Skip to content

Keycloak SSO

Connect a Keycloak realm so your organization signs in to sslcertificates.io with OpenID Connect.

What this configures

Create a confidential client in your Keycloak realm, enable standard flow, and paste the realm issuer URL plus client credentials into Organization → Security. Keycloak is your identity provider; sslcertificates.io does not host it and does not list Keycloak as a certificate integration.

Groups

Map Keycloak groups to organization roles after the connection test succeeds. Role changes do not affect certificate inventory isolation between organizations.

Provisioning

If you also use SCIM from Keycloak, issue the token under User Provisioning. Membership changes apply to the sslcertificates.io organization, not to certificates or DNS zones.