{"id":30092756,"url":"https://github.com/acie-io/ackc","last_synced_at":"2026-04-14T06:03:22.854Z","repository":{"id":308683326,"uuid":"1028892771","full_name":"acie-io/ackc","owner":"acie-io","description":"Acie's Awesome API Client for Keycloak","archived":false,"fork":false,"pushed_at":"2025-08-07T09:38:12.000Z","size":820,"stargazers_count":0,"open_issues_count":1,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-08-07T09:51:00.759Z","etag":null,"topics":["api","api-client","api-client-python","authentication","authorization","docker","docker-compose","keycloak","niquests","openapi","openapi-generator","openapi-specification","python"],"latest_commit_sha":null,"homepage":"https://pypi.org/project/ackc/","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/acie-io.png","metadata":{"files":{"readme":"readme.md","changelog":null,"contributing":"contributing.md","funding":null,"license":"license.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-07-30T08:06:06.000Z","updated_at":"2025-08-07T09:42:42.000Z","dependencies_parsed_at":"2025-08-07T10:01:44.712Z","dependency_job_id":null,"html_url":"https://github.com/acie-io/ackc","commit_stats":null,"previous_names":["acie-io/ackc"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/acie-io/ackc","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/acie-io%2Fackc","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/acie-io%2Fackc/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/acie-io%2Fackc/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/acie-io%2Fackc/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/acie-io","download_url":"https://codeload.github.com/acie-io/ackc/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/acie-io%2Fackc/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":269548500,"owners_count":24436113,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-09T02:00:10.424Z","response_time":111,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api","api-client","api-client-python","authentication","authorization","docker","docker-compose","keycloak","niquests","openapi","openapi-generator","openapi-specification","python"],"created_at":"2025-08-09T08:04:18.425Z","updated_at":"2026-04-14T06:03:17.815Z","avatar_url":"https://github.com/acie-io.png","language":"Python","funding_links":[],"categories":["Clients"],"sub_categories":[],"readme":"# 🔑 ACKC: API Client for Keycloak\n\n[![Python Version](https://img.shields.io/pypi/pyversions/ackc?style=flat-square\u0026logo=python\u0026logoColor=white)](https://pypi.org/project/ackc/)\n[![PyPI Version](https://img.shields.io/pypi/v/ackc?style=flat-square\u0026logo=pypi\u0026logoColor=white)](https://pypi.org/project/ackc/)\n[![GitHub Release](https://img.shields.io/github/v/release/acie-io/acic?style=flat-square\u0026logo=github)](https://github.com/acie-io/ackc/releases)\n[![Downloads](https://img.shields.io/pypi/dm/ackc?style=flat-square)](https://pypistats.org/packages/ackc)\n[![Ask DeepWiki](https://deepwiki.com/badge.svg)](https://deepwiki.com/acie-io/ackc)\n\n[//]: # ([![DeepWiki]\u0026#40;https://img.shields.io/badge/DeepWiki-acie--io%2Fackc-blue.svg?logo=data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACwAAAAyCAYAAAAnWDnqAAAAAXNSR0IArs4c6QAAA05JREFUaEPtmUtyEzEQhtWTQyQLHNak2AB7ZnyXZMEjXMGeK/AIi+QuHrMnbChYY7MIh8g01fJoopFb0uhhEqqcbWTp06/uv1saEDv4O3n3dV60RfP947Mm9/SQc0ICFQgzfc4CYZoTPAswgSJCCUJUnAAoRHOAUOcATwbmVLWdGoH//PB8mnKqScAhsD0kYP3j/Yt5LPQe2KvcXmGvRHcDnpxfL2zOYJ1mFwrryWTz0advv1Ut4CJgf5uhDuDj5eUcAUoahrdY/56ebRWeraTjMt/00Sh3UDtjgHtQNHwcRGOC98BJEAEymycmYcWwOprTgcB6VZ5JK5TAJ+fXGLBm3FDAmn6oPPjR4rKCAoJCal2eAiQp2x0vxTPB3ALO2CRkwmDy5WohzBDwSEFKRwPbknEggCPB/imwrycgxX2NzoMCHhPkDwqYMr9tRcP5qNrMZHkVnOjRMWwLCcr8ohBVb1OMjxLwGCvjTikrsBOiA6fNyCrm8V1rP93iVPpwaE+gO0SsWmPiXB+jikdf6SizrT5qKasx5j8ABbHpFTx+vFXp9EnYQmLx02h1QTTrl6eDqxLnGjporxl3NL3agEvXdT0WmEost648sQOYAeJS9Q7bfUVoMGnjo4AZdUMQku50McDcMWcBPvr0SzbTAFDfvJqwLzgxwATnCgnp4wDl6Aa+Ax283gghmj+vj7feE2KBBRMW3FzOpLOADl0Isb5587h/U4gGvkt5v60Z1VLG8BhYjbzRwyQZemwAd6cCR5/XFWLYZRIMpX39AR0tjaGGiGzLVyhse5C9RKC6ai42ppWPKiBagOvaYk8lO7DajerabOZP46Lby5wKjw1HCRx7p9sVMOWGzb/vA1hwiWc6jm3MvQDTogQkiqIhJV0nBQBTU+3okKCFDy9WwferkHjtxib7t3xIUQtHxnIwtx4mpg26/HfwVNVDb4oI9RHmx5WGelRVlrtiw43zboCLaxv46AZeB3IlTkwouebTr1y2NjSpHz68WNFjHvupy3q8TFn3Hos2IAk4Ju5dCo8B3wP7VPr/FGaKiG+T+v+TQqIrOqMTL1VdWV1DdmcbO8KXBz6esmYWYKPwDL5b5FA1a0hwapHiom0r/cKaoqr+27/XcrS5UwSMbQAAAABJRU5ErkJggg==\u0026#41;]\u0026#40;https://deepwiki.com/acie-io/ackc\u0026#41;)\n\nA comprehensive Python client library for Keycloak Admin REST API, providing a clean and typed interface for managing Keycloak resources.\n\nThe only dependencies are `niquests` for HTTP and `attrs` for data models, making it lightweight and easy to integrate.\n\n## Overview\n\nACKC is a fully-typed Python library that wraps Keycloak's Admin REST API.\n\nIt provides both synchronous and asynchronous interfaces for all major Keycloak administrative operations, with a focus on developer experience, type safety, and efficiency.\n\nThe author of this package was also a little fed up with the usual daily slog of CLI login and token acquisition before getting to work, so this library aims to make that process as painless as possible.\n\n## Features\n\n- **Complete API Coverage**: 100% implementation of all 371 non-deprecated Keycloak Admin API endpoints\n- **Type Safety**: Full type annotations with `attrs` models for all requests and responses  \n- **Async Support**: Both sync and async methods for all operations (using the `niquests` library)\n- **Auto-generated Models**: Generated from Keycloak's OpenAPI specification using `openapi-python-client`\n- **CLI Tools**: Handy command-line utilities for common tasks like token acquisition and realm export\n- **Developer Friendly**: Clean API design with explicit parameters and comprehensive docstrings\n- **Multiple Auth Methods**: Support for client credentials, password grant, and device code flows\n\n## Installation\n\n`uv` is recommended, but you can also use other package managers like `pip`.\n\n```bash\nuv add ackc\n```\n\nStandalone tool installation is also available:\n\n```bash\nuv tool install --python 3.13 ackc\n```\n\n## Quick Start\n\n```python\nfrom ackc import KeycloakClient\n\nclient = KeycloakClient(\n    server_url=\"https://keycloak.example.com\",\n    client_id=\"admin-cli\",\n    client_secret=\"your-secret\",\n    realm=\"my-realm\",  # Default realm for API calls\n    auth_realm=\"master\",  # Default realm for client authentication\n)\n\nwith client:\n    users = client.users.get_all()\n    realms = client.realms.get_all()\n\nasync def main():\n    async with client:\n        await client.users.aget_all()\n        await client.realms.aget_all()\n```\n\n## Authentication Methods\n\nACKC supports multiple authentication flows:\n\n### Client Credentials (Default, Recommended for M2M)\n```python\nclient = KeycloakClient(\n    server_url=\"https://keycloak.example.com\",\n    client_id=\"admin-cli\", \n    client_secret=\"secret\"\n)\nusers = client.users.get_all()\n```\n\n### Password Grant (Legacy Flow)\n```python\nclient = KeycloakClient(\n    server_url=\"https://keycloak.example.com\",\n    client_id=\"my-client\",\n    client_secret=\"secret\"\n)\n\ntoken = client.get_token_password(\n    username=\"admin\",\n    password=\"admin\",\n    scopes=[\"openid\", \"profile\", \"email\"]\n)\n```\n\n### Device Code Flow (For CLI Tools)\n```python\nclient = KeycloakClient(\n    server_url=\"https://keycloak.example.com\",\n    client_id=\"cli-client\"\n)\n\ndef device_callback(*, verification_uri, user_code, expires_in):\n    print(f\"Please visit: {verification_uri}\")\n    print(f\"User code: {user_code}\")\n    print(f\"You have {expires_in} seconds to authorize\")\n\ntoken = client.get_token_device(\n    scopes=[\"openid\", \"offline_access\"],\n    callback=device_callback\n)\n```\n\n### Working with JWTs\n\nACKC provides methods for validating and working with JWTs:\n\n```python\nclaims = KeycloakClient.jwt_decode(jwt=\"your-jwt-token\")\nprint(f\"User: {claims.get('preferred_username')}\")\nprint(f\"Expires: {claims.get('exp')}\")\n\nneeds_refresh = KeycloakClient.jwt_needs_refresh(jwt=\"your-jwt-token\", buffer_seconds=300)\n\nclient = KeycloakClient(...)\nuser_info = client.jwt_userinfo(jwt=\"your-jwt-token\")\n\ntoken_info = client.jwt_introspect(jwt=\"your-jwt-token\")\n\nif token_info.get(\"active\"):\n    print(f\"Token is valid for user: {token_info.get('username')}\")\n\nnew_token = client.jwt_refresh(refresh_token=\"your-refresh-token\")\n```\n\n## Async Support\n\nAll API methods have async equivalents with the `a` prefix, allowing for non-blocking operations:\n\n```python\nimport asyncio\nfrom ackc import KeycloakClient\n\nasync def main():\n    client = KeycloakClient(\n        server_url=\"https://keycloak.example.com\",\n        client_id=\"admin-cli\",\n        client_secret=\"secret\"\n    )\n\n    async with client:\n        users = await client.users.aget_all()\n        realms = await client.realms.aget_all()\n        roles = await client.roles.aget_all()\n\nasyncio.run(main())\n```\n\n## CLI Tools\n\nACKC includes helpful CLI tools:\n\n### Get Token\n\nAcquire an access token for Keycloak using client, password, or device code flows.\nAlso supports 2FA for password grant using the `--otp`/`--otp-code` options.\n\n```bash\nauth-token --server https://keycloak.example.com --client admin-cli\n```\n\n### Export Realm\nExport a realm and associated data to JSON.\n\n```bash\nauth-realm-export my-realm\n```\n\n### Management Commands\n\nGet health status or dump Keycloak prometheus metrics.\nRequires `KC_HEALTH_ENABLED` or `KC_METRICS_ENABLED` to be set in Keycloak.\n\n```bash\nauth-mc --url http://localhost:9000 --json metrics \n```\n\n### Initialize Docker Environment\n\nCreates Keycloak Docker compose.yaml and .env files in the current directory for development.\n\n```bash\nackc-init \n```\n## Advanced Usage\n\n### Cloudflare Access Integration\n```python\n# Use with Cloudflare Access (+ Tunnel = HTTPS for local development or secure remote management)\n# Note: This gets you past Cloudflare, but you still need to authenticate with Keycloak.\n\nclient = KeycloakClient(\n    server_url=\"https://keycloak.example.com\",\n    cf_client_id='\u003cyour-cf-client-id\u003e.access',  # or CF_ACCESS_CLIENT_ID\n    cf_client_secret='your-cf-secret',  # or CF_ACCESS_CLIENT_SECRET\n)\n```\n\n### Per-Request Realm and Auth Realm Override\n```python\n# Initialize client for custom realm\nclient = KeycloakClient(server_url=\"...\", realm=\"my-realm\")\n\n# Override realm for specific calls\nusers = client.users.get_all(realm=\"other-realm\")\n\n# Use a different realm for API client authentication (master by default).\n# Recommended for backend production clients to maintain least privilege - the admin client should not have access to all realms.\ncompany_realm = \"my-company-realm\"\nclient = KeycloakClient(server_url=\"...\", auth_realm=company_realm, realm=company_realm)\n```\n\n### Direct API Access\n\n(Just don't do this)\n\n## Error Handling\n\n```python\nfrom ackc import KeycloakClient, AuthError\n\ntry:\n    with KeycloakClient(...) as client:\n        users = client.users.get_all()\n\nexcept AuthError as e:\n    print(f\"Authentication failed: {e}\")\nexcept Exception as e:\n    print(f\"API error: {e}\")\n```\n\n## Development\n\n### Regenerating API Client\n\nTo update the generated code when Keycloak API changes:\n\n```bash\npython gen/generate_client.py --download\n```\n\n## Requirements\n\n- Python 3.13+\n- Keycloak 26+ (tested with Keycloak 26.3)\n\n## License\n\nThis project is licensed under the Apache License 2.0. See the [license](license.md) file for details.\n\n## Contributing\n\nContributions are welcome! Please read the [contributing guidelines](contributing.md) for details on how to contribute to this project.\n\n## See Also\n\n- [Keycloak Documentation](https://www.keycloak.org/documentation)\n- [Keycloak Admin REST API](https://www.keycloak.org/docs-api/latest/rest-api/)\n\n## Appearances\n\n- [@thomasdarimont/awesome-keycloak](https://github.com/thomasdarimont/awesome-keycloak) (pending)\n\n\n# API Modules\n\nACKC organizes Keycloak's functionality into logical API modules:\n\n## Users API (`client.users`)\nManage users, credentials, roles, and user sessions.\n- Create, read, update, delete users\n- Manage user credentials and password resets\n- User role mappings and group memberships\n- User sessions and consent management\n\n[Keycloak Documentation: User Management](https://www.keycloak.org/docs/latest/server_admin/#assembly-managing-users_server_administration_guide)\n\n## Realms API (`client.realms`)\nConfigure realms, realm settings, and realm-level operations.\n- Create and configure realms\n- Manage realm settings and themes\n- Default groups and client scopes\n- Realm events and admin events\n- Localization and internationalization\n\n[Keycloak Documentation: Realms](https://www.keycloak.org/docs/latest/server_admin/#_configuring-realms)\n\n## Clients API (`client.clients`)\nManage OAuth2/OIDC clients and their configurations.\n- Create and configure clients\n- Client secrets and registration tokens\n- Client scopes and protocol mappers\n- Service accounts and permissions\n- Client session management\n\n[Keycloak Documentation: Clients](https://www.keycloak.org/docs/latest/server_admin/#_oidc_clients)\n\n## Roles API (`client.roles`)\nDefine and manage realm and client roles.\n- Create realm and client roles\n- Role hierarchies and composites\n- Role permissions and attributes\n- List role members\n\n[Keycloak Documentation: Roles](https://www.keycloak.org/docs/latest/server_admin/#proc-creating-realm-roles_server_administration_guide)\n\n## Groups API (`client.groups`)\nOrganize users into groups with hierarchical structures.\n- Create and manage groups\n- Group hierarchies and subgroups\n- Group role mappings\n- Group members management\n\n[Keycloak Documentation: Groups](https://www.keycloak.org/docs/latest/server_admin/#proc-managing-groups_server_administration_guide)\n\n## Identity Providers API (`client.identity_providers`)\nConfigure external identity providers for federation.\n- SAML and OIDC provider configuration\n- Social login providers (Google, GitHub, etc.)\n- Identity provider mappers\n- First broker login flows\n\n[Keycloak Documentation: Identity Providers](https://www.keycloak.org/docs/latest/server_admin/#_identity_broker)\n\n## Authentication API (`client.authentication`)\nCustomize authentication flows and requirements.\n- Authentication flows and executions\n- Required actions configuration\n- Authenticator providers\n- Password policies\n\n[Keycloak Documentation: Authentication](https://www.keycloak.org/docs/latest/server_admin/#_authentication-flows)\n\n## Authorization API (`client.authorization`)\nFine-grained authorization using Keycloak Authorization Services.\n- Resource servers and resources\n- Authorization scopes and permissions\n- Policies (role, group, time, JS, etc.)\n- Policy evaluation and testing\n\n[Keycloak Documentation: Authorization Services](https://www.keycloak.org/docs/latest/authorization_services/)\n\n## Client Scopes API (`client.client_scopes`)\nManage reusable scope configurations for clients.\n- Create and configure client scopes\n- Protocol mappers for scopes\n- Default and optional client scopes\n- Scope evaluation\n\n[Keycloak Documentation: Client Scopes](https://www.keycloak.org/docs/latest/server_admin/#_client_scopes)\n\n## Protocol Mappers API (`client.protocol_mappers`)\nConfigure how tokens and assertions are populated.\n- Token claim mappings\n- SAML attribute mappings\n- User attribute and role mappings\n- Hardcoded and dynamic values\n\n[Keycloak Documentation: Protocol Mappers](https://www.keycloak.org/docs/latest/server_admin/#_protocol-mappers)\n\n## Components API (`client.components`)\nManage pluggable components like user storage providers.\n- User storage providers (LDAP, custom)\n- Key providers and keystores\n- Theme providers\n- Other SPI implementations\n\n[Keycloak Documentation: User Storage](https://www.keycloak.org/docs/latest/server_admin/#_user-storage-federation)\n\n## Sessions API (`client.sessions`)\nMonitor and manage active user and client sessions.\n- List active sessions\n- Session statistics\n- Offline sessions\n- Session revocation\n\n[Keycloak Documentation: Sessions](https://www.keycloak.org/docs/latest/server_admin/#managing-user-sessions)\n\n## Events API (`client.events`)\nAccess and configure audit and admin events.\n- Query login and admin events\n- Configure event listeners\n- Event types and details\n- Event retention policies\n\n[Keycloak Documentation: Events](https://www.keycloak.org/docs/latest/server_admin/#configuring-auditing-to-track-events)\n\n## Keys API (`client.keys`)\nManage realm cryptographic keys.\n- Active signing and encryption keys\n- Key rotation\n- Algorithm configuration\n- Certificate management\n\n[Keycloak Documentation: Keys](https://www.keycloak.org/docs/latest/server_admin/#realm_keys)\n\n## Organizations API (`client.organizations`)\nManage organizations (Keycloak 25+).\n- Organization management\n- Organization members\n- Organization identity providers\n- Multi-tenancy support\n\n[Keycloak Documentation: Organizations](https://www.keycloak.org/docs/latest/server_admin/#_managing_organizations)\n\n## Scope Mappings API (`client.scope_mappings`)\nManage client and realm scope mappings for users and groups.\n- Realm-level role mappings\n- Client-level role mappings\n- Available and effective roles\n- Composite role resolution\n\n[Keycloak Documentation: Role Mappings](https://www.keycloak.org/docs/latest/server_admin/#_role_mappings)\n\n## Client Role Mappings API (`client.client_role_mappings`)\nManage client-specific role assignments.\n- Assign client roles to users\n- Assign client roles to groups\n- List available client roles\n- Composite client role management\n\n[Keycloak Documentation: Client Roles](https://www.keycloak.org/docs/latest/server_admin/#client-roles)\n\n## Role Mapper API (`client.role_mapper`)\nManage realm-level role assignments.\n- Assign realm roles to users\n- Assign realm roles to groups\n- List available realm roles\n- Effective role calculation\n\n[Keycloak Documentation: Realm Roles](https://www.keycloak.org/docs/latest/server_admin/#realm-roles)\n\n## Roles by ID API (`client.roles_by_id`)\nManage roles using their unique IDs.\n- Role CRUD operations by ID\n- Composite role management by ID\n- Role permissions by ID\n- Cross-realm role operations\n\n[Keycloak Documentation: Role Management](https://www.keycloak.org/docs/latest/server_admin/#_roles)\n\n## Attack Detection API (`client.attack_detection`)\nManage brute force attack detection.\n- View brute force status for users\n- Clear brute force flags for users\n- Reset attack detection counters\n- Manage lockout policies\n\n[Keycloak Documentation: Attack Detection](https://www.keycloak.org/docs/latest/server_admin/#password-policies)\n\n## Client Initial Access API (`client.client_initial_access`)\nManage initial access tokens for dynamic client registration.\n- Create initial access tokens\n- List active tokens\n- Delete tokens\n- Configure token policies\n\n[Keycloak Documentation: Client Registration](https://www.keycloak.org/docs/latest/securing_apps/#_client_registration)\n\n## Client Attribute Certificate API (`client.client_attribute_certificate`)\nManage client certificates and keystores.\n- Generate new certificates\n- Upload certificate chains\n- Download keystores (JKS/PKCS12)\n- Certificate information retrieval\n\n[Keycloak Documentation: Client Certificates](https://www.keycloak.org/docs/latest/server_admin/#_client-certificate-authentication)\n\n## Client Registration Policy API (`client.client_registration_policy`)\nManage policies for dynamic client registration.\n- List available policy providers\n- Configure registration policies\n- Set default client configurations\n- Validation rules for client registration\n\n[Keycloak Documentation: Client Registration Policies](https://www.keycloak.org/docs/latest/securing_apps/#_client_registration_policies)\n\n# Implementation Status\n\n* **Total API Endpoints**: 371 generated endpoints (excluding 23 deprecated template endpoints)\n* **Categories with Wrappers**: 21\n\n| API Module                       | Endpoints | Coverage | Status                                                                                     |\n|----------------------------------|-----------|----------|--------------------------------------------------------------------------------------------|\n| **Users**                        | 33        | 100%     | Full CRUD, groups, sessions, credentials, consents, federated identity, profile management |\n| **Realms**                       | 44        | 100%     | Full CRUD, events, admin events, default groups, client scopes, partial import/export      |\n| **Clients**                      | 34        | 100%     | Full CRUD, sessions, scopes, revocation, registration tokens                               |\n| **Roles**                        | 27        | 100%     | Full CRUD, composites, client roles, users/groups with role                                |\n| **Groups**                       | 11        | 100%     | Full CRUD, members, children, count                                                        |\n| **Identity Providers**           | 17        | 100%     | Full CRUD, mappers, import/export, mapper types                                            |\n| **Authentication**               | 39        | 100%     | Flows, executions, required actions, configurations                                        |\n| **Authorization**                | 31        | 100%     | Resource server, resources, scopes, policies, permissions                                  |\n| **Client Scopes**                | 5         | 100%     | Full CRUD operations (excluding 5 deprecated template endpoints)                           |\n| **Protocol Mappers**             | 14        | 100%     | Full mapper operations (excluding 7 deprecated template endpoints)                         |\n| **Components**                   | 6         | 100%     | Component management and sub-types                                                         |\n| **Sessions**                     | 5         | 100%     | Session management for realms, clients, users                                              |\n| **Events**                       | 6         | 100%     | User events, admin events, configuration                                                   |\n| **Keys**                         | 1         | 100%     | Realm key management                                                                       |\n| **Organizations**                | 19        | 100%     | Full organization management (Keycloak 25+)                                                |\n| **Scope Mappings**               | 22        | 100%     | Realm and client scope mappings for users/groups (excluding 11 deprecated templates)       |\n| **Client Role Mappings**         | 10        | 100%     | User and group client role assignments and available roles                                 |\n| **Role Mapper**                  | 12        | 100%     | User and group realm role assignments and effective roles                                  |\n| **Roles by ID**                  | 10        | 100%     | Role operations by ID, composite management, cross-realm operations                        |\n| **Attack Detection**             | 3         | 100%     | Brute force detection status and flag management                                           |\n| **Client Initial Access**        | 3         | 100%     | Initial access tokens for dynamic client registration                                      |\n| **Client Attribute Certificate** | 6         | 100%     | Certificate generation, upload, keystore management                                        |\n| **Client Registration Policy**   | 1         | 100%     | Registration policy provider configuration                                                 |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Facie-io%2Fackc","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Facie-io%2Fackc","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Facie-io%2Fackc/lists"}