{"repo":"califio/keycloak-recaptcha-password-defense","free":true,"listed":false,"github":"https://github.com/califio/keycloak-recaptcha-password-defense","clone":"git clone https://github.com/califio/keycloak-recaptcha-password-defense.git","description":"Drop-in provider for Keycloak 22+ that detects password leaks and breached credentials with Google reCAPTCHA Enterprise – Password Defense","language":"Java","stars":14,"topics":["credentials-checker","keycloak","keycloak-provider","keycloak-spi"],"license":null,"category":"auth-billing-email","readme_excerpt":"Keycloak reCAPTCHA Password Defense Drop-in provider for Keycloak 22+ that detects password leaks and breached credentials with Google reCAPTCHA Enterprise – Password Defense. Tested with Keycloak 22 - 26. When users log in, if reCAPTCHA flags the credentials as breached: User has another strong factor (OTP / WebAuthn / Passkey) → challenge with that factor, then require a password change. User has no strong factor → disable the account and show a contact-admin message (unless you enable Unsafe mode – Do not disable account ). For password updates and registration, this provider also blocks breached credentials. Implementation follows Google’s documented Private Password Leak Verification flow and uses the official helper library to perform the cryptographic handshake locally so plaintext credentials are never sent to Google. See: Detect password leaks and breached credentials and the Java helper lib recaptcha-password-check-helpers. --- Screenshots --- What’s included This module provides four components you can add to your authentication flows: 1. Authenticator : Username Password Form with reCAPTCHA Password Defense Extends Keycloak’s username/password form; on successful password validation, it checks whether the credentials are breached and applies the policy described above. 2. Conditional : If breached then execute (step-up) A conditional execution that only matches if a breach was detected earlier in the flow. Nest your 2FA executions (OTP, WebAuthn, etc.) under a con","default_branch":null,"files":null,"tree":[],"storefront":"/r/califio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/califio/keycloak-recaptcha-password-defense/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}