KeycloakPro

Service Packages

Fixed-price Keycloak implementations with clear scope, timeline, and deliverables. No hourly billing surprises.

Most Popular

Multi-Tenancy SaaS IAM

Every enterprise customer has their own IDP. We configure Keycloak to federate Okta, Azure AD, Auth0, and SAML providers. One endpoint for your app. Zero per-customer auth work for your team.

  • Keycloak multi-tenant setup: Organizations + domain-based routing
  • Per-tenant IDP federation: Okta, Azure AD, Auth0, SAML 2.0, OIDC
  • SSO integration for Spring Boot, Next.js, Angular, Django, Flask, and PHP
  • +2 more
View Details →

B2B CIAM: Organizations & Entitlements

One Keycloak organization per customer, a custom entitlement service for products, plans and seats, and OpenFGA for fine-grained access. Customers are provisioned automatically the moment a deal closes in your CRM.

  • Keycloak Organizations tenancy model with per-customer SSO
  • Entitlement service: products, plans, seats and validity
  • Login-time entitlement check and lean token claims
  • +3 more
View Details →

Oracle & Legacy App SSO

Bring Oracle E-Business Suite, PeopleSoft, JD Edwards, Siebel and header-based legacy apps under Keycloak SSO and MFA, through integration paths Oracle supports and without touching application code.

  • Sign-on assessment per application and release
  • EBS Asserter / Oracle Access Manager federation to Keycloak
  • SAML 2.0 for PeopleSoft and JD Edwards where supported
  • +3 more
View Details →

Workforce & VPN MFA

Keycloak-backed MFA for Windows logon and RDP, macOS login, Linux SSH and sudo, and every major VPN over RADIUS or SAML. One MFA policy across desktops, servers and remote access.

  • Highly available RADIUS front end for Keycloak
  • VPN integration: Cisco, Palo Alto, Fortinet, Check Point and more
  • Windows credential provider and RD Gateway via NPS
  • +3 more
View Details →

AI Agent & MCP Security

Give every AI agent its own Keycloak identity with scoped, short-lived tokens, protect MCP servers with OAuth 2.1, and add human approval, audit trails and a tested kill switch.

  • Agent inventory and access model
  • Keycloak clients, scopes and audiences per agent
  • Token exchange for delegated, on-behalf-of access
  • +3 more
View Details →

Keycloak Production HA Cluster on Kubernetes

K8s deployment with Infinispan caching, PostgreSQL 16, blue-green rollouts, and full observability. Targets 99.9%+ availability.

  • K8s manifests / Helm charts
  • PostgreSQL 16 HA (primary-replica)
  • Infinispan distributed session cache
  • +3 more
View Details →

Certificate-Based Authentication

Map X.509 client certificates to Keycloak users for device-bound, passwordless Single Sign-On (SSO). Managed devices log in without friction. Unmanaged devices are hard-blocked before they reach a login page.

  • X.509 certificate-to-user mapper (Subject DN / Subject Alternative Name)
  • Mutual TLS (mTLS) termination config (Nginx / HAProxy)
  • Certificate revocation via OCSP and CRL
  • +3 more
View Details →

CIAM Foundation & Federation

End-to-end identity foundation: passkeys, configurable MFA flows, federated brokering across SAML/OIDC providers, custom branded UI, and compliance audit logging.

  • Complete IAM architecture design
  • Passkeys + configurable MFA flows
  • Federated identity brokering (SAML / OIDC)
  • +3 more
View Details →

Custom Auth SPI — Passwordless SMS OTP & Push Login

Keycloak Authentication SPIs for passwordless e-commerce login: customers check out with a phone number and SMS One-Time Password (OTP), while returning mobile users get one-tap push approval.

  • SMS OTP passwordless login SPI
  • Push notification login SPI
  • Passwordless authentication flow configuration
  • +3 more
View Details →

Custom SPI & SIEM Integration

Bespoke event listener SPIs, protocol mappers for custom token claims, Kafka event streaming, SIEM forwarding, and full Terraform IaC for your Keycloak realm.

  • Custom event listener SPIs
  • Protocol mappers (custom token claims)
  • Kafka event streaming
  • +3 more
View Details →

Custom Branding & Login UI

Pixel-perfect custom login, registration, and account pages that match your product's design system — delivered as FreeMarker themes deployable per realm.

  • Custom FreeMarker login theme
  • Registration & forgot-password pages
  • Account management page
  • +3 more
View Details →

Social Login & CIAM Setup

Google, Apple, GitHub, Facebook, and LinkedIn identity providers wired into Keycloak — with self-registration, email verification, account linking, and consent management.

  • Social IdP config (up to 4 providers)
  • Self-registration flow
  • Email verification
  • +3 more
View Details →

Passkeys & Passwordless Login

Full WebAuthn/FIDO2 implementation with fallback OTP flows, device management UI, and a Keycloak Required Action that nudges existing users to enrol on their next login.

  • WebAuthn registration flow
  • Passkey login flow
  • Fallback TOTP flow
  • +3 more
View Details →

Managed Keycloak-as-a-Service

Ongoing management, monitoring, patching, scaling, and incident response. Your dedicated Keycloak ops team — without the overhead of hiring one.

  • Continuous monitoring & alerting
  • Security patches within 72 hours of release
  • Scaling & performance optimisation
  • +3 more
View Details →

Not sure which package fits? We’ll help you figure it out.