Keycloak: 1. Authenticate
This documentation is part of the Automate with the CLI guide. You can view the complete guide here: Start Keycloak, retrieve its credentials, and modify its configuration programmatically using the Stackhero CLI.
👋 Welcome to the Stackhero documentation!
Stackhero offers a Keycloak cloud service that makes it easy to deploy a production-ready identity provider in just 2 minutes:
- Unlimited users, realms, and clients
- Supports OpenID Connect, OAuth 2.0, SAML 2.0, social login, LDAP, and Active Directory federation
- Custom domain name with built-in HTTPS for secure access (for example, https://login.your-company.com)
- Custom themes: easily brand your login pages, account console, and emails with the included online editor
- Dedicated email server with SPF, DKIM, and DMARC, so account confirmations and password resets are handled for you
- Built-in PostgreSQL database, with the administration console available on its own dedicated, closable port
- One-click updates keep your system up to date without manual intervention
Spend your time building, not configuring: you can try out Stackhero's Keycloak cloud solution in less than 5 minutes.
The simplest way to get started is to log in through your browser. When you run the login command, the CLI opens a web page where you can approve access. No passwords or 2FA codes are entered directly into the CLI.
stackhero login
After logging in, your credentials are stored locally and will be used automatically by future CLI commands.
For fully automated environments such as scripts or CI pipelines, you may prefer a non-interactive access token. You can create one from your dashboard (Account > Access tokens), then export it as an environment variable. The CLI, as well as any script you run, will automatically detect it.
export STACKHERO_TOKEN="usr-xxxxxx:your-token"