Keycloak
One sign-in for everything.
Keycloak is the central place where your users sign in — once, for all applications. Single sign-on, second factor and user management through open standards, on your own instance in our data centres.
What Keycloak does
Identities in one place
Keycloak is open-source software for identity and access management. Applications no longer ask for a username and password themselves; they send the user to Keycloak — and get back the answer as to who the user is and what they are allowed to do.
This works through the standards OpenID Connect, OAuth 2.0 and SAML 2.0, which practically every modern application understands. Existing directories such as LDAP or Active Directory can be connected, as can external sign-in services. Second factor, one-time passwords and passkeys are part of the feature set, and roles and permissions can be granted per application.
The gain shows when an employee leaves: one account is disabled — not twelve.
- Single sign-on across all applications
- OpenID Connect, OAuth 2.0, SAML 2.0
- Connection to LDAP and Active Directory
- Sign-in through external providers
- Second factor, one-time passwords, passkeys
- Roles and permissions per application
- Tenant separation through realms
- Customisable sign-in pages
What we take on
Keycloak as a run instance
We provide Keycloak on its own virtual machine and run it. The exact setup is set out in the quote.
Provisioning
Your own instance with its own address, certificate and secured access to the administration console.
Updates
Operating system, Keycloak and the database underneath stay up to date — security updates included.
Monitoring
If sign-in is down, everything is down. That is why we keep an eye on availability and load.
Backup
Configuration and user data are backed up as well, geo-redundantly to a second data centre if you want.
MoreFrequently asked questions
Which applications can be connected?
Does Keycloak replace our Active Directory?
Not necessarily. Keycloak can connect an existing LDAP or Active Directory and sit in front of it as the sign-in point. Whether a directory is replaced or supplemented is a decision we make together with you.
What happens if Keycloak fails?
Then nobody can get into the connected applications any more — that is the flip side of central sign-in. That is why, with us, Keycloak can be spread across several nodes and across two data centres: if one site fails, the other takes over, and the database underneath is duplicated as well. Our sites are far enough apart for this — more than 80 and more than 250 kilometres. How far you want to go belongs at the start of the conversation, not at the end.
Where is the identity data stored?
In our data centres in Germany, certified to ISO 27001 based on BSI IT-Grundschutz. No access under the US CLOUD Act.
Sovereignty
Paving the way for digital sovereignty
-
Owner-managed since 1997
As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.
-
100% made in Germany
Our data center, product development, and customer support are all based in Germany for your digital sovereignty.
-
24/7 Customer Support
We are here for you: 24/7/365 customer support, in English and German
How many sign-ins does your working day have?
Tell us which applications should come together and what directory you have today. That is what shapes the setup. Feel free to contact me directly.
- We will get back to you as soon as we can.
- No obligation, free of charge.