Keycloak
CMP supports Keycloak as an external identity provider for SSO, social login (Google, GitHub), and 2FA when Keycloak is the active provider.
CMP supports Keycloak as an external identity provider for SSO, social login (Google, GitHub), and 2FA when Keycloak is the active provider.
Keycloak documentation has moved to Platform Features → Identity Providers.
This page covers Keycloak-specific requirements for enabling Single Sign-On (SSO) with CMP. Complete the common prerequisites first. Domain and callback URLs used in Keycloak must match your CMP URLs — see Domain Name / URL.
Create a Zitadel service account (machine user) and Personal Access Token (PAT) so CMP can create or link users during user migration.
Zitadel integration is currently in Beta. It is fully functional for OIDC customer/affiliate authentication and user migration, with continuous enhancements being added.
Step-by-step setup for a Zitadel instance, Stack Console Web/OIDC application, and CMP Social Login configuration.
When transitioning to Zitadel, existing CMP accounts can be migrated so that users can seamlessly sign in through Login with Zitadel using their registered email addresses.