fastmcp/examples/auth/keycloak_oauth
2026-04-13 17:11:17 -04:00
..
client.py AuthKit: auto-bind token audience to resource URL (RFC 8707) (#3905) 2026-04-13 17:11:17 -04:00
README.md AuthKit: auto-bind token audience to resource URL (RFC 8707) (#3905) 2026-04-13 17:11:17 -04:00
server.py AuthKit: auto-bind token audience to resource URL (RFC 8707) (#3905) 2026-04-13 17:11:17 -04:00

Keycloak OAuth Example

Demonstrates FastMCP server protection with Keycloak OAuth.

Requires Keycloak 26.6.0 or later with Dynamic Client Registration enabled.

Setup

  1. Configure a Keycloak realm with Dynamic Client Registration enabled and a trusted host policy for your server URL (e.g. http://127.0.0.1:8000/*).

  2. Set environment variables:

    export KEYCLOAK_REALM_URL="http://localhost:8080/realms/your-realm"
    
  3. Run the server:

    python server.py
    
  4. In another terminal, run the client:

    python client.py
    

The client will open your browser for Keycloak authentication.