Directories & identity providers

ConnectorStandard

Keycloak

Nova manages users and group memberships in Keycloak through the Admin REST API and additionally provisions AI agents as dedicated service account clients with secret rotation.

Capabilities

What Nova does with Keycloak

  • Users and passwords

    Creates users, resets passwords, and removes accounts on offboarding; a failed password reset is surfaced instead of silently ignored.

  • Realm groups

    Assigns and removes realm group memberships; Nova checks the actual membership state before every write and journals only effective changes.

  • AI agents as clients

    Provisions AI agents as confidential clients with a service account: create, disable, delete, secret rotation with show-once display, and a configurable token lifetime per client.

  • Same group path

    Entitlements for AI agents flow through the same group path as for human users, so requests and recertification apply to agents unchanged.

  • Import with hierarchies

    Imports existing groups including nested hierarchies, plus users and agent clients, through background jobs.

  • Last sign-in

    Determines the last logon from login events and active sessions, and from client logins for agents.

Technology and process

Integration and identity lifecycle

Technical integration

Nova connects through the Keycloak Admin REST API with one realm per target system, authenticating as a confidential client with a service account (client credentials); the required realm-management roles are documented. The health check verifies actual admin permissions, not just a successful login.

In the identity lifecycle

Joiners get their Keycloak account through lifecycle routines and leavers are disabled; when someone leaves, Nova can automatically transfer their AI agents to a deputy or manager. Approved requests are provisioned as group memberships and reconciled against the realm during recertification.

More in the catalog

Related integrations

All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.

Next step

Ask your questions live on the system.

30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.

Request a demo

What happens next

  1. ReplyWe usually get back to you on the same working day and agree a date with you.
  2. PreparationWe prepare the demo around the topics you name.
  3. 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.