About Keycloak
Keycloak is an open-source identity and access management server. It lets application teams add authentication and secure services without building their own login system, since Keycloak handles storing users and authenticating them. The project is written in Java, released under the Apache-2.0 license and governed under the Cloud Native Computing Foundation code of conduct.
Keycloak supports standard protocols such as OpenID Connect and SAML, and offers user federation, strong authentication, user management and fine-grained authorization. You can run it from the downloadable distribution using a start-dev command, or use the official Docker image published on Quay for containers and Kubernetes setups. The project provides documentation, a user mailing list and community channels for help, along with guidance for building and testing from source.
Key features
- Single sign-on with OpenID Connect and SAML
- User federation with external directories
- Strong and multi-step authentication options
- Central user and account management
- Fine-grained authorization policies
- Docker image and standalone distribution
Good fit for
- →Adding SSO across internal applications
- →Securing APIs and microservices with tokens
- →Replacing a hand-built login system
- Built with
- Java
- Tags
- identity
- sso
- oidc
- saml
- authentication
- iam
- java
- self-hosted
Keycloak: questions and answers
- What is Keycloak used for?
- Keycloak is an open-source identity and access management server that adds single sign-on, user management and authorization to applications. It is a good fit for adding SSO across internal applications, securing APIs and microservices with tokens, and replacing a hand-built login system.
- Is Keycloak open source?
- Yes. Keycloak is open source under the Apache-2.0 licence. Its source code is on GitHub at keycloak/keycloak and is written mainly in Java.
- Is Keycloak free?
- Yes. Keycloak is open source, so the software itself is free to use.
- Can I self-host Keycloak?
- Yes. Keycloak can be self-hosted on your own server or infrastructure.
- What is Keycloak an alternative to?
- Keycloak is an open-source alternative to Auth0, Okta, Microsoft Entra ID and Ping Identity. Other open-source alternatives to Auth0 include ZITADEL, Authentik and Logto.
- Is Keycloak actively maintained?
- Yes. The most recent commit to Keycloak was on 2 October 2026, and the latest release is 26.8.0, published on 1 October 2026. The project has 37k stars on GitHub.
Open-source alternatives to Keycloak
See all
ZITADEL
Auth & Identity
ZITADEL - Identity infrastructure, simplified for you.
AGPL-3.0vs Auth0★ 15k
Authentik
Auth & Identity
The authentication glue you need.
OSSvs Auth0★ 26k
Logto
Auth & Identity
🧑🚀 Authentication and authorization infrastructure for SaaS and AI apps, built on OIDC
MPL-2.0vs Auth0★ 15k
WSO2 Identity Server
Auth & Identity
Welcome to the WSO2 Identity Server source code! For info on working with the WSO2 Identit
Apache-2.0vs Auth0★ 881
SuperTokens
Auth & Identity
Open Source User Authentication. Build fast, maintain control, with reasonable pricing.
OSSvs Auth0★ 15k
Hanko
Auth & Identity
Open source, privacy-first, and built to scale. Hanko is the fastest way you integrate pas
OSSvs Auth0★ 9k
SaaS alternatives to Keycloak
See all
Auth0
Auth & Identity
Auth0 is an authentication and authorization platform that lets developers add login, single sign-on and access control to apps with SDKs and quickstarts.
SaaS
Okta
Auth & Identity
Cloud identity platform for workforce single sign-on, multifactor authentication and lifecycle management
SaaS
Microsoft Entra ID
Auth & Identity
Microsoft cloud identity service for SSO, MFA and conditional access, formerly Azure AD
SaaS
Ping Identity
Auth & Identity
Enterprise workforce and customer identity management with SSO and MFA
SaaS
OneLogin
Auth & Identity
Cloud single sign-on and MFA for workforce identity, from One Identity
SaaS
Duo Security
Auth & Identity
Cisco's multi-factor authentication and device trust service for workforces
SaaS

