Developer docs
API playgroundTry for free, no card

Search company profiles

Keycloak

Full company profile

uuid0008n95

Namestring
Keycloak
Legal namestring
Keycloak
Websiteurl
keycloak.org
Company typeenum
Private
Founded yearint
2014
Descriptiontext

Keycloak is an open-source identity and access management (IAM) project originally created in 2014 by co-founders Bill Burke and Stian Thorgersen (originally under Red Hat) and currently incubating under the Cloud Native Computing Foundation (CNCF), part of The Linux Foundation. The project provides single sign-on (SSO), identity brokering and social login, user federation with LDAP and Active Directory, fine-grained authorization services, and clustering via Infinispan distributed caching — all built on the Quarkus framework and supporting OpenID Connect, OAuth 2.0, and SAML 2.0 protocols. The platform is distributed as a standalone server (ZIP/TAR.GZ downloads from keycloak.org), container images on Quay.io, and a Kubernetes/OpenShift Operator on OperatorHub, with client libraries distributed via Maven Central and NPM. Architecture is positioned for cloud-native and air-gapped deployments, including DDIL (Denied, Disrupted, Intermittent, Limited) environments used in field hospitals and tactical medical scenarios.

Keycloak has no direct commercial revenue stream: the software is free under the Apache 2.0 license with no per-user fees, tiered pricing, or feature restrictions, and the project itself is governed as a non-commercial entity. Commercial value is captured indirectly through Red Hat's Red Hat Single Sign-On (a supported distribution of the upstream project), third-party integration partners (e.g., Strata Maverics for healthcare identity orchestration with Epic), and consulting/support services from Red Hat, IBM, Hitachi, and other ecosystem vendors. The project serves three primary customer segments: enterprise IT organizations needing centralized authentication across diverse application portfolios, B2B SaaS companies needing enterprise SSO/SCIM/MFA capabilities without per-seat commercial IAM costs, and AI/ML platform operators needing authorization for AI agents and Model Context Protocol (MCP) tool calls. Key contributors include senior engineers from Red Hat (e.g., Rishabh Singh), IBM (Alexander Schwartz, VP Customer Engineering), and Hitachi (Takashi Norimatsu, Yoshiyuki Tabata), and the project maintains a regular release cadence (versions 25.x through 26.6.3) with active security maintenance and emerging-standard adoption (AuthZEN 1.0, RFC 8693 delegation tokens).

Short descriptiontext

Keycloak is a CNCF-incubating open-source identity and access management platform providing SSO, identity brokering, LDAP/AD federation, and fine-grained authorization via OpenID Connect, OAuth 2.0, and SAML 2.0, serving enterprise IT, B2B SaaS, and AI agent deployments globally under Apache 2.0 licensing.

Operating statusenum
Operating
Ownership categoryenum
akta.pro rankint
Markets served

Serves global market

Keyword5 values
identity access management, single sign-on, open source IAM, identity brokering, authorization services
Industry3 codes
1Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers)
CodeHDAEAJABPrimaryYes
2Federation & Identity Standards (SAML/OIDC/OAuth, Federation Hubs)
CodeHDADAAAGPrimaryNo
3Directory Services & Identity Stores (LDAP/AD, Cloud Directory)
CodeHDAEAJAAPrimaryNo
NAICS code1 code
  • Computer Systems Design and Related Services54151
Product category
Identity and Access Management
Social media profiles3 records
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model1 record
1Open-Source Software (No Direct Revenue)
TypeOthers
Description

Keycloak is a free, open-source identity and access management solution. The project does not generate direct revenue from software licensing. The project is maintained by a community of contributors with significant involvement from Red Hat (IBM) engineers. Organizations such as Red Hat commercialize Keycloak by offering support, consulting, and integration services around it.

keycloak.org
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components3 values
Technology or R&D, Personnel, Operations
Pricing details1 tier
1Free Open-Source Edition
ModelFreemiumBilling cadenceOthers
Notes

Keycloak server, client adapters, and client libraries are freely available under the Apache License 2.0. No pricing tiers, no per-user fees, no feature restrictions. All features including SSO, identity brokering, LDAP/AD federation, authorization services, clustering, and themes are included at no cost.

keycloak.org
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

Keycloak is an open-source identity and access management (IAM) platform that provides single sign-on (SSO), identity brokering with social and external IdPs, user federation with LDAP/Active Directory, fine-grained authorization services, and clustering for high availability. It supports standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and is distributed as a standalone server, container image, and Kubernetes Operator for enterprise self-hosting.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Automatic failover from Microsoft Entra ID to Keycloak within seconds during identity provider degradation, without reconfiguration of Epic EHR
+2 more records
Product overview1 text field

Keycloak is a unified open-source identity and access management platform positioned as a CNCF incubation project. The core product is the Keycloak Server (powered by Quarkus), which provides single-sign-on, identity brokering, user federation, and fine-grained authorization services. The platform includes client libraries for Java (Admin Client, Authorization Client, Policy Enforcer) and client adapters for JavaScript and Node.js applications. Infrastructure support includes a Kubernetes Operator and container images for cloud-native deployments. The server supports standard protocols including OpenID Connect, OAuth 2.0, and SAML 2.0, and integrates with LDAP and Active Directory user directories.

Product and service8 records
1Keycloak Server
CategoryCore product
Description

The main open-source identity and access management server powered by Quarkus. Provides single-sign-on, identity brokering, user federation, authorization services, and support for OpenID Connect, OAuth 2.0, and SAML 2.0 protocols for enterprise IT and developer use.

2Keycloak Admin Client
CategoryClient library
Description

Java library (keycloak-admin-client) for programmatically administering Keycloak realms, clients, users, roles, and identity providers via the Admin REST API. Targeted at enterprise developers integrating Keycloak into automation and operational tooling.

3Keycloak Authorization Client
CategoryClient library
Description

Java library (keycloak-authz-client) for integrating fine-grained authorization services into applications, enabling permission management through the Keycloak admin console. Targeted at application developers implementing policy-based access control.

4Keycloak Policy Enforcer
CategoryClient library
Description

Java library (keycloak-policy-enforcer) for enforcing OAuth2-based resource protection and permission-based access control in Java applications.

5Keycloak JavaScript Adapter
CategoryClient adapter
Description

Browser-side JavaScript library (keycloak-js) for integrating web applications with Keycloak for authentication and token management. Targeted at frontend web developers.

6Keycloak Node.js Adapter
CategoryClient adapter
Description

Server-side Node.js library (keycloak-connect) for protecting Node.js applications with Keycloak authentication. Targeted at backend Node.js developers.

7Keycloak Operator
CategoryInfrastructure
Description

Kubernetes and OpenShift operator for deploying and managing Keycloak clusters on enterprise Kubernetes environments. Available on OperatorHub. Targeted at platform engineering and SRE teams.

8Keycloak Container Image
CategoryInfrastructure
Description

Container image for Docker, Podman, Kubernetes, and OpenShift deployment of Keycloak server. Hosted on Quay.io. Enables containerized deployment in any container runtime environment.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Partnership4 partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Red Hat engineers are primary maintainers and contributors to the Keycloak project. Rishabh Singh from Red Hat presented at KubeCon India 2026 on 'Federated Client Authentication.' Red Hat commercializes Keycloak through Red Hat Single Sign-On, a supported distribution of the open-source project.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

IBM engineers, notably Alexander Schwartz (VP Customer Engineering, IBM), are key contributors and maintainers of Keycloak. Alexander Schwartz authored multiple Keycloak blog posts and is organizing KeycloakCon at KubeCon Japan 2026. IBM leverages Keycloak as part of its cloud native and hybrid cloud identity offerings.

Strategic tierMajorTypeStrategic or Co-development Partner
Description

Hitachi engineers Takashi Norimatsu and Yoshiyuki Tabata are Keycloak contributors and presenters at KubeCon Japan 2026. Topics include 'Identities and Authentication for your Agents with Keycloak,' 'CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems,' and 'AuthZEN in Practice.' Hitachi contributes both to the project and to CNCF IAM standardization efforts involving Keycloak.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Keycloak is a CNCF incubation project. The CNCF provides governance, marketing support, and community infrastructure. Keycloak participates in CNCF events (KubeCon), CNCF TAG Security working groups, and contributes to CNCF identity and access management standardization efforts.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight7 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Okta is the leading commercial cloud identity platform offering SSO, MFA, and lifecycle management via OIDC/OAuth/SAML — the same core protocol stack as Keycloak. It is the primary commercial alternative cited in Keycloak's own B2B SaaS positioning.

TypeDirect peer
Description

Auth0 (now an Okta company) provides developer-focused SSO, MFA, and identity APIs targeting B2B SaaS customers, directly overlapping with Keycloak's primary B2B SaaS segment and competing on developer experience and enterprise federation.

TypeBroad incumbent
Description

Microsoft Entra ID (formerly Azure Active Directory) is the identity backbone for Microsoft 365 and Azure, providing SSO, federation, and authorization for enterprise and SaaS workloads. It is the dominant incumbent and the failover source in Keycloak's Epic EHR deployment.

TypeBroad incumbent
Description

AWS Cognito provides managed user pools and identity federation for applications hosted on AWS, supporting OIDC and SAML. It competes with Keycloak for B2B SaaS and cloud-native deployments, particularly where AWS-native integration is preferred.

TypeBroad incumbent
Description

Ping Identity (merged with ForgeRock) offers enterprise SSO, federation, and identity governance with strong on-premises and hybrid deployment options. It is a direct commercial alternative for the same enterprise IT and regulated-segment buyers Keycloak targets.

TypeBroad incumbent
Description

IBM Security Verify is IBM's commercial IAM offering built on the same identity lineage as Keycloak (IBM engineers are Keycloak maintainers). It competes for the same enterprise and hybrid cloud buyers and represents the commercialized path for Keycloak in IBM's portfolio.

TypeEmerging player
Description

Authentik is an open-source SSO/identity provider supporting OIDC, SAML, and LDAP federation with a comparable self-hostable deployment model. It targets the same cost-sensitive, self-hosted customer base as Keycloak, especially in the homelab and SMB segments.

TypeEmerging player
Description

Ory provides an open-source identity stack (Ory Kratos, Hydra, Oathkeeper) supporting OIDC, OAuth 2.0, and modern API-first deployments. It targets cloud-native developers and overlaps with Keycloak's API-first, Kubernetes-friendly positioning.

TypeEmerging player
Description

FusionAuth is a developer-focused identity platform offering SSO, MFA, and user management with both self-hosted and managed deployment options. It directly competes with Keycloak for B2B SaaS authentication infrastructure use cases.

TypeDirect peer
Description

Auth0's B2B and B2C identity products remain operated as a distinct platform within Okta and are widely cited alongside Keycloak in developer IAM comparison guides for enterprise SaaS authentication use cases.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration10 records

Each record includes

Title, Type, Description, Source

AI maturity
App detail

Has app

Feature11 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance1 record

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Keycloak

Identity and Access Managementkeycloak.org

Keycloak is a CNCF-incubating open-source identity and access management platform providing SSO, identity brokering, LDAP/AD federation, and fine-grained authorization via OpenID Connect, OAuth 2.0, and SAML 2.0, serving enterprise IT, B2B SaaS, and AI agent deployments globally under Apache 2.0 licensing.

What Keycloak does

Keycloak is an open-source identity and access management (IAM) project originally created in 2014 by co-founders Bill Burke and Stian Thorgersen (originally under Red Hat) and currently incubating under the Cloud Native Computing Foundation (CNCF), part of The Linux Foundation. The project provides single sign-on (SSO), identity brokering and social login, user federation with LDAP and Active Directory, fine-grained authorization services, and clustering via Infinispan distributed caching — all built on the Quarkus framework and supporting OpenID Connect, OAuth 2.0, and SAML 2.0 protocols. The platform is distributed as a standalone server (ZIP/TAR.GZ downloads from keycloak.org), container images on Quay.io, and a Kubernetes/OpenShift Operator on OperatorHub, with client libraries distributed via Maven Central and NPM. Architecture is positioned for cloud-native and air-gapped deployments, including DDIL (Denied, Disrupted, Intermittent, Limited) environments used in field hospitals and tactical medical scenarios.

Keycloak has no direct commercial revenue stream: the software is free under the Apache 2.0 license with no per-user fees, tiered pricing, or feature restrictions, and the project itself is governed as a non-commercial entity. Commercial value is captured indirectly through Red Hat's Red Hat Single Sign-On (a supported distribution of the upstream project), third-party integration partners (e.g., Strata Maverics for healthcare identity orchestration with Epic), and consulting/support services from Red Hat, IBM, Hitachi, and other ecosystem vendors. The project serves three primary customer segments: enterprise IT organizations needing centralized authentication across diverse application portfolios, B2B SaaS companies needing enterprise SSO/SCIM/MFA capabilities without per-seat commercial IAM costs, and AI/ML platform operators needing authorization for AI agents and Model Context Protocol (MCP) tool calls. Key contributors include senior engineers from Red Hat (e.g., Rishabh Singh), IBM (Alexander Schwartz, VP Customer Engineering), and Hitachi (Takashi Norimatsu, Yoshiyuki Tabata), and the project maintains a regular release cadence (versions 25.x through 26.6.3) with active security maintenance and emerging-standard adoption (AuthZEN 1.0, RFC 8693 delegation tokens).

Keycloak firmographics

Firmographics
Name
Keycloak
Legal name
Keycloak
Website
https://keycloak.org
Company type
Private
Founded year
2014
Operating status
Operating
Short description
Keycloak is a CNCF-incubating open-source identity and access management platform providing SSO, identity brokering, LDAP/AD federation, and fine-grained authorization via OpenID Connect, OAuth 2.0, and SAML 2.0, serving enterprise IT, B2B SaaS, and AI agent deployments globally under Apache 2.0 licensing.
Ownership category
akta.pro rank

Keycloak industry classification

Industry
Product category
Identity and Access Management
NAICS
Computer Systems Design and Related Services (54151)
akta.pro primary industry
Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers) (HDAEAJAB)
akta.pro secondary industries
Federation & Identity Standards (SAML/OIDC/OAuth, Federation Hubs) (HDADAAAG), Directory Services & Identity Stores (LDAP/AD, Cloud Directory) (HDAEAJAA)

Keywords

  • Identity access management
  • Single sign-on
  • Open source IAM
  • Identity brokering
  • Authorization services

Keycloak business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Operations

Revenue model

  1. Open-Source Software (No Direct Revenue): Keycloak is a free, open-source identity and access management solution. The project does not generate direct revenue from software licensing. The project is maintained by a community of contributors with significant involvement from Red Hat (IBM) engineers. Organizations such as Red Hat commercialize Keycloak by offering support, consulting, and integration services around it.

Pricing tiers

ModelBillingPrice
FreemiumOthersFree Open-Source Edition

Go-to-market motion2 records

Distribution channels6 records

Marketing channels7 records

Keycloak product offering

Product offering

Core offering

Keycloak is an open-source identity and access management (IAM) platform that provides single sign-on (SSO), identity brokering with social and external IdPs, user federation with LDAP/Active Directory, fine-grained authorization services, and clustering for high availability. It supports standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and is distributed as a standalone server, container image, and Kubernetes Operator for enterprise self-hosting.

Product overview

Keycloak is a unified open-source identity and access management platform positioned as a CNCF incubation project. The core product is the Keycloak Server (powered by Quarkus), which provides single-sign-on, identity brokering, user federation, and fine-grained authorization services. The platform includes client libraries for Java (Admin Client, Authorization Client, Policy Enforcer) and client adapters for JavaScript and Node.js applications. Infrastructure support includes a Kubernetes Operator and container images for cloud-native deployments. The server supports standard protocols including OpenID Connect, OAuth 2.0, and SAML 2.0, and integrates with LDAP and Active Directory user directories.

Differentiator

Problem solved

Functional benefit

Products and services

  • Keycloak Server The main open-source identity and access management server powered by Quarkus. Provides single-sign-on, identity brokering, user federation, authorization services, and support for OpenID Connect, OAuth 2.0, and SAML 2.0 protocols for enterprise IT and developer use.
  • Keycloak Admin Client Java library (keycloak-admin-client) for programmatically administering Keycloak realms, clients, users, roles, and identity providers via the Admin REST API. Targeted at enterprise developers integrating Keycloak into automation and operational tooling.
  • Keycloak Authorization Client Java library (keycloak-authz-client) for integrating fine-grained authorization services into applications, enabling permission management through the Keycloak admin console. Targeted at application developers implementing policy-based access control.
  • Keycloak Policy Enforcer Java library (keycloak-policy-enforcer) for enforcing OAuth2-based resource protection and permission-based access control in Java applications.
  • Keycloak JavaScript Adapter Browser-side JavaScript library (keycloak-js) for integrating web applications with Keycloak for authentication and token management. Targeted at frontend web developers.
  • Keycloak Node.js Adapter Server-side Node.js library (keycloak-connect) for protecting Node.js applications with Keycloak authentication. Targeted at backend Node.js developers.
  • Keycloak Operator Kubernetes and OpenShift operator for deploying and managing Keycloak clusters on enterprise Kubernetes environments. Available on OperatorHub. Targeted at platform engineering and SRE teams.
  • Keycloak Container Image Container image for Docker, Podman, Kubernetes, and OpenShift deployment of Keycloak server. Hosted on Quay.io. Enables containerized deployment in any container runtime environment.

Quantifiable outcome

  • Automatic failover from Microsoft Entra ID to Keycloak within seconds during identity provider degradation, without reconfiguration of Epic EHR
  • +2 more outcomes

Companies that use Keycloak

Customer profile

Named customers3 records

Segments4 records

Ideal customer profiles4 records

Keycloak technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration10 records

Feature11 records

Keycloak partnerships and signals

Strategic signal

Partnerships

Four partnerships are on record, tiered core and major.

  • Red HatcoreStrategic or Co-development PartnerRed Hat engineers are primary maintainers and contributors to the Keycloak project. Rishabh Singh from Red Hat presented at KubeCon India 2026 on 'Federated Client Authentication.' Red Hat commercializes Keycloak through Red Hat Single Sign-On, a supported distribution of the open-source project.
  • IBMcoreStrategic or Co-development PartnerIBM engineers, notably Alexander Schwartz (VP Customer Engineering, IBM), are key contributors and maintainers of Keycloak. Alexander Schwartz authored multiple Keycloak blog posts and is organizing KeycloakCon at KubeCon Japan 2026. IBM leverages Keycloak as part of its cloud native and hybrid cloud identity offerings.
  • HitachimajorStrategic or Co-development PartnerHitachi engineers Takashi Norimatsu and Yoshiyuki Tabata are Keycloak contributors and presenters at KubeCon Japan 2026. Topics include 'Identities and Authentication for your Agents with Keycloak,' 'CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems,' and 'AuthZEN in Practice.' Hitachi contributes both to the project and to CNCF IAM standardization efforts involving Keycloak.
  • Cloud Native Computing Foundation (CNCF)coreStrategic or Co-development PartnerKeycloak is a CNCF incubation project. The CNCF provides governance, marketing support, and community infrastructure. Keycloak participates in CNCF events (KubeCon), CNCF TAG Security working groups, and contributes to CNCF identity and access management standardization efforts.

Scale indicators3 records

Recent moves6 records

Expansion highlights7 records

Keycloak competitors and assessment

Company assessment

Direct peers

  • Okta: Okta is the leading commercial cloud identity platform offering SSO, MFA, and lifecycle management via OIDC/OAuth/SAML — the same core protocol stack as Keycloak. It is the primary commercial alternative cited in Keycloak's own B2B SaaS positioning.
  • Auth0: Auth0 (now an Okta company) provides developer-focused SSO, MFA, and identity APIs targeting B2B SaaS customers, directly overlapping with Keycloak's primary B2B SaaS segment and competing on developer experience and enterprise federation.
  • Auth0 by Okta Workforce Identity: Auth0's B2B and B2C identity products remain operated as a distinct platform within Okta and are widely cited alongside Keycloak in developer IAM comparison guides for enterprise SaaS authentication use cases.

Broad incumbents

  • Microsoft Entra ID: Microsoft Entra ID (formerly Azure Active Directory) is the identity backbone for Microsoft 365 and Azure, providing SSO, federation, and authorization for enterprise and SaaS workloads. It is the dominant incumbent and the failover source in Keycloak's Epic EHR deployment.
  • AWS Cognito: AWS Cognito provides managed user pools and identity federation for applications hosted on AWS, supporting OIDC and SAML. It competes with Keycloak for B2B SaaS and cloud-native deployments, particularly where AWS-native integration is preferred.
  • Ping Identity: Ping Identity (merged with ForgeRock) offers enterprise SSO, federation, and identity governance with strong on-premises and hybrid deployment options. It is a direct commercial alternative for the same enterprise IT and regulated-segment buyers Keycloak targets.
  • IBM Security Verify: IBM Security Verify is IBM's commercial IAM offering built on the same identity lineage as Keycloak (IBM engineers are Keycloak maintainers). It competes for the same enterprise and hybrid cloud buyers and represents the commercialized path for Keycloak in IBM's portfolio.

Emerging players

  • Authentik: Authentik is an open-source SSO/identity provider supporting OIDC, SAML, and LDAP federation with a comparable self-hostable deployment model. It targets the same cost-sensitive, self-hosted customer base as Keycloak, especially in the homelab and SMB segments.
  • Ory: Ory provides an open-source identity stack (Ory Kratos, Hydra, Oathkeeper) supporting OIDC, OAuth 2.0, and modern API-first deployments. It targets cloud-native developers and overlaps with Keycloak's API-first, Kubernetes-friendly positioning.
  • FusionAuth: FusionAuth is a developer-focused identity platform offering SSO, MFA, and user management with both self-hosted and managed deployment options. It directly competes with Keycloak for B2B SaaS authentication infrastructure use cases.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks6 records

Key highlights6 records

Customer concentration

Keycloak social profiles

Digital presence

Keycloak compliance and trust

Trust signal

Compliance1 record

Keycloak financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Keycloak leadership team

Management profile

Number of profiles

Profiles1 record

Keycloak funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Keycloak M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Keycloak

What does Keycloak do?

Keycloak is an open-source identity and access management (IAM) platform that provides single sign-on (SSO), identity brokering with social and external IdPs, user federation with LDAP/Active Directory, fine-grained authorization services, and clustering for high availability. It supports standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and is distributed as a standalone server, container image, and Kubernetes Operator for enterprise self-hosting.

Is Keycloak a public or private company?

Keycloak is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Keycloak founded?

Keycloak was founded in 2014.

How does Keycloak make money?

One revenue line is on record: open-Source Software (No Direct Revenue).

Who are Keycloak's main competitors?

Direct peers on record are Okta, Auth0 and Auth0 by Okta Workforce Identity. Broad incumbents are Microsoft Entra ID, AWS Cognito, Ping Identity and IBM Security Verify. Emerging players are Authentik, Ory and FusionAuth.

Does Keycloak have an API?

Yes. Keycloak provides a comprehensive REST-based Admin REST API for managing realms, clients, users, roles, and identity providers. It also includes an Account REST API for user self-service. The platform offers client libraries including Admin Client (keycloak-admin-client), Authorization Client (keycloak-authz-client), and Policy Enforcer (keycloak-policy-enforcer) for Java. The JavaScript adapter (keycloak-js) enables frontend integration, while keycloak-connect provides Node.js support. Keycloak also implements AuthZEN Evaluation and Evaluations APIs for authorization interactions, and supports Model Context Protocol (MCP) for AI agent authorization as demonstrated in integration tutorials. Developer documentation is at www.keycloak.org/documentation.

What industry is Keycloak in?

Keycloak's product category is Identity and Access Management. Its primary akta.pro industry code is HDAEAJAB, Single Sign-On (SSO) & Federation (SAML/OIDC, Identity Providers), with a secondary code of HDADAAAG, Federation & Identity Standards (SAML/OIDC/OAuth, Federation Hubs). Its NAICS code is 54151.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
WebProNewsCritical Keycloak Vulnerability (CVE-2026-18963) Enables Account Takeover via Password Reset BypassRed Hat and the Keycloak development team have released updates for versions 26.7.2 and later to address CVE-2026-18963, a high-severity vulnerability in the Keycloak identity management platform that allows unauthenticated attackers to bypass password reset mechanisms. The flaw stems from inadequate validation of state parameters during account recovery, enabling potential account takeovers including administrative privileges. Organizations are urged to upgrade immediately as no confirmed exploitation has been reported yet.The Hacker NewsCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any AccountRed Hat and the Keycloak project released patches for CVE-2026-18963, a critical flaw allowing an unauthenticated remote attacker to force a password reset and take over any user account, including administrative ones. Red Hat rated it 9.1 CVSS and issued four errata on August 18, 2026, with upstream Keycloak fixed in version 26.7.2. No evidence of exploitation has been found.Cyber Security NewsKeycloak Vulnerability Exposes User Names and Email Addresses Across Admin BoundariesKeycloak has patched a broken access control vulnerability (CVE-2026-17059) in its Admin REST API that could allow restricted administrators to access usernames, email addresses, and other profile information of users outside their permitted scope. The flaw, discovered by Escape researcher Enzo Mongin, existed in the role-members endpoint which enforced only broad permissions without applying per-user authorization filtering, exposing data even when the standard users API correctly returned empty responses. Keycloak remediated the issue with version 26.7.0 on July 28, 2026; the vulnerability carries a CVSS score of 6.5 (Medium) and primarily affects deployments using the default permission model.Cyber PressKeycloak Flaw Exposes User PII Through Malicious OIDC Client MetadataA broken access control flaw in Keycloak (CVE-2026-17059) lets a restricted admin account harvest user PII by querying a role's membership endpoint. The fix, a single filter line, was shipped in Keycloak 26.7.0 on July 28, 2026.Security BoulevardIdentity Continuity for Epic EHRStrata.io published a technical explainer on Strata Maverics, an identity orchestration layer positioned between Epic EHR and identity providers to maintain authentication continuity during provider outages or migrations. The solution fronts Epic's OAuth 2.0 and SMART on FHIR flows, enabling automatic failover from Microsoft Entra ID to Keycloak within seconds when the primary identity provider degrades, without requiring any reconfiguration of Epic itself. The article also highlights air-gap and DDIL (Denied, Disrupted, Intermittent, Limited) deployment capabilities for field hospitals, rural clinics, and tactical medical environments.Graph Database & AnalyticsFrom Identity Vacuum to Identity Driven Access Control: Securing LLM Agents in the EnterpriseThis technical article from Neo4j's Developer Blog outlines a security architecture for enterprise AI systems using the Model Context Protocol (MCP), identifying a critical flaw where MCP strips user identity from requests, potentially causing data leakage across different clearance levels. The proposed solution demonstrates passing user JWT tokens from Keycloak through Neo4j's MCP Server to enable fine-grained role-based access control, showing how Confidential, Internal, and External users receive different query results from the same knowledge graph. The article provides a complete Docker Compose implementation using Neo4j Enterprise, Keycloak, FastAPI, and LiteLLM as the model-agnostic backend.Security BoulevardYour MCP Server Is a Resource Server Now. Act Like It.Strata published a technical tutorial demonstrating how to deploy an identity gateway between AI agents and MCP servers using OAuth 2.0, OPA policy evaluation, and RFC 8693 token exchange to address security vulnerabilities in the MCP ecosystem. The article references Clutch Security research showing that 43% of tested MCP servers have OAuth implementation flaws, and walks through an example architecture using Keycloak, Maverics Orchestrator, and per-tool scoped delegation tokens with five-second TTLs. The tutorial presents the full configuration as code in git, enabling authorization policy changes to go through standard code review processes.Tech TimesTop 5 Best Customer Identity and Access Management (CIAM) Solutions in 2026This article is a buyer's guide comparing five Customer Identity and Access Management (CIAM) platforms: Descope, Auth0 (Okta Customer Identity Cloud), Keycloak, Ping Identity (PingOne for Customers), and ForgeRock. Each platform is profiled with its key features, deployment options, security capabilities, and target use cases. The guide evaluates trade-offs between visual/no-code approaches, open-source flexibility, enterprise compliance focus, and customization depth. The article concludes with advice for evaluating CIAM solutions based on implementation speed, customization needs, user populations, and industry-specific requirements. No single news event or corporate announcement is being reported.DescopeTop 7 SCIM Providers for B2B SaaS AppsThe article reviews the top SCIM providers for B2B SaaS applications, emphasizing the importance of automated, secure user lifecycle management. It compares seven providers—Descope, Auth0, Microsoft Entra External ID, OneLogin, Keycloak, Authentik, and Ory Polis—highlighting their features, strengths, and ideal use cases.CyberArkYou Can’t Always Win Racing the (Key)cloakCyberArk Labs conducted security research on Keycloak, an open-source identity and access management solution used by approximately 27,000 internet-facing systems, examining LDAP integrations, fuzzing techniques, and web race conditions. The research uncovered two security issues: a low-severity Initial-Access-Token race condition allowing count limit bypass (no CVE assigned) and CVE-2024-1722, a denial-of-service vulnerability enabling attackers to lock legitimate users out of their accounts by exploiting a username-email conflict in the login flow. The research was presented at Insomnihack, Nullcon Goa, and BlueHatIL2025 conferences.