Skip to content

Keycloak Authentication for Django REST Framework

drf-keycloak validates Keycloak-issued JWTs in your Django REST Framework API. It implements the backend half of the Authorization Code Flow:

  • The frontend handles registration and login against Keycloak.
  • The backend validates the JWT from the Authorization header of every incoming request.

That split keeps the backend small — it only verifies tokens — while Keycloak provides the actual authentication and authorization features.

pip install drf-keycloak
  • :material-rocket-launch: Getting started — install, register the authentication backend, make your first authenticated request.
  • :material-cog: Configuration — every KEYCLOAK_CONFIG key, and the two settings that quietly weaken security if you leave them at their defaults.
  • :material-key: Permissions — map Keycloak roles onto DRF permission classes.
  • :material-shield-lock: Security — behavior on invalid tokens, security headers, CSP.
  • :material-api: OpenAPI schema — drf-spectacular integration.

Requirements

Python 3.10 – 3.13
Django 4.2, 5.2, 6.0
Django REST Framework 3.14+

Fin3000

Development of this package is sponsored by Fin3000 — accounting and invoicing for small businesses in Germany.

License

MIT. See LICENSE.txt.