Download the PHP package sandstorm/keycloak-admin-api without Composer

On this page you can find all versions of the php package sandstorm/keycloak-admin-api. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package keycloak-admin-api

sandstorm/keycloak-admin-api

A framework-agnostic PHP client for the Keycloak Admin REST API (target: Keycloak 26.5 or newer).

The whole package is work in progress, and is extended as needed.

Thanks to BroodfondsMakers for sponsoring the development of this package, and for agreeing to Open Source it!

It exposes the admin API in modern PHP, using immutable typed DTOs and collections. It has no framework coupling.

Requirements

Usage

Also on KeycloakUsersApi:

Keycloak REST API coverage

This is based on the Keycloak Admin REST API: The vast majority is not implemented, because so far this is focused upon user-administration.

Legend: โœ… implemented ยท ๐ŸŸก partial ยท โŒ not implemented (candidate)

# KC resource group Status What we cover / our slice
1 Attack Detection โŒ brute-force status/clear - none
2 Authentication Management โŒ realm auth-flow config
3 Client Attribute Certificate โŒ client keystores
4 Client Initial Access โŒ dynamic client registration tokens
5 Client Registration Policy โŒ -
6 Client Role Mappings โŒ a user's client-role grants - candidate
7 Client Scopes โŒ -
8 Clients ๐ŸŸก GET /clients (KeycloakClientsApi::list); client CRUD - โŒ
9 Component โŒ user-federation / key providers
10 default (realm root) โŒ GET/PUT /admin/realms/{realm} - planned KeycloakRealmApi
11 Groups ๐ŸŸก GET /groups (KeycloakGroupsApi::listRealmGroups); group CRUD, /groups/{id}/members, children - โŒ
12 Identity Providers โŒ -
13 Key โŒ realm keys
14 Organizations โŒ -
15 Protocol Mappers โŒ -
16 Realms Admin ๐ŸŸก GET /events, GET /admin-events (KeycloakEventsApi); realm config + /health - โŒ (planned KeycloakRealmApi)
17 Role Mapper โŒ a user's realm-role grants - candidate
18 Roles โŒ realm/client role definitions
19 Roles (by ID) โŒ -
20 Scope Mappings โŒ -
21 Users ๐ŸŸก read + update + user-profile schema + credentials + sessions + membership (see detail below); create/delete/reset-password and many sub-resources - โŒ
22 Workflows โŒ -
- OIDC token endpoint โœ… POST /realms/{realm}/protocol/openid-connect/token - ServiceAccountTokenProvider

21 - Users (paths under /admin/realms/{realm})

Method & path Status Notes
GET /users โœ… KeycloakUsersApi::list (infix search), ::findByUsername (exact=true)
POST /users โœ… KeycloakUsersApi::create (read back by exact username)
GET /users/count โœ… KeycloakUsersApi::count
GET /users/profile โœ… KeycloakRealmApi::getUserProfile (attribute schema + per-role perms)
PUT /users/profile โŒ user-profile schema authoring
GET /users/profile/metadata โŒ user-profile metadata (drives proactive form rendering)
GET /users/{user-id} โœ… KeycloakUsersApi::getById
PUT /users/{user-id} โœ… KeycloakUsersApi::update (lossless read-modify-write; also writes replacement credentials)
DELETE /users/{user-id} โŒ user deletion
GET /users/{user-id}/configured-user-storage-credential-types โŒ -
GET /users/{user-id}/consents โŒ -
DELETE /users/{user-id}/consents/{client} โŒ -
GET /users/{user-id}/credentials โœ… KeycloakCredentialsApi::get
DELETE /users/{user-id}/credentials/{credentialId} โœ… KeycloakCredentialsApi::delete
POST /users/{user-id}/credentials/{credentialId}/moveAfter/{newPreviousCredentialId} โŒ reorder credential
POST /users/{user-id}/credentials/{credentialId}/moveToFirst โŒ reorder credential
PUT /users/{user-id}/credentials/{credentialId}/userLabel โŒ rename credential
PUT /users/{user-id}/disable-credential-types โŒ -
PUT /users/{user-id}/execute-actions-email โœ… KeycloakCredentialsApi::executeActionsEmail (array body)
GET /users/{user-id}/federated-identity โŒ -
POST /users/{user-id}/federated-identity/{provider} โŒ -
DELETE /users/{user-id}/federated-identity/{provider} โŒ -
GET /users/{user-id}/groups โœ… KeycloakGroupsApi::getUserGroups
GET /users/{user-id}/groups/count โŒ -
PUT /users/{user-id}/groups/{groupId} โœ… KeycloakGroupsApi::addUserToGroup (body-less)
DELETE /users/{user-id}/groups/{groupId} โœ… KeycloakGroupsApi::removeUserFromGroup
POST /users/{user-id}/impersonation โŒ deliberately not supported: it plants an SSO cookie in the browser (so a server-side call is useless), and it backchannel-logs-out the caller's own session when caller and target share a realm.
POST /users/{user-id}/logout โœ… KeycloakSessionsApi::logoutAll
GET /users/{user-id}/offline-sessions/{clientUuid} โŒ -
PUT /users/{user-id}/reset-password โŒ not needed: KeycloakUser::withCredentials() + update covers the admin-set / pre-hashed case; execute-actions-email preferred
PUT /users/{user-id}/reset-password-email โŒ deprecated alias of execute-actions-email
PUT /users/{user-id}/send-verify-email โŒ
GET /users/{user-id}/sessions โœ… KeycloakSessionsApi::getSessions
GET /users/{user-id}/unmanagedAttributes โŒ -

11 - Groups (paths under /admin/realms/{realm})

Method & path Status Notes
GET /groups โœ… KeycloakGroupsApi::listRealmGroups
POST /groups โŒ group CRUD
GET /groups/count โŒ -
GET /groups/{group-id} โŒ single group
PUT /groups/{group-id} โŒ group CRUD
DELETE /groups/{group-id} โŒ group CRUD
GET /groups/{group-id}/children โŒ sub-group listing
POST /groups/{group-id}/children โŒ sub-group create
GET /groups/{group-id}/members โŒ list users in a group (group-filter data source)
GET /groups/{group-id}/management/permissions โŒ FGAP admin permissions
PUT /groups/{group-id}/management/permissions โŒ FGAP admin permissions

8 - Clients (paths under /admin/realms/{realm})

Method & path Status Notes
GET /clients โœ… KeycloakClientsApi::list โ€” the realm's applications; KeycloakClients::browserLoginable() filters to the browser-loginable ones, KeycloakClient::resolvedUrl() yields an openable URL (rootUrl/baseUrl join, ${authBaseUrl}/${authAdminUrl} substitution, redirect-URI origin fallback)
GET /clients/{id} โŒ single client
POST /clients โŒ client CRUD
PUT /clients/{id} โŒ client CRUD
DELETE /clients/{id} โŒ client CRUD

16 - Realms Admin (paths under /admin/realms)

Method & path Status Notes
GET / โŒ list realms
POST / โŒ create realm
GET /{realm} โŒ realm config (editUsernameAllowed, events flags) - planned KeycloakRealmApi
PUT /{realm} โŒ realm config authoring
DELETE /{realm} โŒ delete realm
GET /{realm}/admin-events โœ… KeycloakEventsApi::getAdminEventsForUser
DELETE /{realm}/admin-events โŒ clear admin events
POST /{realm}/client-description-converter โŒ -
GET /{realm}/client-policies/policies โŒ -
PUT /{realm}/client-policies/policies โŒ -
GET /{realm}/client-policies/profiles โŒ -
PUT /{realm}/client-policies/profiles โŒ -
GET /{realm}/client-session-stats โŒ -
GET /{realm}/client-types โŒ -
PUT /{realm}/client-types โŒ -
GET /{realm}/credential-registrators โŒ -
GET /{realm}/default-default-client-scopes โŒ -
PUT /{realm}/default-default-client-scopes/{clientScopeId} โŒ -
DELETE /{realm}/default-default-client-scopes/{clientScopeId} โŒ -
GET /{realm}/default-groups โŒ -
PUT /{realm}/default-groups/{groupId} โŒ -
DELETE /{realm}/default-groups/{groupId} โŒ -
GET /{realm}/default-optional-client-scopes โŒ -
PUT /{realm}/default-optional-client-scopes/{clientScopeId} โŒ -
DELETE /{realm}/default-optional-client-scopes/{clientScopeId} โŒ -
GET /{realm}/events โœ… KeycloakEventsApi::getUserEvents
DELETE /{realm}/events โŒ clear login events
GET /{realm}/events/config โŒ events flags
PUT /{realm}/events/config โŒ events config authoring
GET /{realm}/group-by-path/{path} โŒ candidate
GET /{realm}/localization โŒ realm i18n
GET /{realm}/localization/{locale} โŒ realm i18n
POST /{realm}/localization/{locale} โŒ realm i18n
DELETE /{realm}/localization/{locale} โŒ realm i18n
GET /{realm}/localization/{locale}/{key} โŒ realm i18n
PUT /{realm}/localization/{locale}/{key} โŒ realm i18n
DELETE /{realm}/localization/{locale}/{key} โŒ realm i18n
POST /{realm}/logout-all โŒ
POST /{realm}/partial-export โŒ -
POST /{realm}/partialImport โŒ -
POST /{realm}/push-revocation โŒ -
DELETE /{realm}/sessions/{session} โŒ
POST /{realm}/testSMTPConnection โŒ realm SMTP config
GET /{realm}/users-management-permissions โŒ FGAP admin permissions
PUT /{realm}/users-management-permissions โŒ FGAP admin permissions

Development Ideas

Package layout (feature-first)

Each feature keeps its interface, implementation, and DTOs together. Interfaces carry the Keycloak prefix so an imported symbol is self-describing inside a larger host codebase.

Unit and Integration Tests

Two tiers:

Log into the Keycloak admin console at http://localhost:9911 with admin / admin. Seeded users all have password changeit.

Two realms are imported so the wire contract is proven in both authorization modes โ€” classic realm-management roles and Fine-Grained Admin Permissions (FGAP). The FGAP realm drives the caller-relative access map (KeycloakUser::$access) and per-caller write authorisation: a user bearer is obtained via the public e2e-login direct-grant client (tests/Support/DirectGrantTokenProvider), so calls run as that user and Keycloak evaluates that user's own grants.

Realm Admin Permissions (FGAP) Notable seeded users / caller identity
test-realm off (classic roles) service account (admin-api, realm-management roles), login-user (none), jane in /staff
test-realm-fgap on admin-user (roles), login-user (none), sarah + jane in /staff, emma in /endusers

FGAP staff policy (baked into realm-import-fgap.json)

Staff read everyone, edit endusers, can't touch other staff:

License

MIT


All versions of keycloak-admin-api with dependencies

PHP Build Version
Package Version
Requires php Version ^8.3
ext-json Version *
psr/http-client Version ^1.0
psr/http-factory Version ^1.0
psr/http-message Version ^1.1 || ^2.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package sandstorm/keycloak-admin-api contains the following files

Loading the files please wait ...