Directories & identity providers
ConnectorStandard
Keycloak
Nova manages users and group memberships in Keycloak through the Admin REST API and additionally provisions AI agents as dedicated service account clients with secret rotation.
Capabilities
What Nova does with Keycloak
Users and passwords
Creates users, resets passwords, and removes accounts on offboarding; a failed password reset is surfaced instead of silently ignored.
Realm groups
Assigns and removes realm group memberships; Nova checks the actual membership state before every write and journals only effective changes.
AI agents as clients
Provisions AI agents as confidential clients with a service account: create, disable, delete, secret rotation with show-once display, and a configurable token lifetime per client.
Same group path
Entitlements for AI agents flow through the same group path as for human users, so requests and recertification apply to agents unchanged.
Import with hierarchies
Imports existing groups including nested hierarchies, plus users and agent clients, through background jobs.
Last sign-in
Determines the last logon from login events and active sessions, and from client logins for agents.
Technology and process
Integration and identity lifecycle
Technical integration
Nova connects through the Keycloak Admin REST API with one realm per target system, authenticating as a confidential client with a service account (client credentials); the required realm-management roles are documented. The health check verifies actual admin permissions, not just a successful login.
In the identity lifecycle
Joiners get their Keycloak account through lifecycle routines and leavers are disabled; when someone leaves, Nova can automatically transfer their AI agents to a deputy or manager. Approved requests are provisioned as group memberships and reconciled against the realm during recertification.
More in the catalog
Related integrations
Active DirectoryStandard
OpenLDAP & generic LDAPStandard
Microsoft Entra IDStandard
SCIM 2.0Standard
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.
Next step
Ask your questions live on the system.
30 minutes via video call on the demo system: you name your use cases, we show the relevant functions.
Request a demoWhat happens next
- ReplyWe usually get back to you on the same working day and agree a date with you.
- PreparationWe prepare the demo around the topics you name.
- 30 minutes via video callLive on the demo system with fictitious data: you ask, we show the relevant views.