# Callback (hook) on User creation

**URL:** <https://forum.keycloak.org/t/callback-hook-on-user-creation/5259>\
**Category:** Configuring the server\
**Created:** [October 8, 2020, 4:40pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259 "2020-10-08T16:40:33Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 8, 2020, 4:40pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/1 "2020-10-08T16:40:33Z")

</div>

I wonder if there is something like a hook or a callback to activate, either programmatically or via admin console, to trigger some action (call a remote service, for ex.) when a new User is created via admin console?

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [October 8, 2020, 7:15pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/2 "2020-10-08T19:15:16Z")

</div>

Hi,

take a look at the spi-event-listener example in [https://github.com/zonaut/keycloak-extensions](https://github.com/zonaut/keycloak-extensions) and see if this helps you further.

---

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 9, 2020, 7:35am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/3 "2020-10-09T07:35:29Z")

</div>

O, cool, good to know! Thank you for sharing that. 👍

---

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 9, 2020, 7:55am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/4 "2020-10-09T07:55:21Z")

</div>

@zonaut, it is not clear enought how to proceed after copying the `spi-event-listener-0.0.1-SNAPSHOT.jar` into `~/keycloak-11.0.2/standalone/deployments` foldder (I’m using a standalone instance of Keycloak). Should I create a custom class implementing `EventListenerProviderFactory` as it is done in this code-source [example](https://github.com/zonaut/keycloak-extensions/blob/master/spi-event-listener/src/main/java/com/zonaut/keycloak/extensions/events/logging/PlaceholderEventListenerProviderFactory.java) or there is another way to go? Thank you.

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [October 9, 2020, 8:21am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/5 "2020-10-09T08:21:55Z")

</div>

After deployment you need to configure it.  
Take a loot at the readme file on how to set it up [https://github.com/zonaut/keycloak-extensions/blob/master/spi-event-listener/README.md](https://github.com/zonaut/keycloak-extensions/blob/master/spi-event-listener/README.md) -\> Keycloak admin console configuration  
If it isn’t detected try to restart Keycloak so it’s picked up.

---

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 9, 2020, 9:37am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/6 "2020-10-09T09:37:49Z")

</div>

I’ve already done all that is described in [README](https://github.com/zonaut/keycloak-extensions/blob/master/spi-event-listener/README.md) of the extension. The question is what is next after

> select our pl\_event\_listener

Imagine that I’d like to trigger an action once a new user is created via Admin Console. How to branch the Kycloak listener to an external service (no matter, Kafka, a Java micro-service, etc.)?

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [October 9, 2020, 9:58am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/7 "2020-10-09T09:58:56Z")

</div>

Have you taken a look at the [UserVerifiedTransaction](https://github.com/zonaut/keycloak-extensions/blob/master/spi-event-listener/src/main/java/com/zonaut/keycloak/extensions/events/logging/UserVerifiedTransaction.java) example which is executed on the event(s) you listen on and calls an external service through an API call.  
The call `session.getTransactionManager().enlistPrepare(userVerifiedTransaction);` executes this call, you probably will need to do this on the AdminEvent listener

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [October 9, 2020, 10:13am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/8 "2020-10-09T10:13:22Z")

</div>

You’ll probably be interested in

- `onEvent(AdminEvent adminEvent, boolean b) -> ResourceType.USER + OperationType.CREATE`

---

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 9, 2020, 10:20am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/9 "2020-10-09T10:20:20Z")

</div>

As far as I understood, I’ll have to override `public void onEvent(AdminEvent adminEvent, boolean b) ` method to be able to listen to admin events. An instance of `AdminEvent` has some methods, especially the `getOperationType()` could be interesting which returns an `OperationType` enum or the `getResourceType()` method that returns an Enum of `ResourceType`, where the one of [USER](https://www.keycloak.org/docs-api/11.0/javadocs/org/keycloak/events/admin/ResourceType.html#USER) could be interested. Right?

---

<div class="post-metadata">

**Author:** ![belgoros](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/belgoros/32/1380_2.png) [@belgoros](https://forum.keycloak.org/u/belgoros)\
**Post date:** [October 9, 2020, 10:20am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/10 "2020-10-09T10:20:53Z")

</div>

Yep, you were faster this time 😃 So, I have to:

- create a separate micro-service
- package it as a jar
- deploy the jar into the `~/keycloak-11.0.2/standalone/deployments` folder.

Right?

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [October 9, 2020, 11:03am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/12 "2020-10-09T11:03:10Z")

</div>

Yes, that sounds about right.  
Good luck and let us know how it went.

---

<div class="post-metadata">

**Author:** ![lokeshpkumar](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lokeshpkumar/32/2662_2.png) [@lokeshpkumar](https://forum.keycloak.org/u/lokeshpkumar)\
**Post date:** [March 19, 2021, 8:54am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/13 "2021-03-19T08:54:36Z")

</div>

How do we get the user details for the DELETE callback. I mean when a user gets deleted I want the user details as well, currently they are null?

---

<div class="post-metadata">

**Author:** ![harold](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/harold/32/3876_2.png) [@harold](https://forum.keycloak.org/u/harold)\
**Post date:** [October 11, 2021, 7:51am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/14 "2021-10-11T07:51:11Z")

</div>

Did you find an answer for the DELETE callback ?  
I saw the discussion about pre-delete event but I don’t see how implement it.

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [October 11, 2021, 10:45am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/15 "2021-10-11T10:45:49Z")

</div>

The other way to get a user deletion event is to register a `ProviderEventListener` of type `UserModel.UserRemovedEvent` with the `KeycloakSessionFactory`. You can set this up in the `postInit` method of any `ProviderFactory` you create.

```java
  @Override
  public void postInit(KeycloakSessionFactory factory) {
    factory.register(
        (event) -> {
          if (event instanceof UserModel.UserRemovedEvent)
            //do something here with the UserRemovedEvent
            //the user is available via event.getUser()
        });
  }

```

javadoc for the event is here:  
[https://www.keycloak.org/docs-api/15.0/javadocs/org/keycloak/models/UserModel.UserRemovedEvent.html](https://www.keycloak.org/docs-api/15.0/javadocs/org/keycloak/models/UserModel.UserRemovedEvent.html)

---

<div class="post-metadata">

**Author:** ![Luthien](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/luthien/32/982_2.png) [@Luthien](https://forum.keycloak.org/u/Luthien)\
**Post date:** [October 28, 2021, 5:07pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/16 "2021-10-28T17:07:01Z")

</div>

> [@xgp](#):
>
> to register a `ProviderEventListener` of type `UserModel.UserRemovedEvent` with the `KeycloakSessionFactory`

Brilliant, this was exactly what I was looking for. Thanks 💏

---

<div class="post-metadata">

**Author:** ![scottyJamison](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@scottyJamison](https://forum.keycloak.org/u/scottyJamison)\
**Post date:** [May 19, 2022, 9:59pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/17 "2022-05-19T21:59:12Z")

</div>

I was able to follow along in this thread and hook into the user-creation process via a custom extension, which is great! I’m just left with one issue.

When a user is created, we’re sending an event off to our own servers to let it do some user-creation tasks as well. Our servers may reject for a number of reasons, like, the username including certain characters we do not support, or, maybe our server is just down at the moment and can’t pick up the request. Either way, we’d like to it if the user did not get created in these scenarios.

When the user-creation is rejected for whatever reason, we’re currently throwing a RuntimeException within our keycloak extension. I had hoped this would cancel the user creation process and put everything back to how it was. Instead, it seems the user is being created within ldap anyways, but keycloak itself is unaware of the new, partially-created user until I sync the two.

The keycloak APIs have all of this transaction/rollback logic built into it, which makes it sound like its supposed to be able to gracefully support these sorts of errors. Is this a bug, or is there something I need to be doing differently?

(If needed, I can put together a minimal extension to reproduce the problem and report it if this really is a bug)

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [May 20, 2022, 6:14am UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/18 "2022-05-20T06:14:49Z")

</div>

What you are describing sound correct. However, I have spent the last month on a project related to transactions in Keycloak, and while their approach sounds good, I have found it lacking in execution. There are cases where, when dealing with a remote system, they don’t really make an attempt to manually rollback a transaction if there is no integrated, built-in transaction mechanism in the remote system. Although I don’t know if that’s the problem in your LDAP scenario, but it’s my guess.

---

<div class="post-metadata">

**Author:** ![scottyJamison](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@scottyJamison](https://forum.keycloak.org/u/scottyJamison)\
**Post date:** [May 20, 2022, 2:23pm UTC](https://forum.keycloak.org/t/callback-hook-on-user-creation/5259/19 "2022-05-20T14:23:04Z")

</div>

Worst comes to worse, I guess I could always try deleting the user myself if a network error occurs. I’m sure they provide some sort of API to do so, though I may need to first tell it to sync with ldap before I can delete. I’m just a bit scared of doing that - deleting the user being created while we’re in the middle of the user-creation process sounds like a recipe for disaster - even if keycloak doesn’t choke on that now, it might in a future version.
