
Keycloak Recovery Codes, Broader connectivity with the ability to broker with any OAuth 2.
Keycloak Recovery Codes, Switch on the Forgot Password switch. Cheers, Thomas If you enable it, users are able to reset their credentials if they forget their password or lose their OTP generator. Aug 21, 2025 · Actual behavior As soon as a user has configured at least one 2FA option, e. . Jun 24, 2024 · When enabling the recovery codes functionality, it no longer shows up under the Account Console. See this video for all the details you have to know! Don’t forget to subscribe to my YouTube channel! Example sourcecodes (even if they are not used in this video) are available on my GitHub repository: Jul 3, 2025 · To prepare for such a case, the recovery codes feature allows users to print a set of recovery codes as an additional second factor. Nov 2, 2021 · We would like to propose a solution which will deliver a functionality to generate recovery authentication codes that can be printed or stored in a safe location. The Recovery Codes are a number of sequential one-time passwords (currently 12) auto-generated by Keycloak. Broader connectivity with the ability to broker with any OAuth 2. Addition info: Using a custom Jul 3, 2025 · Account recovery with 2FA recovery codes, protecting users from lockout. May 20, 2021 · The remaining backup codes are visible in the account-console on the Account-Security page. I’ve been able to get it to show the generated recovery codes screen to users after OTP setup but not sure how to give users access to using a recovery code? Apr 25, 2023 · Keycloak comes with this option out-of-the-box! You just have to enable the feature and configure the authentication flow appropriately. Oct 20, 2025 · Technically the recovery codes are twelve sequential one-time passwords auto-generated by Keycloak. These options are standard configuration options, so they can be specified in any of the configuration sources such as environment variables or CLI parameters. Bootstrapping a temporary admin account at Keycloak startup Keycloak start and start-dev commands support options for bootstrapping both temporary admin users and admin service accounts. For details on how to reproduce this follow the steps in this tutorial by @dasniko. If the recovery codes are then allowed as an alternative 2FA in the login flow, they can be used instead of the OTP generated passwords. g. When that code is introduced, it is removed and the following code will be required in the subsequent login. 0 URI scheme Jul 28, 2022 · Hi Community, I’ve enabled the preview feature recovery_codes. I wonder whether the PoC can be turned into a built-in Keycloak feature, as the building blocks are mostly there. Instead of showing a list of backup codes in the UI, it would be better just to show that backup codes are present. OTP and the auth flow has enabled OTP and Recovery Codes as Alternatives for 2FA, the "try another way" link will be shown and the credentials selection screen will offer Recovery Codes, although the user hasn't configured them as credential. Version information Version: 1. 0 compliant authorization server, and enhanced trusted email verification The Recovery Codes are a number of sequential one-time passwords (currently 12) auto-generated by Keycloak. How to Reproduce? The Recovery Codes are a number of sequential one-time passwords (currently 12) auto-generated by {project_name}. The authentication process asks the user for the next generated code in order. Go to the Realm Settings left menu item, and click on the Login tab. Mar 24, 2023 · I’m trying to set up the recovery codes preview feature. Should this be configurable? We can possibly make it as configuration option of recovery codes required action similarly like War WorkflowStateRepresentation WorkflowStepRepresentation Overview This is a REST API reference for the Keycloak Admin REST API. I’ve been able to get it to show the generated recovery codes screen to users after OTP setup but not sure how to give users access to using a recovery code? The only mention of recovery codes in the documentation seems to be this Server Administration Guide but it doesn’t explain the full setup. The Recovery Codes are a number of sequential one-time passwords (currently 12) auto-generated by {project_name}. Simplified experiences for application developers with streamlined WebAuthn/Passkey registration and simplified account linking to identity providers via application initiated actions. The codes can be used as a 2nd Factor Authentication (2FA) by adding the Recovery Authentication Code Form authenticator to your authentication flow. The option Warning threshold is the configuration option of the recovery codes required action already. Any hint on how to activate/use them? Thanks リカバリーコードは、Red Hat build of Keycloak によって自動生成される、連続したワンタイムパスワード (現在 12 個) です。認証フローに Recovery Authentication Code Form オーセンティケーターを追加することで、コードを第 2 要素認証 (2FA) として使用できます。フロー内で設定すると、Red Hat build of Keycloak Apr 28, 2025 · Do you want to generate new set of codes? with options to generate new codes (Which would add required action to authenticationSession or UserModel probably) or continue with authentication. Apr 28, 2025 · Description When user generates set of recovery codes, the count of the codes is currently hardcoded to 12. 9ey, t7gb4, avk, ptix, vjm, hwmn, wlxzlju, okw, hwbs, nqcd,