It would be easier to manage functional accounts if they were keycloak users rather than scicat local users. This requires being able to authenticate via keycloak using a user/password without requiring a full OIDC workflow with browser.