Skip to main content

16 posts tagged with "authentication"

View All Tags

Atomic authentication flow updates for Keycloak, built with Gusto

· 7 min read
Razvan Tufisi
Phase Two

We're open-sourcing keycloak-atomic-auth-flows, a Keycloak extension that replaces an entire set of authentication flows, authenticator configs, and their bindings in one atomic, transactional request.

It was built in partnership with Gusto, who use Keycloak for user authentication and rely on Phase Two for enterprise Keycloak support. It has been running in their production environment for almost a year. The public repository is the extraction of that work into a standalone extension anyone can install.

Keycloak Passkeys and WebAuthn: What's the Difference?

· 7 min read
Jeff Patzer
Phase Two

Keycloak supports passkeys and WebAuthn out of the box, with no plugin and, as of 26.7, no custom authentication flow. The thing worth knowing before you turn either on is that they are not one feature. Keycloak treats passwordless passkeys and WebAuthn-as-a-second-factor as two different credentials, registered by two different required actions, governed by two different policies. A user who has one does not have the other, and nothing in the admin console tells you so.

This post is the concept half: what passkeys are, how they relate to WebAuthn, how Keycloak models the difference, and the recovery and cross-platform problems that bite in production. For the configuration itself — every click, every default value, every failure mode — see the tutorial linked below.

SAML, Simplified.

· 8 min read
Jeff Patzer
Phase Two

SAML has a bit of a reputation. For many developers, it lives in that shadowy corner of the B2B internet where XML still rules and stack traces seem to go on forever. If you've ever had the misfortune of debugging a malformed <Assertion>, you know the pain. But here's the thing: it doesn't have to be a nightmare.

At Phase Two, we provide managed hosting and enterprise support for Keycloak, a leading open-source Identity and Access Management platform. And while OIDC has become the default for most modern applications, SAML is still alive and well—especially in enterprise environments.

This post is a gentle (and opinionated) introduction to what SAML is, how it works, and why it still matters particularly if you're implementing SAML SSO in Keycloak.

Keycloak SAML Identity Provider (IdP) Initiated Flow with Okta

· 17 min read
Razvan Tufisi
Phase Two

IdP Initiated Flow​

When implementing SAML for the establishment of an Identity Provider, two primary options are available:

  1. Service Provider (SP) initiated
  2. Identity Provider (IdP) initiated

The SP initiated flow is widely recognized by users due to its straightforward configuration, which is merely the exchange of some metadata. In contrast, the IdP-initiated flow is less intuitive and involves an additional step that may not be readily apparent to many users. The purpose of this blog is to elucidate the steps necessary to successfully execute the IdP-initiated flow. We will setup a full example

A fundamental understanding of SAML 2.0 and Keycloak is required to effectively follow the provided instructions.

Securing Keycloak with OIDC SPA and Phase Two

· 7 min read
Jeff Patzer
Phase Two
OIDC SPA Logo

Our pal over at Keycloakify has been working on creating a simple OpenId Connect (OIDC) library called, OIDC Spa. As with Joseph's usual approach to user friendliness, OIDC SPA simplifies a lot of the integration work that can come with adding an Authentication and Authorization layer to your application. Follow along as we show you how to integrate OIDC SPA with Phase Two's Keycloak, running on your machine or in a hosted Phase Two cluster.

Securing Angular Apps with Keycloak

· 2 min read
Jeff Patzer
Phase Two

In this article we'll be using Keycloak to quickly secure an Angular application with user management and single sign on (SSO) using the open source IAMs Keycloak for Authentication and Authorization. We will demonstrate the integration by securing a page for logged-in users. This quickly provides a jump-off point to more complex integrations.

Phase Two Organizations now support shared Identity Providers (IdPs)

· 2 min read
Jeff Patzer
Phase Two

An exciting new feature has been added to Phase Two Organizations Extension! Organizations now support shared Identity Providers (IdPs) for mapping multiple organizations to a single IDP. This feature is especially useful for organizations that have multiple organizations that need to share the same IDP.

Securing SvelteKit Apps with Keycloak

· 2 min read
Rishi Raj Jain
Guest contributor

In this article we'll be using Keycloak to quickly secure a SvelteKit application with user management and single sign on (SSO) using the open source IAMs Keycloak for Authentication and Authorization. We will demonstrate the integration by securing a page for logged-in users. This quickly provides a jump-off point to more complex integrations.

Securing React Router v7 (formerly Remix) Apps with Keycloak

· 2 min read
Rishi Raj Jain
Guest contributor

In this article we'll be using Keycloak to quickly secure a React Router v7 application, the successor of Remix, with user management and single sign on (SSO) using the open source IAMs Keycloak for Authentication and Authorization. We will demonstrate the integration by securing a page for logged-in users. This quickly provides a jump-off point to more complex integrations.