Allowing users to manage their data
In the previous sections, you learned how to manage users through the admin console as an administrator. You also learned that users can self-register in a realm. However, one of the main capabilities of Keycloak is to also allow users to manage their own accounts through a service called Keycloak account console.
The Keycloak account console is a regular application provided by Keycloak and is where users can manage their own accounts. They can also do the following:
- Update their user profile
- Update their password
- Enable second-factor authentication
- View applications, including what applications they have authenticated to
- View open sessions, including remotely signing out of other sessions
To access the account console, open http://localhost:8080/realms/myrealm/account/
in a browser. You will be redirected to a welcome page, as follows:
Figure 10.10: The Keycloak account console
To log...