Keycloak

One sign-in for everything.

Keycloak is the central place where your users sign in — once, for all applications. Single sign-on, second factor and user management through open standards, on your own instance in our data centres.

Open standards: OpenID Connect, OAuth 2.0, SAML 2.0ISO 27001 based on BSI IT-GrundschutzIdentities stay in Germany

What Keycloak does

Identities in one place

Keycloak is open-source software for identity and access management. Applications no longer ask for a username and password themselves; they send the user to Keycloak — and get back the answer as to who the user is and what they are allowed to do.

This works through the standards OpenID Connect, OAuth 2.0 and SAML 2.0, which practically every modern application understands. Existing directories such as LDAP or Active Directory can be connected, as can external sign-in services. Second factor, one-time passwords and passkeys are part of the feature set, and roles and permissions can be granted per application.

The gain shows when an employee leaves: one account is disabled — not twelve.

  • Single sign-on across all applications
  • OpenID Connect, OAuth 2.0, SAML 2.0
  • Connection to LDAP and Active Directory
  • Sign-in through external providers
  • Second factor, one-time passwords, passkeys
  • Roles and permissions per application
  • Tenant separation through realms
  • Customisable sign-in pages

What we take on

Keycloak as a run instance

We provide Keycloak on its own virtual machine and run it. The exact setup is set out in the quote.

Provisioning

Your own instance with its own address, certificate and secured access to the administration console.

Updates

Operating system, Keycloak and the database underneath stay up to date — security updates included.

Monitoring

If sign-in is down, everything is down. That is why we keep an eye on availability and load.

Backup

Configuration and user data are backed up as well, geo-redundantly to a second data centre if you want.

More

Frequently asked questions

Which applications can be connected?

Anything that speaks OpenID Connect, OAuth 2.0 or SAML 2.0 — and today that is almost every business application. Nextcloud and GitLab can be connected this way too.

Does Keycloak replace our Active Directory?

Not necessarily. Keycloak can connect an existing LDAP or Active Directory and sit in front of it as the sign-in point. Whether a directory is replaced or supplemented is a decision we make together with you.

What happens if Keycloak fails?

Then nobody can get into the connected applications any more — that is the flip side of central sign-in. That is why, with us, Keycloak can be spread across several nodes and across two data centres: if one site fails, the other takes over, and the database underneath is duplicated as well. Our sites are far enough apart for this — more than 80 and more than 250 kilometres. How far you want to go belongs at the start of the conversation, not at the end.

Where is the identity data stored?

In our data centres in Germany, certified to ISO 27001 based on BSI IT-Grundschutz. No access under the US CLOUD Act.

Sovereignty

Paving the way for digital sovereignty

ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023
BSI-IGZ-0552-2023 ISO 27001 based on BSI IT-Grundschutz Scope: all data centers and all cloud services Security concept
  • Owner-managed since 1997

    As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.

  • 100% made in Germany

    Our data center, product development, and customer support are all based in Germany for your digital sovereignty.

  • 24/7 Customer Support

    We are here for you: 24/7/365 customer support, in English and German

How many sign-ins does your working day have?

Tell us which applications should come together and what directory you have today. That is what shapes the setup. Feel free to contact me directly.

  • We will get back to you as soon as we can.
  • No obligation, free of charge.

How we process your details is explained in our privacy notice.