Skip to content

Keycloak

Security

An identity and access management server that provides single sign-on with OpenID Connect, OAuth 2.0 and SAML.

Open-source alternative to:

Apache-2.0Self-hostedNot yet assessed
Screenshot of the Keycloak website
Homepage of keycloak.org

What the free edition leaves out

We have not been able to confirm enough from official sources to give a verdict. “Not confirmed” means the official pages we read did not say, so we do not guess.

Open-core feature checklist for Keycloak
FeatureFree editionDetailsSource
SSO / SAMLFreeThe homepage says Keycloak supports OpenID Connect, OAuth 2.0 and SAML and can broker logins to external OIDC or SAML 2.0 identity providers.Source ↗
Role-based access controlFreeThe Server Administration Guide has a section on assigning permissions using roles and groups.Source ↗
Audit logsFreeThe Server Administration Guide describes events as audit streams admins can view and hook into, with sections on auditing admin events and event listeners.Source ↗
Multi-user / teamsFreeThe Server Administration Guide says one deployment can define, store and manage as many realms as there is space for in the database.Source ↗
Backups and restoreNot confirmed––
API accessNot confirmedAvailability of the admin API by edition is not described on the pages checked.Source ↗
Support SLANot confirmed––

Best for

Teams that need self-hosted single sign-on across several applications, with SAML, OIDC and LDAP or Active Directory federation.

Why choose it over Auth0

The code is Apache-2.0 licensed and the project is in the CNCF. It supports OpenID Connect, OAuth 2.0 and SAML, can connect to existing LDAP or Active Directory servers, and can broker external identity providers. You pay no per-user fee to the project.

Where it falls short

You run it yourself, including the database, upgrades and backups. The admin model with realms, clients and flows takes time to learn. Production use should specify an external database (the dev-file default is deprecated in production mode); building an optimized image is recommended but not required.

Open-source alternative to

  • Auth0 — Keycloak adds login, user federation and social or identity-provider brokering to applications, so it can replace Auth0 when you want to host it yourself. This is a replacement use, not an official claim by the project.
  • Okta — Keycloak is a self-hosted identity provider with SSO, SAML and OIDC, so it can replace Okta for login and user management. This is a replacement use, not an official claim by the project.

Category

Security

Topics

Tech stack

Languages as reported by GitHub for the repository.

Share: