Directories & identity providers
Connector

Keycloak

Nova manages users and group memberships in Keycloak through the Admin REST API and additionally provisions AI agents as dedicated service account clients with secret rotation.

What Nova does with Keycloak

Technical integration

Nova connects through the Keycloak Admin REST API with one realm per target system, authenticating as a confidential client with a service account (client credentials); the required realm-management roles are documented. The health check verifies actual admin permissions, not just a successful login.

In the identity lifecycle

Joiners get their Keycloak account through lifecycle routines and leavers are disabled; when someone leaves, Nova can automatically transfer their AI agents to a deputy or manager. Approved requests are provisioned as group memberships and reconciled against the realm during recertification.

All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.