Skip to content

Tenant Keycloak Configuration Management

Description

Enables ExpertFlow operations teams to update Keycloak identity provider configuration for a tenant through the tenant management REST API — adding new attributes or modifying existing Keycloak settings without requiring direct database access. Realm name, tenant ID, and tenant name remain immutable to protect identity continuity.

Canonical use case

An ExpertFlow operations engineer needs to add a new SAML attribute mapping to a customer's Keycloak configuration after the customer's Azure AD policy changes. Instead of scheduling a database maintenance window, the engineer calls the tenant update API to patch the Keycloak configuration object and the change takes effect immediately without service interruption.