Keycloak
Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications.
- GitHub stars
- 37k
- Last commit
- today
- Latest release
- 26.8.0
- Licence
- Apache-2.0
- Self-hosted
- Yes

Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.
Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.
Key features
- Single sign-on with OpenID Connect and SAML
- User federation with external directories
- Strong and multi-step authentication options
- Central user and account management
- Fine-grained authorization policies
- Docker image and standalone distribution
Pricing: Free and open source under the Apache-2.0 license; you host and operate it yourself.





