Keycloak at FOSDEM 2026
Published on February 3, 2026 by Thomas Darimont

A few days have passed since FOSDEM 2026, and it was once again great to see so much interest in identity and access management in the free and open-source community.
 
Over the weekend of January 31st and February 1st in Brussels, a few Keycloak-related talks in the Identity and Access Management Devroom took place on Sunday, covering a wide range of topics and sparking many good discussions. Thanks to everyone who attended the sessions, asked questions, and shared feedback. 

We also really enjoyed meeting people at the Keycloak stand — from long-time contributors to first-time users — and collaborating, exchanging ideas, and hacking on problems together. If you stopped by to chat or help out: thank you! 

If you missed the talks or conversations, we’ll be following up with links, slides, and next steps in the sections below.

As security threats become more sophisticated, the need for efficient, real-time communication between identity providers and relying parties is essential. The Shared Signals Framework (SSF) and related specifications such as CAEP and RISC address this challenge by providing a standardised way for systems to exchange security related signals, such as session revocations, credential breaches, and other identity-related incidents, in a secure and scalable manner. This talk introduces the Shared Signals Framework and explains how it enhances security and operational efficiency in modern identity ecosystems. We’ll explore how SSF can be supported in Keycloak to enable real-time event-driven communication between providers and relying parties. Attendees will learn how Keycloak can help to detect and mitigate threats, and improve overall system security with SSF.

OAuth 2.0 and OpenID Connect have been around for years to secure web and mobile applications alike with growing popularity.

To keep your applications and their data secure, these standards are evolving to align with security best practices.

Join this talk to see how the FAPI 2.0 Security Profile and the upcoming OAuth 2.1 standard promotes and enforces best practices, how to adapt your applications, and how Keycloak as an Open Source IAM can help you. Expect a demo and examples for some of the enhancements.