Keycloak
Open-source identity and access management with SSO
35.9k stars 8.7k forks last commit first released Apache-2.0
Actively maintained
Last commit 13 Jul 2026.

Keycloak is an open-source Identity and Access Management (IAM) server for modern applications and services. It centralizes authentication and authorization so applications can rely on standards-based SSO instead of implementing login, user storage, and session management.
Key Features
- Single sign-on and single sign-out across multiple applications
- Support for standard protocols: OpenID Connect, OAuth 2.0, and SAML 2.0
- Identity brokering and social login via configurable identity providers
- User federation with LDAP and Active Directory, with extensible provider support
- Admin console for managing realms, clients, users, roles, sessions, and policies
- Account management console for end users (profile, password changes, session management, and 2FA)
- Fine-grained authorization services for policy-based access control
Use Cases
- Centralized SSO for internal apps, APIs, and microservices
- Replacing custom authentication with standards-based identity and token issuance
- Integrating enterprise directories (LDAP/AD) and external identity providers into one login flow
Limitations and Considerations
- Operating securely at scale requires careful configuration of realms, clients, token lifetimes, and session settings
- Some advanced deployments may require external databases and clustering planning for high availability
Keycloak is widely used as a central identity provider to standardize authentication and access control across heterogeneous systems. It reduces application complexity while enabling consistent security policies and user management in one place.
Categories:
Tags:
Tech Stack:
Similar to Keycloak

Logto
Authentication and authorization platform for apps and APIs
Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

Casdoor
UI-first IAM and SSO platform for modern authentication
Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Kanidm
Simple, secure identity management and SSO provider
Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

FusionAuth
Self-hosted identity and access management for applications
FusionAuth is a self-hosted authentication and IAM platform supporting OAuth2, OIDC and SAML, with SSO, MFA, user management and developer-focused integrations.

authentik
Open-source Identity Provider (IdP) for SSO, OIDC, and SAML
Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.
ZITADEL
API-first identity and access management platform for applications
ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.



