Trending 2026Keycloak 25.x – 26.x

B2B SSO with Organizations

Domain Mapping · IDP Routing

Keycloak Organizations enables B2B SSO by mapping user email domains to enterprise identity providers. Applications authenticate against a single Keycloak endpoint — Keycloak detects the domain and routes each user to their organization’s IDP automatically.

Delivery: 3–4 weeks

How It Works

Enter emailResolve orgRoute to IdPAuth completeJWT issued📧User Email🔍Domain Match🏢Org Lookup🔀Org IdP🎫KC SessionApp Access

Technical Highlights

Domain-to-IDP mapping via Keycloak OrganizationsAutomatic home realm discovery by email domainSAML 2.0 and OIDC IdP connections per organizationJust-in-time user provisioning from org IdPOrganization-scoped token claimsDelegated org admin without realm-level access

How Organizations Work

Keycloak Organizations groups users into logical tenants within a single realm. Each organization maps one or more email domains (e.g., @acme.com) to a specific identity provider — Okta, Azure AD, Google Workspace, or any SAML/OIDC-compliant IdP. When a user enters their email at login, Keycloak resolves the organization and redirects to the correct IdP without any application-side logic.

Domain-Based IDP Routing

The application has one integration point: Keycloak. When login begins, Keycloak’s home realm discovery checks the email domain against all configured organizations. On a match, the user is transparently redirected to that organization’s IdP. After authentication, Keycloak issues a standard session token — the application never interacts with the upstream IdP directly.

Delegated Organization Admin

Each organization has its own admins who manage membership, configure the IdP connection, and invite users — all without realm-level access. Just-in-time user provisioning creates Keycloak accounts on first login from the org IdP, and organization-scoped token claims let downstream services enforce tenant-aware authorization.

Why in 2026

B2B SaaS customers expect to log in via their own corporate IdP. Keycloak Organizations delivers this from a single realm, with no custom application-side routing code required.

Related service package: Multi-Tenancy SaaS IAM

Delivery: 3–4 weeks

Ready to implement B2B SSO with Organizations?

Fixed price. Clear scope. 30-day warranty.

Or view all service packages