Keycloak 26.7: news, updates and new features
Keycloak 26.7 Release: news and updates
Keycloak has released the new version 26.7 of its open source platform for authentication and authorization management.
The new release introduces several features designed to simplify the management of corporate IT architectures and strengthen their security. Among the main new features are support for open standards to automate user provisioning and a new, simpler approach to managing high availability in multi-cluster environments.
Automating user provisioning through SCIM APIs
The integration of the SCIM (System for Cross-domain Identity Management) standard makes it possible to automate the management and provisioning of users and groups between Keycloak and external applications or systems, such as HR platforms and Identity Governance solutions.
The SCIM API, introduced as a preview feature, supports the main CRUD and PATCH operations, as well as filtering, pagination, and schema extension capabilities.
Ready-Made Templates
Are you looking for an IAM system?Visit the Yookey website to discover the available solutions.
Simplified multi-cluster high availability
The new multi-cluster architecture (v2) simplifies the management of distributed environments by eliminating the need to deploy and administer an external Infinispan cluster and fencing infrastructures dedicated to session replication between different sites.
With this architecture, Keycloak instances communicate directly through the integrated Infinispan caches and use a synchronously replicated database as the single source of truth.
Step-up Authentication for SAML clients
The step-up authentication feature, which allows a higher level of authentication to be applied when particularly sensitive operations are performed, is now also available for the SAML protocol.
SAML Service Providers can specify specific authentication context classes in their requests. With the 26.7 release, this feature moves out of the preview phase and becomes officially supported.
Enhanced security for the Identity Brokering API
The second version of the API dedicated to retrieving tokens issued by external identity providers replaces the previous V1 API with a more secure implementation that is more closely aligned with standards.
New features include access control at the client level, excluding public clients, compliance with OAuth 2.0, and the ability to store tokens directly within the user session, with their automatic removal upon expiration.
To explore all the details of the new version of Keycloak, consult the official Keycloak 26.7 release.
Yookey, the IAM solution based on Keycloak
Yookey is an Identity and Access Management (IAM) platform based on Keycloak, designed to ensure secure and structured management of digital identities and access to resources, applications, and services.
The solution simplifies and makes onboarding and offboarding activities more secure, thanks to integration with Single Sign-On (SSO) and the automation of access management processes. The adoption of multi-factor authentication (MFA) mechanisms also makes it possible to increase the level of account protection from the first access.
The entire identity lifecycle is tracked, monitored, and documented in a structured manner, supporting the organization in managing regulatory compliance requirements, including those provided for by NIS2 and ISO 27001.
Speak directly with our team for further information.

