Managing Your Account & Passkeys
Your account across The Nest is managed by Keycloak, our central identity and access platform. Keycloak acts as the digital keyring for all services, ensuring your login experience is seamless, consistent, and passwordless.
What Keycloak Does
Keycloak works behind the scenes to handle three core functions:
- Single Sign-On (SSO): Log in once to gain access to all connected Nest applications (such as Matrix, Forgejo, or Vaultwarden).
- Passwordless Authentication: Securely verifies your identity using WebAuthn passkeys instead of traditional passwords.
- Group Access Control: Grants or restricts access to specific services based on your account's group memberships.
Group-Based Permissions
Your access to different applications across The Nest is managed through Keycloak Groups. In most cases, group names match the service they unlock (for example, belonging to the foundry-vtt group gives you access to Foundry VTT).
To request access to additional services, please see the Requesting Service Access guide.
Account Recovery
If you lose access to all of your enrolled devices or passkeys:
- Reach out to an administrator on Matrix in the Ask an Admin room in the Admin space.
- Verify your identity using the email address linked to your account.
- An administrator will send you a secure recovery link to reset your credentials and register a new passkey.
5. Service Summary & Related Links
| Component | URL / Endpoint | Purpose |
|---|---|---|
| Keycloak | sso.mynest.love | Account, identity, and authorization |
| Official Docs | Keycloak Docs | The official Keycloak docs |