Fixed Price

Custom SPI & SIEM Integration

Bespoke event listener SPIs, protocol mappers for custom token claims, Kafka event streaming, SIEM forwarding, and full Terraform IaC for your Keycloak realm.

·3-5 weeks

Overview

We build custom Keycloak Service Provider Interfaces for event streaming and token enrichment. Event listener SPIs capture every authentication event — login, logout, failed attempt, token refresh, admin action — and stream them to Kafka topics for downstream processing. Protocol mapper SPIs inject custom claims into OIDC tokens from external sources (databases, internal APIs, attribute stores), so your applications receive the exact payload they need without additional token introspection calls. A SIEM forwarding pipeline routes structured security events to Splunk or Elastic in real time. All realm configuration — clients, roles, scopes, identity providers, and SPI deployment — is codified in Terraform using the mrparkers provider, enabling repeatable deployments and GitOps workflows. Every plugin ships with unit tests and integration tests against a containerised Keycloak instance.

Delivery Process

ArchitectImplementWire UpCodifyValidateShip📋Requirements📝SPI Design🛠️Plugin Dev📡Kafka/SIEM🏗️TerraformTest🚀Deploy

What's Included

  • Custom event listener SPIs
  • Protocol mappers (custom token claims)
  • Kafka event streaming
  • SIEM forwarding (Splunk / Elastic)
  • Terraform realm configuration
  • Unit + integration tests

Timeline & Scope

Timeline

3-5 weeks

Ideal For

Security and platform teams that need custom Keycloak plugins for audit event streaming, token enrichment, and infrastructure-as-code realm management.

Warranty

30-day warranty covering SPI compatibility, event delivery reliability, and Terraform plan drift discovered after deployment.

Tech Stack

Keycloak 26.xJava SPIKafkaSplunk / Elastic SIEMTerraform

Ready to get started?

Fixed price. Clear scope. 30-day warranty.

Or view all service packages