIAM / Zero-Trust Overhaul

Delivery: 2–4 weeks

Ready to implement Federated Identity Brokering?

Fixed price. Clear scope. 30-day warranty.

Or view all service packages