102 Security Tests
Every validation rule is verified with automated tests covering OIDC, SAML, Admin API, and token response security.
Test Categories
Our test suite covers all aspects of Keycloak security validation.
OIDC Validation
15 TestsGrant type enforcement, scope validation, PKCE, state/nonce, redirect URI.
DetailsAdmin API Protection
12 TestsEndpoint whitelist, master realm blocking, export prevention, bulk detection.
DetailsToken Validation
10 TestsJWT algorithm, lifetime, claim leakage, token size, structure validation.
DetailsRedirect URI Security
8 TestsHTTPS enforcement, localhost blocking, private IP blocking, fragment detection.
DetailsRealm & Client Isolation
6 TestsRealm whitelist, client ID validation, per-client policy enforcement.
DetailsRate Limiting
8 TestsPer-IP and per-client rate limiting, connection limiting, brute force detection.
DetailsBidirectional Validation
Request Validation (16 Steps)
Every incoming request passes through the full 16-step validation pipeline:
- OIDC grant type and scope enforcement
- PKCE and state/nonce validation
- Admin API endpoint whitelist
- SAML XXE and signature wrapping prevention
- SQL injection and XSS detection
Response Validation (9 Steps)
Every response from Keycloak is validated before reaching clients:
- JWT algorithm and structure validation
- Token lifetime enforcement
- Claim leakage detection
- Security header enforcement
- Discovery document and JWKS inspection
Compliance Mapping
Our tests are aligned with industry standards and regulations.
ISO 27001
Controls for access control, cryptography, and operational security.
OWASP Top 10
Full coverage of OWASP API Security Top 10 risks.
BSI Grundschutz
IT baseline protection modules for web applications and identity management.
BAIT/VAIT
Financial sector-specific requirements from BaFin.