Keycloak
SecurityAn identity and access management server that provides single sign-on with OpenID Connect, OAuth 2.0 and SAML.

What the free edition leaves out
We have not been able to confirm enough from official sources to give a verdict. “Not confirmed” means the official pages we read did not say, so we do not guess.
| Feature | Free edition | Details | Source |
|---|---|---|---|
| SSO / SAML | Free | The homepage says Keycloak supports OpenID Connect, OAuth 2.0 and SAML and can broker logins to external OIDC or SAML 2.0 identity providers. | Source ↗ |
| Role-based access control | Free | The Server Administration Guide has a section on assigning permissions using roles and groups. | Source ↗ |
| Audit logs | Free | The Server Administration Guide describes events as audit streams admins can view and hook into, with sections on auditing admin events and event listeners. | Source ↗ |
| Multi-user / teams | Free | The Server Administration Guide says one deployment can define, store and manage as many realms as there is space for in the database. | Source ↗ |
| Backups and restore | Not confirmed | – | – |
| API access | Not confirmed | Availability of the admin API by edition is not described on the pages checked. | Source ↗ |
| Support SLA | Not confirmed | – | – |
Best for
Teams that need self-hosted single sign-on across several applications, with SAML, OIDC and LDAP or Active Directory federation.
Why choose it over Auth0
The code is Apache-2.0 licensed and the project is in the CNCF. It supports OpenID Connect, OAuth 2.0 and SAML, can connect to existing LDAP or Active Directory servers, and can broker external identity providers. You pay no per-user fee to the project.
Where it falls short
You run it yourself, including the database, upgrades and backups. The admin model with realms, clients and flows takes time to learn. Production use should specify an external database (the dev-file default is deprecated in production mode); building an optimized image is recommended but not required.
Open-source alternative to
- Auth0 — Keycloak adds login, user federation and social or identity-provider brokering to applications, so it can replace Auth0 when you want to host it yourself. This is a replacement use, not an official claim by the project.
- Okta — Keycloak is a self-hosted identity provider with SSO, SAML and OIDC, so it can replace Okta for login and user management. This is a replacement use, not an official claim by the project.
Category
SecurityTopics
Tech stack
Languages as reported by GitHub for the repository.