Keycloak 26.8 supports SCIM and stateless multi-cluster deployments
The release also promotes client secret rotation, adds consent-based delegation for agents, and deprecates the older multi-site architecture.
Keycloak 26.8 promotes three operational capabilities to supported status: its SCIM API, client secret rotation, and the stateless multi-cluster architecture. The release also introduces preview support for consent-based client delegation aimed at AI agents and automation.
What changed
The SCIM API now provides supported standards-based user and group management, including multivalued attributes, user-profile permissions, fine-grained administration checks in searches, and performance work for large user bases.
Multi-cluster v2 is also supported. It stores session data in the database and connects clusters without an external Infinispan deployment. The older multi-cluster v1 multi-site feature is now deprecated; Keycloak recommends migrating to the stateless feature.
Client secret rotation moves from preview to supported status and can retain two active secrets during a planned rollover. Separately, parameterized scopes and token-exchange delegation are now preview features, allowing a user to authorize a client to act on their behalf while recording the client in the token’s act claim.
Who it affects
Identity teams running cross-site Keycloak, provisioning users through external identity systems, or coordinating zero-downtime secret rotation gain supported paths. Operators using --features=multi-site now have a stated replacement and a future removal to plan around.
What to do
Before upgrading, review the 26.8 migration guide. Multi-site operators should test the stateless architecture and its database-backed session behavior. Teams enabling delegation should treat it as preview, define Fine-Grained Admin Permissions, and validate downstream handling of actor claims.
sources
- Keycloak 26.8.0 release notesgithub.com
- Keycloak 26.8 upgrading guidewww.keycloak.org
comments · 0