Keycloak is the most widely adopted open-source IAM platform with 25K+ GitHub stars, maintained by Red Hat for enterprise-grade authentication and authorization.
Provides SSO, social login, LDAP/AD federation, OpenID Connect, OAuth 2.0, and SAML 2.0 support. Identity brokering connects external providers seamlessly.
Fine-grained authorization with attribute-based, role-based, and policy-based access control. Multi-tenancy through independent realms. Comprehensive admin console.
Self-hosted with no per-user fees, ideal for data sovereignty, compliance, and cost control at scale. Red Hat SSO available for enterprise support.