List usersFind users in the realm. Search across username, first name, last name and email at once, or filter on any of them individually, and narrow to enabled or verified accounts.
Get userRead one user in full by their Keycloak user ID: username, name, email and whether it is verified, whether the account is enabled, when it was created, and any required actions outstanding.
Create userCreate a user in the realm and return the created record, including the new user ID for later steps. The username must be unique in the realm, and so is the email address when the realm requires one.
Update userChange a user's details. Only the fields you fill in change - everything else is left exactly as it was.
Delete userPermanently delete a user, with their sessions, group memberships and role assignments. This cannot be undone - to block someone's access reversibly, use Update user to disable the account instead.
Reset user passwordSet a user's password. By default the password is temporary, so Keycloak makes the user choose their own at the next sign-in - which is what an administrator setting a password usually wants.
List user sessionsThe user's active sessions: when each started, when it was last used, the IP address it came from and which applications it has reached. An empty list means the user is not signed in anywhere.
List groupsThe realm's top-level groups, each with its path and how many subgroups it has. Search by name to find one anywhere in the tree.
Get groupRead one group: its name, description, full path, parent and attributes.
Create groupCreate a top-level group and return it, including the new group ID for later steps. Group names are unique among their siblings.
Delete groupDelete a group and its subgroups. The members keep their accounts and lose whatever the group granted them.
List group membersThe users in a group. Members of its subgroups are not included - Keycloak treats each group's membership as its own.
Add user to groupPut a user in a group, so they pick up whatever roles and attributes it carries. Adding someone who is already a member changes nothing and is not an error.
Remove user from groupTake a user out of a group. Their account and everything else about it are untouched; they simply lose what the group granted.
List realm rolesThe realm's own roles, with their descriptions and whether each is composite. Roles that belong to a client are listed under that client, not here.
Create realm roleCreate a realm role and return it. Role names are unique in the realm and are how every other role step refers to them, so pick a name you can keep.
Delete realm roleDelete a realm role by name. Everyone who held it loses it immediately, and any composite role built on it loses that part.
Assign realm role to userGive a user a realm role. The role takes effect on their next token, so an already signed-in user picks it up when their session refreshes rather than instantly.
List user's realm rolesThe realm roles assigned directly to a user. Roles they hold only through a group, or through a composite role, are not listed here - Keycloak counts those as effective roles rather than as this user's own.
List clientsThe applications registered in the realm, with each one's UUID, client ID, protocol, redirect URIs and which flows it allows. Search by part of a client ID, or turn off partial matching to look one up exactly.