Keymate Logo

Identity & security - Keymate Blog

Category: Identity & security

AI Agent Authorization: From Java Day Demo to Open Source Toolkit

AI Agent Authorization: From Java Day Demo to Open Source Toolkit

At Java Day Istanbul 2026, we asked one question: once an AI agent has a valid token, who decides what data it can reach? This post recaps what we showed on stage, what we open-sourced afterwards, and how the deeper blog series picks up the thread.
Hüseyin Akdoğan

May 2026

Beyond the Default Image: Hardening Keycloak for Enterprise Production

Beyond the Default Image: Hardening Keycloak for Enterprise Production

The default Keycloak image is a strong baseline, not a hardened production runtime. Here is how we rebuilt it on Wolfi OS, with three-tier CVE management, non-root execution, and a Quarkus-optimized runtime.
Ali Tuğrul Pınar

April 2026

What is Keycloak? A Developer's Introduction to Identity and Access Management

What is Keycloak? A Developer's Introduction to Identity and Access Management

Learn what Keycloak is, how Identity and Access Management works, and why Keycloak is the leading open-source IAM solution for modern applications.
Muhammed Oğuz

April 2026

Beyond Bearer Tokens: Implementing DPoP for Modern Enterprise Identity

Beyond Bearer Tokens: Implementing DPoP for Modern Enterprise Identity

Bearer tokens are like cash: anyone who holds them can spend them. DPoP (RFC 9449) binds tokens to cryptographic keys so stolen tokens become useless. Here is how we implemented it.
Eren Kan

April 2026