Overview
Keycloak is the reference open-source identity and access management server, maintained on GitHub under the Apache 2.0 licence with a community on the CNCF Slack. Applications hand login to Keycloak over OpenID Connect, OAuth 2.0 or SAML 2.0, so they never store passwords or build login forms, and users get single sign-on and single sign-out across every connected app.
Its feature set is broad: identity brokering to social networks and external OIDC or SAML providers, user federation with LDAP and Active Directory (or your own user store through a provider), fine-grained authorization services, an admin console for realms, clients, users and sessions, and an account console where users manage their profile, passwords, two-factor auth and linked identities.
Everything is free, but you operate it: a Java server plus a database, upgrades, themes written in FreeMarker, and clustering if you need high availability. It is excellent for internal SSO and enterprise integrations, and heavier than developer-focused tools when all you want is login for one web app.
Pricing and plans
checked 28 Sept 2026Free tier · no card
Entirely free and open source (Apache 2.0) with no user limits; you provide the servers and database
| Plan | Price | What you get |
|---|---|---|
| Keycloak | Free | Self-hosted, Apache 2.0, all features |
What it does
- Single sign-on and sign-out
- Users log in once for all connected applications and log out of all of them at once.
- Identity brokering
- Social login and external OIDC or SAML 2.0 identity providers configured in the admin console without code changes.
- User federation
- Built-in LDAP and Active Directory integration, plus custom providers for other user stores.
- Authorization services
- Central fine-grained permission policies beyond simple roles.
- Admin and account consoles
- Admin UI for realms, clients, users and sessions; self-service console for users' profiles, passwords and 2FA.
- Container image
- Official image on quay.io; a single command starts a dev server.
Strengths and limitations
Strengths
- Free and Apache-licensed with no user limits
- Covers OIDC, OAuth 2.0, SAML, LDAP and AD in one server
- Large, long-running community (since 2013)
- Runs anywhere, so data location is your choice
Limitations
- You must operate, upgrade and scale the Java server and its database
- No official hosted service or paid support from the project itself
- Custom login UI means working with Keycloak themes
- Heavier to set up than developer-first hosted auth for a single app
Who it suits
Good for
- Internal SSO across many company applications
- Enterprises integrating LDAP or Active Directory
- Teams that need free, self-hosted SAML and OIDC
Look elsewhere if
- Solo developers who want hosted auth with drop-in UI components
- Teams without capacity to run and patch an identity server
Alternatives to Keycloak
| Tool | From | Free option | Stages |
|---|---|---|---|
| Amazon Cognito Cloud user directory and auth service | Usage-based | Free tier | |
| Asgardeo Hosted CIAM (with open-source self-hosted option) | $20/mo | Free tier | |
| Auth0 Hosted customer identity (CIAM) | $35/mo | Free tier | |
| authentik Open-source self-hosted identity provider | Usage-based | Free tier | |
| Authgear Open-source CIAM (cloud, VPC or one-time self-host licence) | $50/mo | Free tier | |
| Descope No-code CIAM with visual flows | $249/mo | Free tier |
Questions
Is Keycloak free?
Yes. Keycloak is open source under the Apache 2.0 licence with no user limits; you pay only for the servers you run it on.
Does Keycloak support SAML?
Yes. It supports OpenID Connect, OAuth 2.0 and SAML 2.0, both as an identity provider and for brokering to other providers.
Can Keycloak connect to Active Directory?
Yes. It has built-in LDAP and Active Directory user federation.
How do I try Keycloak quickly?
Run the official container image in dev mode with docker run quay.io/keycloak/keycloak start-dev.
Sources read for this page