Keycloak for the systems other IdPs leave behind
B2B CIAM with organizations and entitlements, single sign-on for Oracle and other legacy applications, MFA at every desktop, server and VPN, and identity built for AI agents — delivered on upstream Keycloak you own.
- B2B CIAM: orgs, entitlements & OpenFGA
- Oracle EBS, PeopleSoft, JDE & Siebel
- Windows, macOS, Linux & VPN MFA
- OAuth for AI agents & MCP
B2B CIAM
Organizations, entitlements and fine-grained access
CIAM Reference Architecture
Orgs, entitlements & authorization
Separate what a customer bought from what a person may do. Keycloak owns identity and organizations, an entitlement service owns products, plans and seats, and OpenFGA answers resource-level questions — each fact with exactly one owner.
Learn moreOrganization Onboarding
Tenants, SSO & admin invites
Every business customer becomes a Keycloak organization with its own domains, identity provider, admins and members. We automate the provisioning, give customers a safe way to set up SSO, and enforce seats at the moment users join.
Learn moreEntitlement Service
Products, plans & seats per org
Identity providers have no place for plans, seats or contract dates. We build an entitlement service that does — fed by CRM and billing events, read at login and by every API, and publishing changes so access follows the contract.
Learn moreCRM-to-Identity Lifecycle
Closed-won to active org
When a deal closes or a subscription changes, access should follow without a ticket. We connect CRM and billing to Keycloak and the entitlement service through an event-driven, idempotent onboarding saga — every step retryable and every change traceable.
Learn moreUser Migration into Orgs
Bulk import, org by org
We migrate users from your legacy store or current IdP into Keycloak organizations one customer at a time — importing password hashes where possible, recreating memberships, roles, seats and resource grants, and reconciling everything before each org cuts over.
Learn moreFine-Grained Authorization
OpenFGA for orgs & resources
Tokens answer the coarse questions — which organization, which product, which plan. Questions like “can Bob edit this workspace?” need relationships. We add OpenFGA with a model that ties every grant to org membership and an active product license, and keep it in sync with Keycloak and the entitlement service.
Learn more
Legacy App SSO
Modern SSO for Oracle and other enterprise applications
Oracle Access Manager Alternative
Replace OAM with Keycloak
Move sign-in, MFA and federation off Oracle Access Manager and onto open-source Keycloak — application by application, keeping the Oracle components each app is supported with, and without rewriting your applications.
Learn moreOracle E-Business Suite
SSO for EBS 12.2
We connect EBS to Keycloak through the integration paths Oracle supports, so users reach forms and self-service pages with one login and MFA — including their existing Entra ID, Okta or Active Directory credentials — without touching EBS application code.
Learn morePeopleSoft
SSO for PeopleSoft apps
HCM, Financials, Campus Solutions and Interaction Hub behind one Keycloak login with MFA — using the native SAML 2.0 support added in PeopleTools 8.63, or Signon PeopleCode behind a hardened proxy on earlier releases.
Learn moreJD Edwards
SSO for EnterpriseOne
EnterpriseOne's documented single sign-on runs through Oracle Access Management rather than SAML or OIDC directly. We keep that trusted path intact, federate it to Keycloak, and give web client users one login with MFA — including their Entra ID, Okta or AD credentials.
Learn moreSiebel CRM
SSO for Siebel CRM
Siebel CRM 17.0 and later support both header-based Web SSO and federated SSO with SAML. We connect whichever fits your deployment to Keycloak — hardened against spoofing — so agents and portal users get one login with MFA.
Learn moreOther Legacy Apps
Header-based & custom apps
Plenty of business-critical applications only understand an HTTP header, a cookie or their own login form. We put a hardened identity-aware proxy in front of them, authenticate users at Keycloak, and hand each application exactly the identity it expects.
Learn more
Workforce MFA
MFA for desktops, servers and VPNs
Windows Logon MFA
MFA for Windows & RDP
Keycloak doesn't run on Windows desktops by itself, so we add the pieces that let it: a credential provider for console and RDP logons, and RADIUS for Remote Desktop Gateway — all enforcing the MFA policy you already run in Keycloak.
Learn moremacOS Login MFA
MFA at the Mac login
Macs sign in to local accounts by default. We add a login-window agent that authenticates users against Keycloak with MFA, keeps the local password in step with Keycloak, and behaves predictably with FileVault and without a network.
Learn moreLinux & SSH MFA
MFA for servers & sudo
We protect server access two ways: PAM modules that check a second factor against Keycloak for SSH and sudo, or short-lived SSH certificates issued only after a Keycloak login — so long-lived keys stop being the way in.
Learn moreVPN MFA (RADIUS)
MFA for every major VPN
Most VPNs can check a second factor over RADIUS, and many can hand sign-in to a SAML identity provider. We connect yours to Keycloak the best way it supports — so remote access uses the same users, groups and MFA as everything else.
Learn more
AI Agent Security
Identity, authorization and governance for AI agents
Secure AI Agents
Identity for AI agents
Agents call APIs, read data and act for people. We give each one its own Keycloak identity, issue tokens scoped to the task and valid for minutes, and make delegation explicit — so you always know which agent did what, and for whom.
Learn moreMCP Authorization
OAuth for MCP servers
The Model Context Protocol expects remote MCP servers to be protected with OAuth. We set Keycloak up as that authorization server — discovery, PKCE, client registration and tokens bound to the right MCP server — and fill the gaps where the spec and Keycloak differ.
Learn moreAI Governance
Control what agents can do
As agents multiply, the questions from security and audit get sharper: which agents exist, what can each one reach, who approved it, and how fast can we shut it off? We make Keycloak the place where those answers live.
Learn more