Keycloak

Keycloak

Open Source

Open source identity and access management for modern applications and services.

Authentication

Published 29 May 2026 · Last updated 27 September 2026

Scores

Popularity4/5

34.5K GitHub stars, CNCF Incubating project status since 2023, and validated deployments in enterprise, government, and financial sectors worldwide — including the Austrian Business Service Portal (2M+ users) and FAPI-compliant authorization for Japanese banks. Well-known in enterprise Java and Spring Boot circles; less visible to indie developers and the startup ecosystem.

Learning Curve5/5

The realm/client/flow/mapper mental model is unique to Keycloak and requires significant upfront investment — documented case studies show 40+ hours of onboarding effort even for developers with Java experience. The admin UI, while comprehensive, surfaces its full complexity immediately. Non-trivial configurations (custom flows, multi-IdP brokering, LDAP mapping) require deep familiarity with the Server Administration Guide and often trial-and-error.

Flexibility5/5

Supports OAuth 2.0, OIDC, and SAML 2.0 simultaneously, making it compatible with virtually any application stack regardless of language or framework. The Service Provider Interface (SPI) system allows custom user storage providers, custom authenticators, custom event listeners, and custom themes — essentially every layer is extensible. Realm isolation supports arbitrarily complex multi-tenant topologies.

Performance3/5

JVM-based (Quarkus) with non-trivial startup time and memory footprint relative to lightweight auth libraries. Handles high throughput at scale when properly tuned and clustered, but 'properly tuned' requires explicit effort: JVM heap sizing, Infinispan cache configuration, and database connection pooling. Out-of-the-box configuration is not optimised for production load.

Portability5/5

Apache 2.0 licensed, fully self-hosted, and deployable on any infrastructure that runs a JVM: bare-metal servers, Docker, Kubernetes (official Helm chart), or cloud VMs. Because integration is via standard OIDC and SAML protocols, client applications have no Keycloak-specific SDK dependency — migrating away requires only reconfiguring the OIDC endpoints in client applications, not replacing auth code.

About Keycloak

Keycloak is an open-source identity and access management (IAM) platform, a CNCF Incubating project sponsored primarily by Red Hat and licensed under Apache 2.0. It provides centralised authentication and authorisation for applications and services, acting as an identity provider (IdP) that applications delegate sign-in to rather than handling credentials themselves.

Keycloak is standards-based: it implements OAuth 2.0, OpenID Connect, and SAML 2.0, so any application that speaks these protocols can integrate regardless of language or framework. Python, Java, PHP, Go, Ruby, Node.js, and .NET applications all connect through the same OIDC or SAML layer, which makes it a common choice for organisations running several backend ecosystems.

The platform is organised around realms, isolated namespaces for users, clients, and configuration. That makes it practical for multi-tenant deployments where different applications or organisations need separate identity spaces with their own branding, policies, and user bases.

User federation connects Keycloak to existing directories: LDAP and Active Directory sync is built in, and a User Storage SPI (Service Provider Interface) connects any existing user database without migrating data. Identity brokering lets Keycloak sit between an application and external providers such as Entra ID, Okta, Google, or GitHub, handling protocol translation in both directions.

Keycloak runs as a self-hosted Java service built on Quarkus, deployed with Docker, the Kubernetes Operator, or a plain JVM. Red Hat sells a supported distribution, Red Hat build of Keycloak, for enterprises that need SLA-backed support. The community edition is free with no user limits, per-MAU pricing, or feature gating.

Key Features

  • Single Sign-On (SSO) across multiple applications with one login
  • OAuth 2.0, OpenID Connect, and SAML 2.0 in one platform
  • User federation with built-in LDAP and Active Directory sync
  • Identity brokering to Entra ID, Okta, Google, GitHub, and other IdPs
  • Social login (Google, GitHub, Facebook, and more)
  • Multi-factor authentication (TOTP, WebAuthn/passkeys)
  • Realm-based multi-tenancy with per-realm branding, policies, and user bases
  • Fine-grained authorisation services and standard token exchange

Pros

  • Any language or framework integrates through standard OIDC or SAML
  • No per-MAU pricing and no feature gating in the community edition
  • LDAP/AD federation built in, essential for enterprise and on-premise environments
  • CNCF project with Red Hat backing and a supported commercial build
  • Proven in large government and financial deployments

Cons

  • Steep learning curve: realms, clients, flows, and mappers all need understanding before anything works
  • JVM-based, with higher memory and startup overhead than library-based auth
  • Significant operational burden for updates, backups, clustering, and security patches
  • Documentation can feel scattered for non-trivial configurations
  • Admin UI is functional but complex, not designed for rapid onboarding

Keycloak Pricing

Open Source

Tech Stacks with Keycloak

Advanced API (Go)

Project

A high-performance API stack for advanced engineers. Go handles concurrency, PostgreSQL + Redis back the data layer, Prometheus + Grafana provide observability, and Kubernetes can orchestrate containers as an optional addition.

Deploy on:
Authentication add-on:
CI/CD add-on:
Containerization add-on:
Email add-on:
Payments add-on:

Spring Boot API

Project

Production-ready Java REST API with Spring Boot and PostgreSQL (or MySQL and MariaDB), the standard enterprise stack for backend services.

Database:
Deploy on:
Authentication add-on:
CI/CD add-on:
Containerization add-on:
Observability add-on:
Email add-on:
Payments add-on:

Keycloak Self-Hosted

Infrastructure

Run Keycloak as your own identity provider instead of paying per user for a hosted one. Keycloak handles sign-in, single sign-on, and federation for every app that trusts it, PostgreSQL stores realms, users, and sessions, and Docker packages the server for any VPS, cloud instance, or on-premises machine.

Databases

Hosting

Authentication

DevOps

Deploy on:
Reverse Proxy:
Self-Hosted PaaS:
Tunnel add-on:

Tools Related to Keycloak

Works well with Keycloak(3)

Keycloak is the canonical IAM solution for Spring Boot — Spring Security's OAuth2 resource server and client support natively integrates with Keycloak's OIDC endpoints, and Spring Boot is the most common framework paired with Keycloak in enterprise Java environments.

Keycloak can protect NestJS APIs via OIDC JWT verification — NestJS passport-jwt strategy validates tokens issued by Keycloak, a common pattern in enterprise microservice architectures.

Keycloak can protect Express APIs via OIDC JWT bearer token verification — the keycloak-connect middleware or manual JWT validation using Keycloak's public keys.

Alternatives to Keycloak(3)

Both are enterprise-grade IAM platforms; Auth0 is a managed cloud service while Keycloak is self-hosted and open-source — Keycloak trades Auth0's zero-ops convenience for full control, no per-MAU pricing, and LDAP/AD federation.

Keycloak and Clerk solve authentication at different scales and with different philosophies — Clerk is a developer-friendly SaaS for web apps while Keycloak is an enterprise IAM platform designed for SSO across many applications and LDAP/AD federation.

Both are self-hosted open-source auth solutions; BetterAuth is a lightweight TypeScript library embedded in a single app, while Keycloak is a standalone IAM server designed to serve many applications via SSO — different scale and operational model.

Tags

Open SourceSelf-hostableDocker CompatibleWeb DevelopmentAuthenticationWeb

Details

Maintained
Yes