# What is Gatekeeper?

**URL:** <https://forum.keycloak.org/t/what-is-gatekeeper/934>\
**Category:** Getting advice\
**Tags:** gatekeeper\
**Created:** [January 13, 2020, 6:50pm UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934 "2020-01-13T18:50:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharpedavid](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sharpedavid/32/463_2.png) [@sharpedavid](https://forum.keycloak.org/u/sharpedavid)\
**Post date:** [January 13, 2020, 6:50pm UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934/1 "2020-01-13T18:50:51Z")

</div>

The current Keycloak documentation has a table of contents like this:

- OpenID Connect
  - Java Adapters
  - Javascript Adapter
  - Node.js Adapter
  - Keycloak Gatekeeper

And the entry for Gatekeeper reads:

> Keycloak provides a Go programming language adapter for use with OpenID Connect (OIDC) that supports both access tokens in a browser cookie or bearer tokens.

Now, I’m new to Keycloak so I assume someone more experienced wouldn’t have this difficulty, but I read this as we have a Java adapter, a JavaScript adapter, a Node.js adapter, and a Go adapter.

It wasn’t until I went to the [Downloads](https://www.keycloak.org/downloads.html) page and saw the Server and Gatekeeper download at the very top, listed separately from the language adapters, that I knew for certain Gatekeeper must be a different kind of thing.

So where in all the documentation is a high-level description of what Gatekeeper _is_? I can see a clue in the documentation URL – [Securing Applications and Services Guide](https://www.keycloak.org/docs/latest/securing_apps/index.html#_keycloak_generic_adapter) – it’s a “generic adapter”, but the documentation never actually says this, it just launches immediately in to how to configure it.

Is there some blog post or documentation that _introduces_ Gatekeeper, its architecture, its features, and when it should be used?

p.s. Keycloak looks really great and I’m excited to use it. The tone of this post sounds a bit angry maybe, but I’m really just looking for advice.

---

<div class="post-metadata">

**Author:** ![jangaraj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jangaraj/32/5175_2.png) [@jangaraj](https://forum.keycloak.org/u/jangaraj)\
**Post date:** [January 13, 2020, 11:33pm UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934/2 "2020-01-13T23:33:35Z")

</div>

IMHO “Go programming language adapter” isn’t correct definition.

I would say: Keycloak Gatekeeper is authentication (optional authorization) proxy application written in Golang. Recommended usage is when used app/lib doesn’t support grant code flow (sorry not designated for SPA apps), but it is able to read user identity from request headers. It is good solution for dockerized environment due to small memory footprint, stateless functionality, horizontal scaling ability, … It was originally community project, so not all Keycloak features are implemented in the Keycloak way (e.g authorization).

It is not coupled deeply with Keycloak =\> it doesn’t introduce any Keycloak vendor lock-in, so it should work with any standard OIDC IdP.

---

<div class="post-metadata">

**Author:** ![abstractj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/abstractj/32/9_2.png) [@abstractj](https://forum.keycloak.org/u/abstractj)\
**Post date:** [January 14, 2020, 10:30am UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934/3 "2020-01-14T10:30:15Z")

</div>

@sharpedavid there’s a lot to improve into our documentation and the links that you mentioned are the only ones available at the moment. if you have any suggestions about how to improve our docs, you’re more than welcome to submit a pull-request to [https://github.com/keycloak/keycloak-documentation/blob/master/securing\_apps/topics/oidc/keycloak-gatekeeper.adoc](https://github.com/keycloak/keycloak-documentation/blob/master/securing_apps/topics/oidc/keycloak-gatekeeper.adoc) or [https://github.com/keycloak/keycloak-web](https://github.com/keycloak/keycloak-web) //cc @jangaraj

@jangaraj your definition makes sense to me. The only word that we avoid all the time is “proxy”, because the goal of Gatekeeper is to act more like a sidecar protecting apps, instead of act like a proxy and provide things like load-balancing and proxy related functionality.

---

<div class="post-metadata">

**Author:** ![sharpedavid](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sharpedavid/32/463_2.png) [@sharpedavid](https://forum.keycloak.org/u/sharpedavid)\
**Post date:** [January 14, 2020, 5:49pm UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934/4 "2020-01-14T17:49:38Z")

</div>

> [@abstractj](#):
>
> there’s a lot to improve into our documentation and the links that you mentioned are the only ones available at the moment. if you have any suggestions about how to improve our docs, you’re more than welcome to submit a pull-request

Because I only just learned what Gatekeeper is (thanks to this forum thread), I don’t think I"m a good person to write an official description of Gatekeeper. I hope @jangaraj has some time to submit a pull-request, because I really think a basic description of Gatekeeper would help adoption: people aren’t going to use it if they don’t even know what _it_ is.

---

<div class="post-metadata">

**Author:** ![sharpedavid](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sharpedavid/32/463_2.png) [@sharpedavid](https://forum.keycloak.org/u/sharpedavid)\
**Post date:** [March 11, 2020, 5:45pm UTC](https://forum.keycloak.org/t/what-is-gatekeeper/934/5 "2020-03-11T17:45:15Z")

</div>

I have discovered a good way to learn more about Gatekeeper. In September 2018 Gatekeeper was renamed from [Keycloak Proxy](https://github.com/keycloak/keycloak-gatekeeper/blob/b3073403a8872c37286d2f15f539389a558d7a7a/README.md). If you Google “Keycloak Proxy”, you will find many more blog posts and videos. I particularly liked [this one](https://github.com/YunSangJun/keycloak-proxy-demo) because it has a sequence diagram.
