Keycloak Authentication for Django REST Framework¶
drf-keycloak validates Keycloak-issued JWTs in your Django REST Framework API.
It implements the backend half of the Authorization Code Flow:
- The frontend handles registration and login against Keycloak.
- The backend validates the JWT from the
Authorizationheader of every incoming request.
That split keeps the backend small — it only verifies tokens — while Keycloak provides the actual authentication and authorization features.
- :material-rocket-launch: Getting started — install, register the authentication backend, make your first authenticated request.
- :material-cog: Configuration — every
KEYCLOAK_CONFIGkey, and the two settings that quietly weaken security if you leave them at their defaults. - :material-key: Permissions — map Keycloak roles onto DRF permission classes.
- :material-shield-lock: Security — behavior on invalid tokens, security headers, CSP.
- :material-api: OpenAPI schema — drf-spectacular integration.
Requirements¶
| Python | 3.10 – 3.13 |
| Django | 4.2, 5.2, 6.0 |
| Django REST Framework | 3.14+ |
Sponsor¶
Development of this package is sponsored by Fin3000 — accounting and invoicing for small businesses in Germany.
License¶
MIT. See LICENSE.txt.