Keycloak Overview

Open-source identity and access management for self-hosted authentication, federation, authorization, and extensible identity workflows.

Keycloak is an open-source Identity and Access Management project for adding authentication and authorization to applications and services. It supports SSO, MFA, user federation, identity brokering, social identity, and fine-grained authorization through standards including OpenID Connect, OAuth 2.0, and SAML 2.0. Organizations operate the community distribution on infrastructure they control, while Red Hat offers a separately supported commercial distribution called Red Hat build of Keycloak.

Keycloak Pricing

The community Keycloak distribution is open source under the Apache License 2.0 and does not use per-user licensing. Self-hosted deployments still carry infrastructure, database, operations, upgrade, monitoring, and support costs. Commercial support is available separately through products and service providers, including Red Hat build of Keycloak.

Get Started with Keycloak →
No affiliate relationship — direct link only.
TypeSelf-Hosted IAM
ProtocolsOIDC / SAML / OAuth 2.0
LicenseApache 2.0 (Free)
DeploymentSelf-Hosted / Kubernetes

What is Keycloak?

Keycloak is an identity server that applications and services can use for authentication, federation, and authorization. Applications integrate through standards such as OpenID Connect, OAuth 2.0, and SAML rather than implementing every identity function independently. The administration model covers realms, clients, users, groups, roles, authentication flows, identity providers, federation, and authorization services.

Realms are isolated identity domains with their own users, clients, roles, and configuration. A Keycloak deployment can host multiple realms, although realm boundaries, tenancy design, operational isolation, and scaling should be planned according to the application architecture rather than assuming one realm per environment or customer.

Operational Fit

  • Organizations that need to control where the identity service and its primary data stores are deployed
  • Environments evaluating self-managed, isolated, or restricted-network identity deployments
  • Engineering teams requiring customizable authentication flows, providers, protocol mappers, themes, or extensions
  • Organizations integrating existing LDAP or Active Directory directories through user federation
  • Application teams evaluating realm-based isolation for multiple identity domains or tenant models
  • Organizations comparing open-source self-hosting costs with per-user managed-IAM licensing

Documented Strengths

  • Community Keycloak uses the Apache License 2.0 and does not impose per-user software licensing
  • Self-hosting gives the operator control over Keycloak deployment location, database placement, backups, and infrastructure
  • Service Provider Interfaces and extension points support custom authentication, user storage, protocol mapping, events, and other identity workflows
  • User federation can connect Keycloak to LDAP and Active Directory without requiring all identities to be migrated into Keycloak
  • The Keycloak Operator supports Kubernetes-based installation and management of Keycloak resources
  • The community project publishes regular releases, documentation, extensions, and operator tooling

Considerations

  • Self-hosting makes the operator responsible for infrastructure, database availability, upgrades, monitoring, backups, security configuration, and capacity planning
  • Production deployments require familiarity with IAM concepts, Keycloak configuration, database operations, TLS, proxying, clustering, and upgrade procedures
  • Community Keycloak does not include a vendor SLA; Red Hat provides a separately packaged and supported Red Hat build of Keycloak based on the community project
  • High-availability and larger deployments require capacity planning for Keycloak, its database, caching, network topology, and clustering behavior

Base Layer Evaluation Notes

Identity Model

Realm-based identity domains operated by the deploying organization. Keycloak manages users, groups, roles, clients, service accounts, identity providers, and federated directories. Realms provide administrative and identity boundaries within a Keycloak deployment.

Authentication & Federation

Standards-based SSO with configurable authentication and identity brokering. Keycloak supports OpenID Connect, OAuth 2.0, SAML, MFA, WebAuthn/passkeys, social and external identity providers, LDAP/Active Directory federation, and configurable authentication flows.

Authorization & Lifecycle

Roles, groups, service accounts, and fine-grained authorization services. Keycloak supports realm and client roles plus resource- and scope-based policies. User lifecycle can be administered directly or connected to external directories and identity sources; broader provisioning workflows may require integrations or extensions.

Deployment & Integration

Self-managed community distribution with container, Kubernetes, and server deployment paths. Operators control infrastructure, database, networking, upgrades, extensions, and availability. Commercially supported distributions such as Red Hat build of Keycloak provide a different support and lifecycle model.

Core Capabilities

Realms & SSO

Each realm is an isolated identity domain with its own users, clients, roles, identity providers, and authentication configuration. A Keycloak deployment can host multiple realms. SSO operates across participating clients within a realm, while logout behavior depends on client protocol support and configuration.

Server Admin Guide →

User Federation

User federation can connect Keycloak to LDAP and Active Directory so existing directory identities can participate in Keycloak authentication flows. Kerberos integration is also available for supported environments, while synchronization, credential validation, and attribute behavior depend on federation configuration.

User Federation docs →

Authorization Services

Authorization Services provide resource-, scope-, permission-, and policy-based authorization beyond basic role checks, including UMA-related capabilities. Applications can query authorization decisions or use supported policy-enforcement integrations; implementation depends on the application stack and authorization model.

Authorization Services →

Extensions & SPIs

Service Provider Interfaces and extension points support custom authentication components, protocol mappers, user-storage providers, event listeners, themes, and other integrations. Extensions become part of the operator’s compatibility and upgrade surface and should be tested against the deployed Keycloak version.

Extensions directory →

Compare Identity & Access Platforms

Compare Keycloak with other identity and access platforms using the same criteria across identity model, authentication and federation, authorization and lifecycle, and deployment and integration.

View Identity & Access Platforms Comparison →
Evaluation note: Base Layer separates documented project capabilities from operational interpretation. Keycloak releases, supported features, deployment guidance, and extension compatibility can change; official Keycloak resources are linked above for verification.

Commercial relationship: Base Layer has no affiliate relationship with the Keycloak project or Red Hat. Links on this page point directly to official project resources.

Review date: October 2026.