NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1926 most downloaded on PyPI
python-keycloak is a Python package providing access to the Keycloak API.
Last release 7 months ago
15 Feb 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
2 versions withdrawn
withdrawn after publishing
9 years old
172 releases · first in 2017
uma: set requested resource ids correctly in permission ticket creation
decode token with all keys, added get client certificate info method
One column per quarter.
do not throw when processing signed userinfo response
### Fix - Fix/python version and ci
### Fix - python version
this change introduces a very strong typing across the library. From now on, we demand that each method returns a single type and converts the results
changes the behavior of get_group_by_path to raise an exception in case the path is not found, which is now the definitive new behavior
### Feat - Add PKCE support (RFC 7636)
### Feat - implement authz import request
add get_role_composites_by_id method
add pool_maxsize parameter to connection managers
prevent all httpx deprecation warnings
implement endpoints returning the number of members in an organization
add get_composite_client_roles_of_role
get_composite_client_roles_of_role (#660)### Fix - fix tests
add pagination support to get realm roles
### Fix - fix/latest version
implement client for revoking consents/offline access, with async and improved testing
adds support for keycloak organizations
add py.typed marker file (pep-561)
more authentication flows and executions methods
Add functions to get/update realm users profile
small bugs, use ruff as linter, added annotations
### Fix - retry upon 401
get_client_all_sessions now supports pagination
Nothing published for this version
### Fix - change to mounts
Feature parity for a_decode_token and decode_token
a_decode_token and decode_token (#616)make sure to not call sync IO functions inside async functions
add client scope client-specific role mappings
Add optional Nonce parameter to the authorization URL requests
### Fix - add scopes to device auth
changed sync get user id to async get user in create user async function
### Feat - Add the max_retries parameter
Set client_credentials as grant_type also when x509 certificate is given
add ability to remove composite client roles
add matchingUri support for listing resources with wildcards
allow the use of client certificates in all requests
use a_public_key() in a_decode_token() instead of public_key()
correctly pass query params in a_send_update_account and a_send_verify_email
passing timeout values to ConnectionManager
functions for updating resource permissions and getting associated policies for a permission
### Feat - Async feature
### Fix - Leeway config
removed deprecated functionality
allows retrieval of realm and client level roles for a user
### Fix - lowercase default role name
### Feat - add admin group count
fix keycloak_admin.create_user documentation/ typehint
improve KeycloakAdmin.get_client_id() performances
Allow query parameters for group children
incorporate custom headers into default header setup
get_groups pagination call was not used #537
use jwcrypto and remove python-jose
### Feat - new docs. - new docs. - new docs. - new docs. - new docs. - new docs. - new docs. ### Fix - updated readme.
use grant type password with client secret
### Fix - name of client_id parameter
### Fix - update readme.
### Fix - linter check - updated dependencies
Adding additional methods to support roles-by-id api calls Most of the methods rely on the role name within python keycloak, which for the vast majori
Your coding agent can read these notes before it upgrades. Set up the MCP server →