Long-lived access tokens for REST and gRPC APIs. Works with Keycloak for user authentication.
Documentation β’ Quick Start β’ Discord
AuthKit is an authorization server that works alongside Keycloak to provide long-lived access tokens for REST and gRPC applications and services.
Separation of concerns:
- Keycloak β User authentication (login, sessions, SSO)
- AuthKit β API authorization (tokens, scopes, access control)
β οΈ AuthKit does NOT handle user authentication.
Users must authenticate via Keycloak (or OAuth2/OIDC) before generating API tokens.
sequenceDiagram
participant User
participant Dashboard
participant AuthKit
participant YourAPI
Note over User,Dashboard: One-time: Generate Access Token
User->>Dashboard: 1. Login (via Keycloak)
User->>Dashboard: 2. "Generate New Token"
Dashboard->>AuthKit: 3. Create token (user_id, scopes)
AuthKit->>Dashboard: 4. authkit_abc123...
Dashboard->>User: 5. Display token to copy
Note over User,YourAPI: Ongoing: Use Token in API Calls
User->>YourAPI: 6. API Request (Bearer authkit_abc123...)
YourAPI->>AuthKit: 7. Validate token
AuthKit->>YourAPI: 8. β
Valid + user_id + scopes
YourAPI->>User: 9. Response
Simple Flow:
- Authenticate once - Login to dashboard via Keycloak
- Generate tokens - Create tokens for different apps and environments
- Use anywhere - Copy token and use in apps, scripts, or automation
- Validate automatically - Your API validates tokens with AuthKit on each request
- π Multiple tokens per user - Separate keys for different apps/environments
- π― Custom scopes - Fine-grained permissions per token
- β° Flexible expiration - Set TTL or create permanent tokens
- π Instant revocation - Delete/regenerate from dashboard
- π Usage tracking β See when each token was last used
- π Secure by default β Hashed tokens, encrypted storage
- β‘ High performance - Sub-10ms validation, built for scale
Problem: Keycloak is excellent for user authentication, but it's not designed for API token management:
- β Tokens tied to user sessions (expire when user logs out)
- β No support for long-lived API keys
- β Complex scope management for API endpoints
- β Not optimized for service-to-service auth
Solution: AuthKit handles API authorization separately:
- β Long-lived tokens independent of user sessions
- β Multiple tokens per user (dev, staging, prod)
- β Fine-grained API scopes
- β Built for microservices and automation
Developer Workflows
- Separate tokens for local dev, staging, and production
- Personal access tokens for API testing
CI/CD & Automation
- GitHub Actions, GitLab CI, Jenkins authentication
- Scheduled jobs and cron tasks
Third-Party Integrations
- Partner API access with scoped permissions
- Webhook authentication and validation
Microservices
- Service-to-service authentication
- gRPC authorization
- Separation of concerns β Authentication (Keycloak) vs Authorization (AuthKit)
- Security first β Hashed tokens, audit logs, zero-trust validation
- Stateless validation β No sessions, no shared state
- Hybrid API design β RESTful HTTP and gRPC endpoints, OpenAPI specification
- Self-hostable - Run on your infrastructure or use our cloud
We welcome contributions from the community!
π¬ Join our Discord β Get help and discuss ideas
π Report Issues β Founds a bug?
π€ Contributing Guide β How to contribute
Open-source API authorization β’ MIT Licensed
Website β’ Documentation β’ Discord