B2B SSO with Organizations
Domain Mapping · IDP Routing
Keycloak Organizations enables B2B SSO by mapping user email domains to enterprise identity providers. Applications authenticate against a single Keycloak endpoint — Keycloak detects the domain and routes each user to their organization’s IDP automatically.
How It Works
Technical Highlights
How Organizations Work
Keycloak Organizations groups users into logical tenants within a single realm. Each organization maps one or more email domains (e.g., @acme.com) to a specific identity provider — Okta, Azure AD, Google Workspace, or any SAML/OIDC-compliant IdP. When a user enters their email at login, Keycloak resolves the organization and redirects to the correct IdP without any application-side logic.
Domain-Based IDP Routing
The application has one integration point: Keycloak. When login begins, Keycloak’s home realm discovery checks the email domain against all configured organizations. On a match, the user is transparently redirected to that organization’s IdP. After authentication, Keycloak issues a standard session token — the application never interacts with the upstream IdP directly.
Delegated Organization Admin
Each organization has its own admins who manage membership, configure the IdP connection, and invite users — all without realm-level access. Just-in-time user provisioning creates Keycloak accounts on first login from the org IdP, and organization-scoped token claims let downstream services enforce tenant-aware authorization.
Why in 2026
B2B SaaS customers expect to log in via their own corporate IdP. Keycloak Organizations delivers this from a single realm, with no custom application-side routing code required.
Related service package: Multi-Tenancy SaaS IAM
Delivery: 3–4 weeks
Ready to implement B2B SSO with Organizations?
Fixed price. Clear scope. 30-day warranty.