Keycloak
Nova manages users and group memberships in Keycloak through the Admin REST API and additionally provisions AI agents as dedicated service account clients with secret rotation.
What Nova does with Keycloak
- Creates users, resets passwords, and removes accounts on offboarding; a failed password reset is surfaced instead of silently ignored
- Assigns and removes realm group memberships; Nova checks the actual membership state before every write and journals only effective changes
- Provisions AI agents as confidential clients with a service account: create, disable, delete, secret rotation with show-once display, and a configurable token lifetime per client
- Entitlements for AI agents flow through the same group path as for human users, so requests and recertification apply to agents unchanged
- Imports existing groups including nested hierarchies, plus users and agent clients, through background jobs
- Determines the last logon from login events and active sessions, and from client logins for agents
Technical integration
Nova connects through the Keycloak Admin REST API with one realm per target system, authenticating as a confidential client with a service account (client credentials); the required realm-management roles are documented. The health check verifies actual admin permissions, not just a successful login.
In the identity lifecycle
Joiners get their Keycloak account through lifecycle routines and leavers are disabled; when someone leaves, Nova can automatically transfer their AI agents to a deputy or manager. Approved requests are provisioned as group memberships and reconciled against the realm during recertification.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.