Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11To publish Keycloak events to Kafka, implement an EventListenerProvider and its EventListenerProviderFactory, package the provider as a JAR, deploy it to Keycloak, and enable it for the realm. The key design choice is when to send: Keycloak invokes listener callbacks within a transaction, so coordinate Kafka publication with transaction completion if a message must not be sent for a transaction that later rolls back.
What the custom event listener does
Keycloak’s Event Listener SPI lets a provider receive user and administrative events. The provider can turn selected event fields into a bounded message and publish it with a Kafka producer. The factory creates provider instances for Keycloak sessions and supplies the listener’s stable provider ID.
| Event family | Callback | What to decide |
|---|---|---|
| User events | onEvent(Event event) |
Which user-event types to publish and which identity fields policy permits. |
| Administrative events | onEvent(AdminEvent adminEvent, boolean includeRepresentation) |
Whether to publish administrative changes and how to handle the optional representation. |
Keycloak’s Event Listener SPI documentation says implementation starts with the EventListenerProvider and EventListenerProviderFactory interfaces. The callbacks run within a Keycloak transaction, which affects delivery timing.
Design the event message before writing the producer
Do not forward an entire event object or administrative representation by default. Define a stable, deliberately limited envelope so consumers receive only the information they need and can handle schema changes.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Include an event type, realm ID, client ID when relevant, timestamp, and schema version.
- Include a user ID or subject only when your data-handling policy allows it.
- Exclude credentials and avoid unbounded representations that can expose sensitive data or create oversized messages.
- Choose a deterministic Kafka key, such as realm plus user, if events for one user need to be ordered together.
Decide which event types are in scope and how consumers will distinguish versions of the envelope. These choices belong to your integration contract; the SPI does not define a Kafka message schema.
Implement the provider and factory
- Implement the provider. Handle user events in
onEvent(Event event)and administrative events inonEvent(AdminEvent adminEvent, boolean includeRepresentation). Map each supported event into the envelope rather than passing Keycloak objects directly to Kafka serialization. - Implement the factory. Have the factory create providers for Keycloak sessions and expose a stable provider ID. Keep the producer lifecycle owned by the provider or another deliberately managed component; make its creation and cleanup fit the lifecycle of the target Keycloak release.
- Register the factory. In the JAR, add a service registration file at
META-INF/services/org.keycloak.events.EventListenerProviderFactory. Put the factory class name in that file. Keycloak’s Server Developer Guide describes service registration files as part of registering SPI implementations. - Add Kafka libraries deliberately. Include only the client libraries needed by the target runtime, then verify class-loader compatibility against the exact Keycloak release you deploy. There is no universal Kafka-client compatibility matrix established for custom listeners, so pin and validate the dependency set in your own environment.
Choose a transaction-aware delivery strategy
Both listener callbacks execute within a Keycloak transaction. Sending synchronously from a callback can add broker latency to login or administrative work and can make authentication success depend on Kafka availability. Decide explicitly whether that coupling is acceptable.
If Kafka publication must occur only after Keycloak commits successfully, use KeycloakTransactionManager.enlistAfterCompletion(...) to hand off the outbound message after successful completion. That establishes the commit boundary; it does not, by itself, provide durable delivery or retries.
- For a simple handoff: define bounded queue capacity and behavior when the queue is full. An in-memory queue can lose work if the server stops before delivery.
- For retryable delivery: define retry limits, timeouts, and a dead-letter path, along with monitoring for messages that cannot be published.
- For duplicates and ordering: specify how consumers identify duplicates and choose a Kafka key based on the ordering guarantees they actually need.
- For broker outages: decide whether authentication and admin operations continue, block, or fail under the selected send strategy.
These queue, retry, and outage policies are implementation decisions; the SPI’s after-completion mechanism only provides a way to align the handoff with transaction completion.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
Build and deploy the JAR
- Build the provider and package it as a Java Archive (JAR), including its service registration file and the required runtime dependencies.
- Copy the provider JAR, plus any required third-party dependencies, into Keycloak’s
providersdirectory. - If you use an optimized Keycloak installation, run
bin/kc.sh buildafter adding the provider. - Start Keycloak and check its startup output for provider or dependency-loading errors before enabling the listener in a realm.
Keycloak’s provider-configuration documentation specifies JAR packaging and placement in the distribution’s providers directory. It also warns that provider JARs run with the server’s privileges: install only code you trust and review its access to event data and external systems.
Enable the listener for a realm
- Open the Keycloak Admin Console and select the realm that should publish events.
- Go to Realm settings → Events → Event listeners.
- Select the custom provider by its stable provider ID, then save the realm settings.
- Configure the event types and retention or detail limits appropriate to the realm and your data policy.
Keycloak can dispatch an event to multiple listeners, so the Kafka listener can coexist with listeners used for logging or database handling.
Rank #4
Validate the integration
Before relying on the listener, verify each part of the path in the deployed Keycloak release:
- Confirm the provider appears in the realm’s event-listener choices after deployment.
- Trigger a user event and, if enabled, an administrative event; confirm each maps to the expected envelope and topic.
- Check that messages use the intended key and contain no credentials or unnecessary representation data.
- Exercise a failed transaction and confirm the chosen strategy does not publish an event that should have been discarded.
- Test broker unavailability, queue saturation if applicable, retries, and duplicate handling against the policy you selected.
These checks are especially important after changing Keycloak versions or Kafka client dependencies, because compatibility depends on the exact runtime combination.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

