Skip to content
aicoolies logo
Keycloak logo

Keycloak

Open-source identity and access management

Keycloak is an open-source IAM solution with 25K+ GitHub stars by Red Hat. Provides SSO, social login, LDAP/Active Directory federation, standard protocol support (OIDC, OAuth 2.0, SAML), fine-grained authorization, user federation, and admin console. Features identity brokering, multi-tenancy via realms, and client adapters for Java, JavaScript, and Node.js. Self-hosted with no per-user licensing, making it ideal for organizations needing full control over identity infrastructure.

About Keycloak

Keycloak is the most widely adopted open-source IAM platform with 25K+ GitHub stars, maintained by Red Hat for enterprise-grade authentication and authorization.

Provides SSO, social login, LDAP/AD federation, OpenID Connect, OAuth 2.0, and SAML 2.0 support. Identity brokering connects external providers seamlessly.

Fine-grained authorization with attribute-based, role-based, and policy-based access control. Multi-tenancy through independent realms. Comprehensive admin console.

Self-hosted with no per-user fees, ideal for data sovereignty, compliance, and cost control at scale. Red Hat SSO available for enterprise support.

Pricing & Platform Specs

Pricing Summary

Free and 100% open source under the Apache-2.0 license as a CNCF Incubating project. Keycloak has $0 software licensing fees for self-hosted deployments on Kubernetes (via official Operator), Docker, and bare-metal (Quarkus runtime), with users paying only for underlying compute and database (PostgreSQL/MySQL) infrastructure. For enterprise environments requiring certified distributions and 24/7 mission-critical SLAs, Red Hat provides the commercial 'Red Hat build of Keycloak' (RHBK) with enterprise subscription support, alongside third-party managed cloud offerings (Phase Two, Cloud-IAM).

full pricing breakdown →

Supported Platforms

Self-hosted, Docker, Kubernetes, Java

Explore categories, tags & use cases

Open-source auth infrastructure for modern apps

Logto is an open-source authentication and authorization platform built on OIDC and OAuth 2.1, serving as an alternative to Auth0, Cognito, and Firebase Auth. It provides pre-built sign-in flows with customizable UI, social login, Google One Tap, MFA, enterprise SSO via SAML, and role-based access control. SDKs cover 30+ frameworks including React, Next.js, Vue, Flutter, Go, and Python, with multi-tenancy support for SaaS applications.

freemiumOpen Source

Open-source IAM and SSO platform by Casbin

Casdoor is an open-source Identity and Access Management platform built by the Casbin community in Go and React. Supports OAuth 2.0, OIDC, SAML, CAS, LDAP, SCIM, WebAuthn, and MFA with a comprehensive web-based admin UI. Provides multi-tenant organization management, flexible RBAC and ABAC access control via Casbin models, and integrations with Google Workspace and Azure AD. Offers self-hosted deployment with optional managed cloud plans.

Open Source

Side-by-Side Comparisons

Authentik logo
Authentik
vs
Keycloak logo
Keycloak

Authentik vs Keycloak — Modern Python IdP vs Established Java Identity Platform

Authentik and Keycloak both provide self-hosted open-source identity management but represent different generations of IdP architecture. Authentik is a modern Python-based platform with a cleaner UI and simpler operational model, positioning itself as the accessible alternative. Keycloak is the established Java-based enterprise IdP with the broadest feature set and deepest protocol support, backed by Red Hat.

AuthentikKeycloak
Clerk logo
Clerk
vs
Auth0 logo
Auth0
vs
Keycloak logo
Keycloak

Clerk vs Auth0 vs Keycloak — Authentication Platform Comparison

Three authentication solutions spanning the spectrum from developer-friendly SaaS to enterprise identity platform to self-hosted open-source. Clerk is purpose-built for React and Next.js, Auth0 (by Okta) serves enterprise identity needs, and Keycloak provides full IAM control through open-source self-hosting.

ClerkAuth0Keycloak

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is Keycloak?

Keycloak is an open-source IAM solution with 25K+ GitHub stars by Red Hat. Provides SSO, social login, LDAP/Active Directory federation, standard protocol support (OIDC, OAuth 2.0, SAML), fine-grained authorization, user federation, and admin console. Features identity brokering, multi-tenancy via realms, and client adapters for Java, JavaScript, and Node.js. Self-hosted with no per-user licensing, making it ideal for organizations needing full control over identity infrastructure.

Is Keycloak free?

Yes — Keycloak is open source and free to use. Free and 100% open source under the Apache-2.0 license as a CNCF Incubating project. Keycloak has $0 software licensing fees for self-hosted deployments on Kubernetes (via official Operator), Docker, and bare-metal (Quarkus runtime), with users paying only for underlying compute and database (PostgreSQL/MySQL) infrastructure. For enterprise environments requiring certified distributions and 24/7 mission-critical SLAs, Red Hat provides the commercial 'Red Hat build of Keycloak' (RHBK) with enterprise subscription support, alongside third-party managed cloud offerings (Phase Two, Cloud-IAM).

Is Keycloak open source?

Yes — Keycloak is open source.

Is Keycloak still maintained?

Yes — Keycloak is active. Its listing was last verified on September 6, 2026.

What are the best Keycloak alternatives?

The first editor-selected Keycloak alternatives are Logto, Casdoor.

How does Keycloak score in our review?

The published editorial review lists Keycloak at 88/100 overall across speed, privacy, and developer experience. Check the review's evidence status and test metadata for its verification level.