Custom SPI & SIEM Integration
Bespoke event listener SPIs, protocol mappers for custom token claims, Kafka event streaming, SIEM forwarding, and full Terraform IaC for your Keycloak realm.
Overview
We build custom Keycloak Service Provider Interfaces for event streaming and token enrichment. Event listener SPIs capture every authentication event — login, logout, failed attempt, token refresh, admin action — and stream them to Kafka topics for downstream processing. Protocol mapper SPIs inject custom claims into OIDC tokens from external sources (databases, internal APIs, attribute stores), so your applications receive the exact payload they need without additional token introspection calls. A SIEM forwarding pipeline routes structured security events to Splunk or Elastic in real time. All realm configuration — clients, roles, scopes, identity providers, and SPI deployment — is codified in Terraform using the mrparkers provider, enabling repeatable deployments and GitOps workflows. Every plugin ships with unit tests and integration tests against a containerised Keycloak instance.
Delivery Process
What's Included
- Custom event listener SPIs
- Protocol mappers (custom token claims)
- Kafka event streaming
- SIEM forwarding (Splunk / Elastic)
- Terraform realm configuration
- Unit + integration tests
Timeline & Scope
Timeline
3-5 weeks
Ideal For
Security and platform teams that need custom Keycloak plugins for audit event streaming, token enrichment, and infrastructure-as-code realm management.
Warranty
30-day warranty covering SPI compatibility, event delivery reliability, and Terraform plan drift discovered after deployment.
Tech Stack
Ready to get started?
Fixed price. Clear scope. 30-day warranty.