Keycloak 26.8.0 Released
After quite a few releases fixing security vulnerabilities on the 26.7.x branch, here comes 26.8.0. Lots of new features this time. Let’s go through the ones I find the most interesting.
The release notes are available here for those who want more details.
The OID4VP spec available as experimental / OID4VCI in preview
As a reminder, this enables decentralized authentication, unlike OIDC which is centralized. Here, Keycloak becomes able (OID4VP) to verify a Verifiable Credential, a kind of digital token, provided by the user as proof of their identity. One can imagine scenarios such as a government issuing a proof-of-age certificate, and Keycloak validating that a user is an adult without the government being notified that the certificate was used on a given website. With OAuth2/OIDC, if you log in to a website with a government identity provider (such as GOV.UK One Login or Login.gov), the government knows about it immediately. OID4VCI, on the other hand, allows Keycloak to issue credentials that can be used on other websites supporting this standard.
Keycloak now supports the act claim
During token exchange, and by extension impersonation (which is a form of token exchange), generated tokens will contain the act claim, for actor. This finally provides a standard way to know on whose behalf a token obtained through token exchange is being used. Besides impersonation, a notable use case is the authentication of AI agents, which will now get tokens identifying the user they are acting on behalf of.
A native mechanism for zero-downtime client secret rotation
To achieve this, two secrets can temporarily coexist while a client switches over. This should greatly improve security and make life easier for teams operating Keycloak.
SCIM API support
SCIM allows users and groups to be managed in a standard way through applications supporting this protocol. Together with AuthZEN (26.7.0), this makes Keycloak even more portable. Multi-cluster v2 enables multi-cluster deployments without an external Infinispan cluster. This will greatly simplify multi-site Keycloak deployments.