Keycloak
Keycloak is a CNCF-incubating open-source identity and access management platform providing SSO, identity brokering, LDAP/AD federation, and fine-grained authorization via OpenID Connect, OAuth 2.0, and SAML 2.0, serving enterprise IT, B2B SaaS, and AI agent deployments globally under Apache 2.0 licensing.
- Company typePrivate
- Founded2014
- Headquarters—
- Headcount—
- GTM typeB2B
- OfferingSoftware
What Keycloak does
Keycloak is an open-source identity and access management (IAM) project originally created in 2014 by co-founders Bill Burke and Stian Thorgersen (originally under Red Hat) and currently incubating under the Cloud Native Computing Foundation (CNCF), part of The Linux Foundation. The project provides single sign-on (SSO), identity brokering and social login, user federation with LDAP and Active Directory, fine-grained authorization services, and clustering via Infinispan distributed caching — all built on the Quarkus framework and supporting OpenID Connect, OAuth 2.0, and SAML 2.0 protocols. The platform is distributed as a standalone server (ZIP/TAR.GZ downloads from keycloak.org), container images on Quay.io, and a Kubernetes/OpenShift Operator on OperatorHub, with client libraries distributed via Maven Central and NPM. Architecture is positioned for cloud-native and air-gapped deployments, including DDIL (Denied, Disrupted, Intermittent, Limited) environments used in field hospitals and tactical medical scenarios.
Keycloak has no direct commercial revenue stream: the software is free under the Apache 2.0 license with no per-user fees, tiered pricing, or feature restrictions, and the project itself is governed as a non-commercial entity. Commercial value is captured indirectly through Red Hat's Red Hat Single Sign-On (a supported distribution of the upstream project), third-party integration partners (e.g., Strata Maverics for healthcare identity orchestration with Epic), and consulting/support services from Red Hat, IBM, Hitachi, and other ecosystem vendors. The project serves three primary customer segments: enterprise IT organizations needing centralized authentication across diverse application portfolios, B2B SaaS companies needing enterprise SSO/SCIM/MFA capabilities without per-seat commercial IAM costs, and AI/ML platform operators needing authorization for AI agents and Model Context Protocol (MCP) tool calls. Key contributors include senior engineers from Red Hat (e.g., Rishabh Singh), IBM (Alexander Schwartz, VP Customer Engineering), and Hitachi (Takashi Norimatsu, Yoshiyuki Tabata), and the project maintains a regular release cadence (versions 25.x through 26.6.3) with active security maintenance and emerging-standard adoption (AuthZEN 1.0, RFC 8693 delegation tokens).
Keycloak firmographics
Firmographics- Name
- Keycloak
- Legal name
- Keycloak
- Website
- https://keycloak.org
- Company type
- Private
- Founded year
- 2014
- Operating status
- Operating
- Short description
- Keycloak is a CNCF-incubating open-source identity and access management platform providing SSO, identity brokering, LDAP/AD federation, and fine-grained authorization via OpenID Connect, OAuth 2.0, and SAML 2.0, serving enterprise IT, B2B SaaS, and AI agent deployments globally under Apache 2.0 licensing.
- Ownership category
- akta.pro rank
Keycloak industry classification
Industry- Product category
- Identity and Access Management
- NAICS
- Computer Systems Design and Related Services (54151)
- akta.pro primary industry
- Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers) (HDAEAJAB)
- akta.pro secondary industries
- Federation & Identity Standards (SAML/OIDC/OAuth, Federation Hubs) (HDADAAAG), Directory Services & Identity Stores (LDAP/AD, Cloud Directory) (HDAEAJAA)
Keywords
Keycloak business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Operations
Revenue model
- Open-Source Software (No Direct Revenue): Keycloak is a free, open-source identity and access management solution. The project does not generate direct revenue from software licensing. The project is maintained by a community of contributors with significant involvement from Red Hat (IBM) engineers. Organizations such as Red Hat commercialize Keycloak by offering support, consulting, and integration services around it.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free Open-Source Edition |
Go-to-market motion2 records
Distribution channels6 records
Marketing channels7 records
Keycloak product offering
Product offeringCore offering
Keycloak is an open-source identity and access management (IAM) platform that provides single sign-on (SSO), identity brokering with social and external IdPs, user federation with LDAP/Active Directory, fine-grained authorization services, and clustering for high availability. It supports standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and is distributed as a standalone server, container image, and Kubernetes Operator for enterprise self-hosting.
Product overview
Keycloak is a unified open-source identity and access management platform positioned as a CNCF incubation project. The core product is the Keycloak Server (powered by Quarkus), which provides single-sign-on, identity brokering, user federation, and fine-grained authorization services. The platform includes client libraries for Java (Admin Client, Authorization Client, Policy Enforcer) and client adapters for JavaScript and Node.js applications. Infrastructure support includes a Kubernetes Operator and container images for cloud-native deployments. The server supports standard protocols including OpenID Connect, OAuth 2.0, and SAML 2.0, and integrates with LDAP and Active Directory user directories.
Differentiator
Problem solved
Functional benefit
Products and services
- Keycloak Server The main open-source identity and access management server powered by Quarkus. Provides single-sign-on, identity brokering, user federation, authorization services, and support for OpenID Connect, OAuth 2.0, and SAML 2.0 protocols for enterprise IT and developer use.
- Keycloak Admin Client Java library (keycloak-admin-client) for programmatically administering Keycloak realms, clients, users, roles, and identity providers via the Admin REST API. Targeted at enterprise developers integrating Keycloak into automation and operational tooling.
- Keycloak Authorization Client Java library (keycloak-authz-client) for integrating fine-grained authorization services into applications, enabling permission management through the Keycloak admin console. Targeted at application developers implementing policy-based access control.
- Keycloak Policy Enforcer Java library (keycloak-policy-enforcer) for enforcing OAuth2-based resource protection and permission-based access control in Java applications.
- Keycloak JavaScript Adapter Browser-side JavaScript library (keycloak-js) for integrating web applications with Keycloak for authentication and token management. Targeted at frontend web developers.
- Keycloak Node.js Adapter Server-side Node.js library (keycloak-connect) for protecting Node.js applications with Keycloak authentication. Targeted at backend Node.js developers.
- Keycloak Operator Kubernetes and OpenShift operator for deploying and managing Keycloak clusters on enterprise Kubernetes environments. Available on OperatorHub. Targeted at platform engineering and SRE teams.
- Keycloak Container Image Container image for Docker, Podman, Kubernetes, and OpenShift deployment of Keycloak server. Hosted on Quay.io. Enables containerized deployment in any container runtime environment.
Quantifiable outcome
- Automatic failover from Microsoft Entra ID to Keycloak within seconds during identity provider degradation, without reconfiguration of Epic EHR
- +2 more outcomes
Companies that use Keycloak
Customer profileNamed customers3 records
Segments4 records
Ideal customer profiles4 records
Keycloak technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
Feature11 records
Keycloak partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and major.
- Red HatcoreRed Hat engineers are primary maintainers and contributors to the Keycloak project. Rishabh Singh from Red Hat presented at KubeCon India 2026 on 'Federated Client Authentication.' Red Hat commercializes Keycloak through Red Hat Single Sign-On, a supported distribution of the open-source project.
- IBMcoreIBM engineers, notably Alexander Schwartz (VP Customer Engineering, IBM), are key contributors and maintainers of Keycloak. Alexander Schwartz authored multiple Keycloak blog posts and is organizing KeycloakCon at KubeCon Japan 2026. IBM leverages Keycloak as part of its cloud native and hybrid cloud identity offerings.
- HitachimajorHitachi engineers Takashi Norimatsu and Yoshiyuki Tabata are Keycloak contributors and presenters at KubeCon Japan 2026. Topics include 'Identities and Authentication for your Agents with Keycloak,' 'CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems,' and 'AuthZEN in Practice.' Hitachi contributes both to the project and to CNCF IAM standardization efforts involving Keycloak.
- Cloud Native Computing Foundation (CNCF)coreKeycloak is a CNCF incubation project. The CNCF provides governance, marketing support, and community infrastructure. Keycloak participates in CNCF events (KubeCon), CNCF TAG Security working groups, and contributes to CNCF identity and access management standardization efforts.
Scale indicators3 records
Recent moves6 records
Expansion highlights7 records
Keycloak competitors and assessment
Company assessmentDirect peers
- Okta: Okta is the leading commercial cloud identity platform offering SSO, MFA, and lifecycle management via OIDC/OAuth/SAML — the same core protocol stack as Keycloak. It is the primary commercial alternative cited in Keycloak's own B2B SaaS positioning.
- Auth0: Auth0 (now an Okta company) provides developer-focused SSO, MFA, and identity APIs targeting B2B SaaS customers, directly overlapping with Keycloak's primary B2B SaaS segment and competing on developer experience and enterprise federation.
- Auth0 by Okta Workforce Identity: Auth0's B2B and B2C identity products remain operated as a distinct platform within Okta and are widely cited alongside Keycloak in developer IAM comparison guides for enterprise SaaS authentication use cases.
Broad incumbents
- Microsoft Entra ID: Microsoft Entra ID (formerly Azure Active Directory) is the identity backbone for Microsoft 365 and Azure, providing SSO, federation, and authorization for enterprise and SaaS workloads. It is the dominant incumbent and the failover source in Keycloak's Epic EHR deployment.
- AWS Cognito: AWS Cognito provides managed user pools and identity federation for applications hosted on AWS, supporting OIDC and SAML. It competes with Keycloak for B2B SaaS and cloud-native deployments, particularly where AWS-native integration is preferred.
- Ping Identity: Ping Identity (merged with ForgeRock) offers enterprise SSO, federation, and identity governance with strong on-premises and hybrid deployment options. It is a direct commercial alternative for the same enterprise IT and regulated-segment buyers Keycloak targets.
- IBM Security Verify: IBM Security Verify is IBM's commercial IAM offering built on the same identity lineage as Keycloak (IBM engineers are Keycloak maintainers). It competes for the same enterprise and hybrid cloud buyers and represents the commercialized path for Keycloak in IBM's portfolio.
Emerging players
- Authentik: Authentik is an open-source SSO/identity provider supporting OIDC, SAML, and LDAP federation with a comparable self-hostable deployment model. It targets the same cost-sensitive, self-hosted customer base as Keycloak, especially in the homelab and SMB segments.
- Ory: Ory provides an open-source identity stack (Ory Kratos, Hydra, Oathkeeper) supporting OIDC, OAuth 2.0, and modern API-first deployments. It targets cloud-native developers and overlaps with Keycloak's API-first, Kubernetes-friendly positioning.
- FusionAuth: FusionAuth is a developer-focused identity platform offering SSO, MFA, and user management with both self-hosted and managed deployment options. It directly competes with Keycloak for B2B SaaS authentication infrastructure use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Keycloak social profiles
Digital presenceKeycloak compliance and trust
Trust signalCompliance1 record
Keycloak financial estimates
Financial estimateRevenue estimate
Valuation estimate
Keycloak leadership team
Management profileNumber of profiles
Profiles1 record
Keycloak funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Keycloak M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Keycloak
What does Keycloak do?
Keycloak is an open-source identity and access management (IAM) platform that provides single sign-on (SSO), identity brokering with social and external IdPs, user federation with LDAP/Active Directory, fine-grained authorization services, and clustering for high availability. It supports standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and is distributed as a standalone server, container image, and Kubernetes Operator for enterprise self-hosting.
Is Keycloak a public or private company?
Keycloak is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Keycloak founded?
Keycloak was founded in 2014.
How does Keycloak make money?
One revenue line is on record: open-Source Software (No Direct Revenue).
Who are Keycloak's main competitors?
Direct peers on record are Okta, Auth0 and Auth0 by Okta Workforce Identity. Broad incumbents are Microsoft Entra ID, AWS Cognito, Ping Identity and IBM Security Verify. Emerging players are Authentik, Ory and FusionAuth.
Does Keycloak have an API?
Yes. Keycloak provides a comprehensive REST-based Admin REST API for managing realms, clients, users, roles, and identity providers. It also includes an Account REST API for user self-service. The platform offers client libraries including Admin Client (keycloak-admin-client), Authorization Client (keycloak-authz-client), and Policy Enforcer (keycloak-policy-enforcer) for Java. The JavaScript adapter (keycloak-js) enables frontend integration, while keycloak-connect provides Node.js support. Keycloak also implements AuthZEN Evaluation and Evaluations APIs for authorization interactions, and supports Model Context Protocol (MCP) for AI agent authorization as demonstrated in integration tutorials. Developer documentation is at www.keycloak.org/documentation.
What industry is Keycloak in?
Keycloak's product category is Identity and Access Management. Its primary akta.pro industry code is HDAEAJAB, Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers), with a secondary code of HDADAAAG, Federation & Identity Standards (SAML/OIDC/OAuth, Federation Hubs). Its NAICS code is 54151.