Installation¶
keycloak-agent is a standard Python package and a prebuilt container image. Pick
the path that matches how you want to run it.
Requirements¶
- Python 3.11 – 3.14.
- A reachable Keycloak server with an administrative account — see Backing Platform to deploy one locally.
From PyPI (recommended)¶
Optional extras¶
The base install is intentionally minimal. Install the extra for what you need:
| Extra | Install | Pulls in |
|---|---|---|
mcp |
pip install "keycloak-agent[mcp]" |
FastMCP MCP-server runtime (agent-utilities[mcp]) |
agent |
pip install "keycloak-agent[agent]" |
Pydantic-AI agent + Logfire tracing |
all |
pip install "keycloak-agent[all]" |
Everything above |
test |
pip install "keycloak-agent[test]" |
pytest, pytest-asyncio, pytest-cov, pytest-xdist |
From source¶
git clone https://github.com/Knuckles-Team/keycloak-agent.git
cd keycloak-agent
pip install -e ".[all]" # editable install with every extra
With uv:
Prebuilt Docker image¶
A multi-stage, slim image is published on every release (installs
keycloak-agent[all], entrypoint keycloak-mcp):
docker pull knucklessg1/keycloak-agent:latest
docker run --rm -i \
-e KEYCLOAK_URL=http://your-keycloak:8080 \
-e KEYCLOAK_USERNAME=admin \
-e KEYCLOAK_PASSWORD=admin_secure_password \
-e KEYCLOAK_REALM=master \
knucklessg1/keycloak-agent:latest # stdio transport (default)
For an HTTP server with a published port, see Deployment.
Verify the install¶
Next steps¶
- Deployment — run it as a long-lived MCP server and agent behind Caddy + DNS.
- Usage — call the tools, the API, and the CLI.
- Configuration — every environment variable.