# Vendor facets — Keycloak. Open-source identity server the provider runs on its own domain. The # capability is the richest in this cohort — certified OIDC incl. Dynamic Client Registration, FAPI 1 # certified and FAPI 2 conformance-tested, PAR, DPoP, CIBA, RFC 8414 metadata for MCP — but every document # is REALM-SCOPED (/realms//.well-known/...). The root-only harvest does not request it (a live # Keycloak host, sso.redhat.com, answers 404 at the root), so most of that capability does not score. vendor: keycloak name: Keycloak website: https://www.keycloak.org areas: - identity registry_keys: - keycloak rubric_schema_version: 0.22.0 generated: '2026-09-25' features_refreshed: '2026-09-25' basis: capability summary: >- Keycloak is self-hosted, so its discovery document already sits on the provider's own domain, and it advertises authorization_code and a registration endpoint. But the document lives under the realm path, and the harvest probes only the host root, so the served tiers of auth clarity, delegated identity and dynamic client registration are reached only if the provider also answers the root well-known paths (a reverse-proxy rewrite). Keycloak says outright that protected-resource metadata is the MCP server's job, and it does not yet support RFC 8707 resource indicators. features: - id: realm-discovery name: Realm-scoped OIDC discovery description: >- Each realm serves /realms//.well-known/openid-configuration with issuer, authorization_code, client_credentials, token-exchange, CIBA and a registration endpoint; the host root answers 404. source: https://sso.redhat.com/auth/realms/redhat-external/.well-known/openid-configuration tier: open-source - id: client-registration name: Client Registration service (RFC 7591/7592) description: >- /realms//clients-registrations/openid-connect with initial access tokens, bearer tokens, or anonymous registration governed by trusted-host, consent-required and max-clients policies. source: https://www.keycloak.org/securing-apps/client-registration tier: open-source - id: mcp-authorization-server name: MCP authorization server support description: >- RFC 8414 metadata, DCR and experimental CIMD for MCP; no RFC 8707 resource indicators, and RFC 9728 is stated to be the MCP server's responsibility. source: https://www.keycloak.org/securing-apps/mcp-authz-server tier: open-source - id: specifications name: Certified specifications incl. FAPI description: >- OpenID-certified Core/Discovery/Dynamic Registration; FAPI 1 Baseline/Advanced certified, FAPI 2 Security Profile and Message Signing conformance; PAR, DPoP, CIBA, token exchange. source: https://www.keycloak.org/securing-apps/specifications tier: open-source - id: self-registration name: Login and self-registration pages description: Realm login pages with optional user self-registration and terms acceptance. source: https://www.keycloak.org/docs/latest/server_admin/index.html tier: open-source maps: - feature: realm-discovery check: auth_clarity layer: agent_readiness grade: negotiable partial: true partial_note: >- The served tier needs the document at the host root; Keycloak serves it under /realms//, so without a root rewrite only the OpenAPI fallback (oauth2 declared in the provider's contract) reads. provider_must: >- Declare the oauth2/openIdConnect scheme in its own OpenAPI, or serve the realm document at the root well-known path. points: 10 baseline_pass_rate: 0.474 - feature: realm-discovery check: delegated_identity layer: agent_readiness grade: documented partial: true partial_note: >- Served tier needs the root document; documented reads an authorizationCode flow in the provider's OpenAPI. provider_must: Declare the authorizationCode flow in its own OpenAPI. points: 6 baseline_pass_rate: 0.209 - feature: client-registration check: dynamic_client_registration layer: agent_readiness conditional: true condition: >- Only if the provider serves the realm's discovery document at the host's root /.well-known/openid-configuration or oauth-authorization-server (reverse-proxy rewrite) on a host on its record; the realm-path document is not probed. points: 6 baseline_pass_rate: 0.134 - feature: self-registration check: sign_up_present layer: composite provider_must: Enable realm self-registration and declare the login/registration URL as a Login or SignUp pointer. catalog_pass_rate: 0.19 facet: access_clarity points: 5 baseline_pass_rate: 0.463 - feature: mcp-authorization-server check: oauth_scopes_enumerated layer: composite conditional: true condition: Only if the provider's own OpenAPI declares oauth2 and enumerates its client scopes. catalog_pass_rate: 0.866 facet: contract_quality points: 4 baseline_pass_rate: 0.902 saturated: true saturated_note: >- 90% of providers with a contract, docs and a reference already earn this; the vendor cannot move it for most of its buyers. - feature: specifications check: reg_fapi_profile layer: composite conditional: true condition: >- Banking/open-finance regime, FAPI client policies switched on, and the provider's own auth documentation stating FAPI, PAR, private_key_jwt or mTLS-bound tokens. catalog_pass_rate: 0.196 facet: regulatory points: 6 baseline_pass_rate: 0.463 earns_nothing: - feature: specifications check: reg_certification_signal why: The OpenID/FAPI certifications are Keycloak's; the check reads a certification the provider holds. - feature: realm-discovery check: well_known_published why: openid-configuration is not one of the well-known documents that check reads, at any path. out_of_reach: checks: - protected_resource_metadata - security_schemes_defined - oauth_flows_current - consent_identity note: >- Keycloak's own MCP guide assigns RFC 9728 to the MCP server; the OpenAPI checks are the provider's contract. unscored_practice: - feature: realm-discovery why: >- The served document advertises implicit and password grants; oauth_flows_current reads only OpenAPI securitySchemes. surface: contract_quality: reachable: 4.0 total: 211 access_clarity: reachable: 5.0 total: 38 regulatory: reachable: 6.0 total: 108 agent_readiness: reachable: 16.5 total: 139 hard_rule: >- A model, not a score. Adopting this vendor changes a provider's Kin Score only when the provider publishes the resulting artifacts on its own surface; nothing here writes a score, and no sponsorship or partnership can. method: searched source: - https://sso.redhat.com/auth/realms/redhat-external/.well-known/openid-configuration - https://www.keycloak.org/docs/latest/server_admin/index.html - https://www.keycloak.org/securing-apps/client-registration - https://www.keycloak.org/securing-apps/mcp-authz-server - https://www.keycloak.org/securing-apps/specifications measured: cohort: method: vendors-catalog.json detections (CNAME / header / URL shape / markup), never a name match detected: 0 in_baseline: 0 control: basis: providers earning contract_present + documentation_present + api_reference_present, minus the cohort n: 5216 metric: >- cohort_pct / control_pct = mean share of the check's points earned (derived and platform credit weighted), x100 measured_on: '2026-09-25' status: 'not measurable: 0 detected customers clear the baseline (need 20)' simulation: simulated_on: '2026-09-25' rubric: 0.23.0 population: providers publishing a contract (contract_present earned), replayable exactly providers: 8977 providers_unreplayable: 987 providers_moved: 8268 conditional_rows: excluded (they depend on what the API already does) composite_lift: median: 2.4 p75: 2.6 p90: 2.7 max: 2.7 mean_among_movers: 2.3 agent_readiness_lift: median: 5.0 p75: 5.1 p90: 5.9 max: 8.8 mean_among_movers: 5.3 facet_lift_median_among_movers: access_clarity: 13.1 composite_band_moves: thin -> developing: 679 developing -> strong: 189 emerging -> thin: 167 strong -> exemplar: 48 minimal -> emerging: 1 agent_readiness_band_moves: agent-aware -> agent-ready: 2198 agent-ready -> agent-native: 170 method: >- each provider's own kin/checks file, the vendor's maps at their stated credit, the scorer's composite formula; from -> to, nothing written