{"id":25776461,"url":"https://github.com/TNG/keycloak-mock","last_synced_at":"2026-08-13T08:30:22.163Z","repository":{"id":35404005,"uuid":"213330914","full_name":"TNG/keycloak-mock","owner":"TNG","description":"A Java library to test REST endpoints secured by Keycloak via OpenID connect.","archived":false,"fork":false,"pushed_at":"2026-07-29T14:53:20.000Z","size":3101,"stargazers_count":135,"open_issues_count":14,"forks_count":32,"subscribers_count":13,"default_branch":"main","last_synced_at":"2026-07-29T16:16:17.457Z","etag":null,"topics":["keycloak","mock","single-sign-on","testing"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/TNG.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":"DCO","cla":null,"disclosure":null}},"created_at":"2019-10-07T08:26:37.000Z","updated_at":"2026-07-23T16:52:35.000Z","dependencies_parsed_at":"2026-01-16T18:04:34.714Z","dependency_job_id":null,"html_url":"https://github.com/TNG/keycloak-mock","commit_stats":null,"previous_names":[],"tags_count":25,"template":false,"template_full_name":null,"purl":"pkg:github/TNG/keycloak-mock","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TNG%2Fkeycloak-mock","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TNG%2Fkeycloak-mock/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TNG%2Fkeycloak-mock/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TNG%2Fkeycloak-mock/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/TNG","download_url":"https://codeload.github.com/TNG/keycloak-mock/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/TNG%2Fkeycloak-mock/sbom","scorecard":{"id":137228,"data":{"date":"2025-08-04","repo":{"name":"github.com/TNG/keycloak-mock","commit":"3956d161534a3b7b9df771fc41b2b473982ec43b"},"scorecard":{"version":"v5.2.1-28-gc1d103a9","commit":"c1d103a9bb9f635ec7260bf9aa0699466fa4be0e"},"score":3.4,"checks":[{"name":"Code-Review","score":4,"reason":"Found 2/5 approved changesets -- score normalized to 4","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: gradle/wrapper/gradle-wrapper.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"1 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#packaging"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/TNG/keycloak-mock/build.yml/main?enable=pin","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   2 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#branch-protection"}},{"name":"SAST","score":5,"reason":"SAST tool is not run on all commits -- score normalized to 5","details":["Warn: 16 commits out of 27 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"17 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-2p57-rm9w-gvfp","Warn: Project is vulnerable to: GHSA-9c47-m6qq-7p4h","Warn: Project is vulnerable to: GHSA-76p3-8jx3-jpfq","Warn: Project is vulnerable to: GHSA-3rfm-jhwj-7488","Warn: Project is vulnerable to: GHSA-hhq3-ff78-jv3g","Warn: Project is vulnerable to: GHSA-f8q6-p94x-37v3","Warn: Project is vulnerable to: GHSA-rp65-9cf3-cjxr","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w","Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j","Warn: Project is vulnerable to: GHSA-c2qf-rxjj-qqgw","Warn: Project is vulnerable to: GHSA-76p7-773f-r4q5","Warn: Project is vulnerable to: GHSA-4v9v-hfq4-rm2v","Warn: Project is vulnerable to: GHSA-9jgg-88mc-972h"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c1d103a9bb9f635ec7260bf9aa0699466fa4be0e/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-16T06:54:06.275Z","repository_id":35404005,"created_at":"2025-08-16T06:54:06.275Z","updated_at":"2025-08-16T06:54:06.275Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36601168,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-13T02:00:06.325Z","response_time":111,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["keycloak","mock","single-sign-on","testing"],"created_at":"2025-02-27T06:01:24.544Z","updated_at":"2026-08-13T08:30:22.158Z","avatar_url":"https://github.com/TNG.png","language":"Java","funding_links":[],"categories":["Clients","测试"],"sub_categories":[],"readme":"[![Java CI](https://github.com/TNG/keycloak-mock/actions/workflows/build.yml/badge.svg?branch=main)](https://github.com/TNG/keycloak-mock/actions?query=branch%3Amain)\n[![Code Quality](https://img.shields.io/sonar/quality_gate/TNG_keycloak-mock?server=https%3A%2F%2Fsonarcloud.io\u0026label=Code%20Quality)](https://sonarcloud.io/dashboard?id=TNG_keycloak-mock)\n[![Release Date](https://img.shields.io/github/release-date/TNG/keycloak-mock.svg?label=Release%20Date)](https://github.com/TNG/keycloak-mock/releases)\n[![Maven Central](https://img.shields.io/maven-central/v/com.tngtech.keycloakmock/mock?color=informational\u0026label=Maven%20Central)](https://central.sonatype.com/search?namespace=com.tngtech.keycloakmock)\n[![Docker Image](https://img.shields.io/badge/Docker_Image-latest-orange)](https://github.com/TNG/keycloak-mock/pkgs/container/keycloak-mock)\n\n# Keycloak Mock\n\n[Keycloak](https://www.keycloak.org) is a single sign-on solution that supports the [Open ID connect](https://openid.net/connect/) standard. However, it does not\ndeliver light-weight test support. This library is intended to fill that gap.\n\nAll artifacts are available on [Maven Central Repository](https://central.sonatype.com/search?namespace=com.tngtech.keycloakmock)\nwith group ID `com.tngtech.keycloakmock`.\n\n## Recent changes\n\nHave a look at our [release notes](https://github.com/TNG/keycloak-mock/releases) for recent\nreleases and changes.\n\n## Testing authenticated backend calls\n\nWhen testing a REST backend that is protected by Keycloak, the mock allows to generate valid access tokens with\nconfigurable claims (e.g. roles).\n\nYou can create and start the mock directly from the `mock` artifact using Maven\n\n```maven\n\u003cdependency\u003e\n    \u003cgroupId\u003ecom.tngtech.keycloakmock\u003c/groupId\u003e\n    \u003cartifactId\u003emock\u003c/artifactId\u003e\n    \u003cscope\u003etest\u003c/scope\u003e\n    \u003cversion\u003e0.21.0\u003c/version\u003e\n\u003c/dependency\u003e\n```\n\nor Gradle\n\n```gradle\ntestImplementation 'com.tngtech.keycloakmock:mock:0.21.0'\n```\n\nlike this:\n\n```java\nimport static com.tngtech.keycloakmock.api.ServerConfig.aServerConfig;\n\nimport com.tngtech.keycloakmock.api.KeycloakMock;\n\nclass Test {\n\n  void checkSomething() {\n    KeycloakMock mock = new KeycloakMock(aServerConfig().withPort(8000).withDefaultRealm(\"master\").build());\n    mock.start();\n\n    // do your test stuff\n\n    mock.stop();\n  }\n\n  void quarkusKeycloakMocks() {\n    // to mock Keycloak without context path (v18.0.0+)\n    KeycloakMock mockNoContextPath = new KeycloakMock(aServerConfig().withNoContextPath().build());\n    // or to use custom one\n    KeycloakMock mockCustomContextPath = new KeycloakMock(aServerConfig().withContextPath(\"/context-path\").build());\n    // if context path is not provided, '/auth' will be used as default due to backward compatibility reasons\n    KeycloakMock mockDefaultContextPath = new KeycloakMock(aServerConfig().build());\n    // ...\n  }\n}\n```\n\nYou can also use the convenience wrapper `mock-junit` for JUnit4\n\n```java\nimport com.tngtech.keycloakmock.junit.KeycloakMockRule;\n\npublic class Test {\n  @ClassRule\n  public static KeycloakMockRule mock = new KeycloakMockRule();\n\n  // ...\n\n}\n```\n\nor `mock-junit5` for JUnit5\n\n```java\nimport com.tngtech.keycloakmock.junit5.KeycloakMockExtension;\n\nclass Test {\n  @RegisterExtension\n  static KeycloakMockExtension mock = new KeycloakMockExtension();\n\n  // ...\n\n}\n```\n\nto let JUnit start the mock for you.\n\nYou can then generate a token of your choosing by providing a TokenConfig:\n\n```java\nimport static com.tngtech.keycloakmock.api.TokenConfig.aTokenConfig;\n\nclass Test {\n\n  String accessToken = mock.getAccessToken(aTokenConfig().withRole(\"ROLE_ADMIN\").build());\n\n  // ...\n\n}\n```\n\nFor a more in-detail test case, please have a look at the [AuthenticationTest](example-backend/src/test/java/com/tngtech/keycloakmock/examplebackend/AuthenticationTest.java) in our example backend project.\n\n## Testing frontends and E2E flows\n\nIn addition to generating and signing tokens programmatically, the mock also offers\n\n* user login (using implicit or authorization code flow, including support for redirect\n  to `http://localhost` and `urn:ietf:wg:oauth:2.0:oob` for desktop applications)\n* client credentials authentication\n* resource owner password credentials authentication (both for public and confidential clients)\n\nNote that as this is a mock, all flows are allowed for any client. For simplicity, all successful\ncalls to the token endpoint return the same response including a refresh token, even for flows which\nshould not contain it according to the specifications.\n\nWhenever an authentication flow would require a username and password, the mock accepts any input as valid.\nIt will extract name and email address from the username, and will interpret the password as a comma-separated list\nof roles that will be present in the token's `realm_access` and / or `resource_access` roles (depending on the\nconfiguration).\n\n![Login Page](login.png)\n\n### Running the mock\n\nIn addition to including the mock in your existing JUnit tests, you can also run the mock as a standalone application.\n\nFor this, either download the self-contained `standalone` JAR from [Maven Central](https://central.sonatype.com/artifact/com.tngtech.keycloakmock/standalone/versions)\nand run it:\n\n```bash\n$ java -jar standalone.jar \u0026\n[main] INFO com.tngtech.keycloakmock.standalone.Main - Server is running on http://localhost:8000\n```\n\nOr download and run the docker image from our [Github Container Registry](https://github.com/TNG/keycloak-mock/pkgs/container/keycloak-mock):\n\n```bash\n$ docker run ghcr.io/tng/keycloak-mock:latest\n```\n\nIf you use the keycloak.js library for your frontend authentication, you simply need to point the `auth-server-url`\nto the URL the mock is listening on. You can also use the mock in end-to-end tests, as it is e.g. compatible with\n`cypress-keycloak`. Have a look at the [example-frontend-react](example-frontend-react) project on how either of this can be set up.\n\nFor more advanced use-cases, you can also configure the mock server using command line parameters.\nYou can use `--help` to get a list of all options:\n\n```bash\n$ java -jar standalone.jar --help\nUsage: standalone [-hsV] [-p=\u003cport\u003e] [-rm=\u003cloginRoleMapping\u003e]\n                  [-tl=\u003ctokenLifespan\u003e] [-a=AUDIENCE[,AUDIENCE...]]...\n                  [-sc=SCOPE[,SCOPE...]]... [[-cp=\u003ccontextPath\u003e] | -ncp]\nStarts a stand-alone keycloak mock.\n  -a, --audiences=AUDIENCE[,AUDIENCE...]\n                      Audiences to set in the token in addition to the\n                        client_id (default: [server]).\n      -cp, --contextPath=\u003ccontextPath\u003e\n                      Keycloak context path (default: /auth). If present, must\n                        be prefixed with '/', eg. --contextPath=/example-path\n  -h, --help          Show this help message and exit.\n      -ncp, --noContextPath\n                      If present context path will not be used. Good for\n                        mocking Keycloak 18.0.0+.\n  -p, --port=\u003cport\u003e   The port on which to run (default: 8000).\n      -rm, --roleMapping=\u003cloginRoleMapping\u003e\n                      Where to add the roles given in the login dialog\n                        (default: TO_REALM). Valid options: TO_REALM,\n                        TO_RESOURCE, TO_BOTH\n  -s, --https         Whether to use HTTPS instead of HTTP.\n      -sc, --scopes=SCOPE[,SCOPE...]\n                      Scopes to add to generated token (default: [openid]).\n      -tl, --tokenLifespan=\u003ctokenLifespan\u003e\n                      Lifespan of generated tokens (default: 10h). Valid values\n                        are e.g. '10h', '15m', '3m45s'.\n  -V, --version       Print version information and exit.\n```\n\n## Server method documentation\n\nYou can get a list of all implemented endpoints of the mock server at `http://localhost:8000/docs`. This is mainly meant\nfor checking if a specific endpoint you want to use is supported by the mock (yet).\n\n## License\n\nThis project is licensed under the Apache 2.0 license (see [LICENSE](LICENSE)).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FTNG%2Fkeycloak-mock","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FTNG%2Fkeycloak-mock","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FTNG%2Fkeycloak-mock/lists"}