AI‑assisted IAM
Identity and access management on Keycloak, OpenID Connect, OAuth 2.0, SAML and OpenFGA, delivered with AI coding agents. Where Keycloak’s configuration stops, I write the Java extension that goes the rest of the way. I also work on Okta and Auth0, and on identity for AI agents and MCP servers.
What I do
-
Identity security review
Your OAuth 2.0 and OpenID Connect setup, reviewed against the OAuth 2.0 Security Best Current Practice (RFC 9700): flows, PKCE, redirect URIs, token lifetimes and storage, client authentication, MFA. Agents help inventory every realm, client and flow; each finding is checked by hand, ranked by risk, and comes with a fix.
Fixed scope. The usual place to start.
-
Identity for AI agents and MCP servers
Give each agent its own client identity instead of a shared API key. Protect MCP servers with OAuth-based authorization. Let an agent act for a user through token exchange (RFC 8693), with narrow scopes and short lifetimes. Check on OpenFGA which agent may use which tool or record, and keep an audit trail of what each agent did and for whom.
Fits when you are connecting AI agents or an MCP server to real customer data.
-
CIAM platform
Design and build a customer identity platform on Keycloak: realm and client model, OIDC, OAuth 2.0 and SAML federation, MFA and passwordless, integration with CRM, billing and existing SSO. Includes the operational side: upgrades, monitoring and incident response.
Fits when you are launching a customer-facing product, or the identity layer was bolted on and is now the bottleneck.
-
Keycloak migration, upgrades and extensions
Move a legacy identity provider, home-grown authentication, or Okta or Auth0 to Keycloak without locking users out. Take an existing Keycloak estate through major version upgrades. Write custom Java extensions (authenticators, user federation, token mappers, event listeners, themes) where the product stops short. Agents draft the extension code, migration scripts and test suites; I review them against the protocol and your rules.
Fits when you are running an unsupported version, have hit a limit you cannot configure around, or your Okta or Auth0 costs have outgrown the product.
-
Authorization design
Replace role checks scattered across services with one central, relationship-based model on OpenFGA, designed against your real access rules, not a textbook example.
Fits when “who can do what” is answered differently in every service.
How the AI part works
Identity work runs against test realms with synthetic users.
- Where I use it
- A telecom operator’s customer identity platform, in a major Keycloak migration now in testing: data and session migration scripts, test suites and the new proxy. A SaaS company’s identity application, APIs and OpenFGA model. A Norwegian ERP software company, where I set up the team’s Claude Code workflow. And keycloak-otp, where 25 of 44 commits are co-authored with Claude Code.
- What the agents do
- Draft code, tests, Keycloak configuration, migration scripts and Java extensions. Read an unfamiliar codebase quickly. Draft decision records, arc42 sections and C4 diagrams. Give a first-pass review of code and designs.
- What stays with me
- Design and security decisions, a line-by-line review of everything that ships, and responsibility for the result.
- Guardrails
- Tests with every change, static analysis and dependency scanning in CI, small pull requests.
- Your rules
- I follow your policy on which tools may see your code, use your approved accounts where you have them, and work without agents where you ask. Secrets and real user data stay out of prompts.
What it produced
Clients are anonymised. Three engagements in full.
- Under 5 minutes
- of user-facing downtime on each of three major Keycloak upgrades.Web platform operator, several hundred sites
- 10,000+ users
- moved from in-house authentication to Keycloak with no planned downtime.SaaS company
- 1 model
- on OpenFGA for per-organisation access, in place of scattered role checks.SaaS company
Stack
Keycloak (including custom SPIs), Okta, Auth0, OIDC, OAuth 2.0, SAML 2.0, SCIM, FIDO2 / WebAuthn, token exchange, OpenFGA, Java, Spring Boot, Claude Code, Codex. ISC2 Certified in Cybersecurity.
Public code: keycloak-otp, email and SMS one-time-password authenticators for Keycloak 26, built with Claude Code.