Keycloak logo

Keycloak

Website

Open-source identity and access management with SSO

35.9k stars 8.7k forks last commit first released Apache-2.0

Actively maintained

Last commit 13 Jul 2026.

Keycloak screenshot

Keycloak is an open-source Identity and Access Management (IAM) server for modern applications and services. It centralizes authentication and authorization so applications can rely on standards-based SSO instead of implementing login, user storage, and session management.

Key Features

  • Single sign-on and single sign-out across multiple applications
  • Support for standard protocols: OpenID Connect, OAuth 2.0, and SAML 2.0
  • Identity brokering and social login via configurable identity providers
  • User federation with LDAP and Active Directory, with extensible provider support
  • Admin console for managing realms, clients, users, roles, sessions, and policies
  • Account management console for end users (profile, password changes, session management, and 2FA)
  • Fine-grained authorization services for policy-based access control

Use Cases

  • Centralized SSO for internal apps, APIs, and microservices
  • Replacing custom authentication with standards-based identity and token issuance
  • Integrating enterprise directories (LDAP/AD) and external identity providers into one login flow

Limitations and Considerations

  • Operating securely at scale requires careful configuration of realms, clients, token lifetimes, and session settings
  • Some advanced deployments may require external databases and clustering planning for high availability

Keycloak is widely used as a central identity provider to standardize authentication and access control across heterogeneous systems. It reduces application complexity while enabling consistent security policies and user management in one place.

Categories:

Tags:

Tech Stack:

Share:

Similar to Keycloak

Logto logo

Logto

Authentication and authorization platform for apps and APIs

14.2k
1.1k
Last commit

Open-source authentication and authorization infrastructure with OIDC/OAuth 2.1, SAML SSO, multi-tenancy, MFA, and RBAC for SaaS and AI apps.

MPL-2.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19
Casdoor logo

Casdoor

UI-first IAM and SSO platform for modern authentication

14.1k
1.8k
Last commit

Casdoor is an open-source, UI-first IAM/SSO platform supporting OAuth 2.0, OIDC, SAML, LDAP, SCIM, WebAuthn and MFA, with an admin web UI and SDKs.

Apache-2.0Actively maintained
Alternative to:
Okta logo
Okta
+19
Kanidm logo

Kanidm

Simple, secure identity management and SSO provider

5.2k
343
Last commit

Kanidm is a secure identity management platform providing SSO, passkeys (WebAuthn), and integrations like OAuth2/OIDC, RADIUS, and LDAP gateway for legacy apps.

MPL-2.0Actively maintained
Alternative to:
Okta logo
Okta
+19
FusionAuth logo

FusionAuth

Self-hosted identity and access management for applications

FusionAuth is a self-hosted authentication and IAM platform supporting OAuth2, OIDC and SAML, with SSO, MFA, user management and developer-focused integrations.

Activity unknown
Alternative to:
Auth0 logo
Auth0
+19
authentik logo

authentik

Open-source Identity Provider (IdP) for SSO, OIDC, and SAML

22.5k
1.7k
Last commit

Open-source IdP delivering SSO, OAuth2/OIDC, SAML2, LDAP, RADIUS, MFA, WebAuthn, conditional access and application-proxy capabilities for self-hosted deployments.

Actively maintained
Alternative to:
Okta logo
Okta
+19
ZITADEL logo

ZITADEL

API-first identity and access management platform for applications

14.6k
1.2k
Last commit

ZITADEL is an open source IAM/CIAM platform providing SSO, MFA, OIDC/OAuth2, SAML, user management, and multi-tenant organizations with audit logging.

AGPL-3.0Actively maintained
Alternative to:
Auth0 logo
Auth0
+19