Identity platform
Keycloak, database, realms and configuration are deployed reproducibly and kept upgradeable.

WZ-IT plans, installs and operates Keycloak as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
The following are trademarks of their respective owners: Keycloak (Red Hat, Inc.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

Keycloak is an open-source identity and access management (IAM) solution. The platform centralises authentication, single sign-on and authorisation functions for connected applications and APIs.
Keycloak supports OpenID Connect, OAuth 2.0 and SAML as well as connections to directory services and external identity providers. Roles, login flows and the operating architecture are designed for the relevant environment.
We design, integrate and operate Keycloak for your organisation - on European infrastructure, in your cloud account or on-premises in your own environment.
We provide technical monitoring, backups and maintenance for your Keycloak instance. Human response times and support coverage follow the selected service level.
When Keycloak fails or is misconfigured, multiple applications are affected. We therefore treat runtime, database, protocols, directories, keys and emergency access as one system.
Keycloak, database, realms and configuration are deployed reproducibly and kept upgradeable.
OIDC, OAuth 2.0, SAML, LDAP and external identity providers are integrated in a controlled way.
Clients, roles, flows, MFA and token content are coordinated with application teams.
Monitoring, backups, updates, key rotation and break-glass access protect operations.
We operate the platform and integrate systems; business roles and permissions remain with the customer.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Architecture and Keycloak platform | WZ-IT | Sizing and operation of Keycloak, database, proxy and agreed cluster components. |
| Updates and monitoring | WZ-IT | Controlled version changes, technical monitoring and incident handling according to service level. |
| Backups and recovery | WZ-IT | Backup of database, configuration and relevant keys plus scheduled restore checks. |
| Clients and protocol integration | Shared | WZ-IT configures flows and mappings; application teams test login, logout and failure cases. |
| LDAP, AD and identity providers | Shared | Directory access, attributes, groups and synchronisation rules are agreed together. |
| Role and permission model | Customer | The customer owns business roles, approvals and the permissibility of access. |
| Themes, SPIs and custom flows | Optional WZ-IT service | Custom themes, providers and authentication flows can be developed and tested separately. |
Users authenticate once with Keycloak and automatically have access to all connected applications.
Support for OpenID Connect, OAuth 2.0 and SAML 2.0 to connect compatible applications and services.
Native integration with LDAP and Active Directory plus support for custom user stores.
External identity providers and social login services can be connected through configured broker flows.
Centralized web-based management of all aspects of Keycloak, applications, users, and policies.
Advanced authorization services with role-based and policy-based access control mechanisms.
Self-service portal for users to manage their profiles, passwords, and two-factor authentication.
Depending on login load, availability and dependencies, Keycloak can be deployed as a single instance or as part of a cluster architecture.
Themes for custom designs, extensive APIs and SPI for tailored extensions.
A clearly defined operating scope instead of an opaque hosting flat fee.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom Keycloak architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard Keycloak application is included in the Starter workload. Every service level also includes flexible expert time for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Briefly describe the current state and objective for Keycloak. We assess infrastructure, integration, and ongoing operations.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Centralised authentication for connected enterprise applications using SAML, OAuth 2.0 and OpenID Connect
IAM with user and role management, authorisation functions and configurable access controls
Connection of compatible external identity providers and social-login services through configured broker flows
Multi-factor authentication using OTP or WebAuthn with agreed recovery and emergency procedures
OAuth 2.0 and OpenID Connect as the identity and token foundation for APIs and service-to-service communication
Planned integration with existing Active Directory and LDAP directory services
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
Keycloak is modular to the core. Almost every functionality is a replaceable provider. We use Java to implement these SPIs and adapt Keycloak exactly to your infrastructure.
The most important point: We don't necessarily migrate your users. We develop User Storage Providers allowing Keycloak to read users directly from your existing SQL DB, mainframe, or API - without duplication.
Audit compliance requires gapless logs. We write Event Listeners that stream every login, error, and admin action to your SIEM (Splunk, ELK, Graylog) in real-time.
The standard login window is off-putting. We develop responsive, accessible themes (based on your CI/CD) that seamlessly integrate the login experience into your application.
How we implement Keycloak development in practice.
You have thousands of users in an old MySQL database of an EOL software that cannot be migrated.
A 'read-only' User Storage SPI connects the old DB. Keycloak authenticates against old hashes but issues modern OAuth2/OIDC tokens for new apps.
B2C customers constantly forget passwords. The login process must be frictionless.
Implementation of a custom authentication flow that only asks for emails and sends magic links. Fully integrated into Keycloak core, secure, and audited.
Your application needs specific data in the JWT (e.g., tenant ID, cost center) not found in LDAP.
A Script Mapper (JavaScript) or Protocol Mapper (Java) loads this data from an external API during login and signs it into the access token.
User count alone says little. Login peaks, token refreshes, client count, federation, sessions and availability targets determine the architecture.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Internal SSO for a few applications | S or M, external database | Suitable for moderate login load and a clearly limited set of clients. |
| Many applications, realms or directories | M or L, separate database | Federation, sessions, token lifetimes and peaks are measured or estimated. |
| Public login or high authentication load | Custom architecture | Load tests, cache behaviour, rate limits and abuse protection are included. |
| Business-critical or highly available IAM | Custom architecture | Cluster, database, keys, upstream IdPs and break-glass procedures must work as one system. |
The calculator is a starting point for a standard instance. HA, load testing, complex federation and multiple environments are designed individually.
Keycloak can run on WZ-IT infrastructure, in your cloud, on-premises or close to distributed applications and directory services in a hybrid design.
Operations on European infrastructure with compute, backup, monitoring and a selectable service level.
Operations in your cloud with existing network, security and logging services.
Integration with your data centre, virtualisation and internal directory services.
Secure connection to distributed applications, clouds, LDAP/AD and external identity providers.
Keycloak connects users, directories and applications. We document trust relationships, token flows, administrative access and failure paths.
Browsers, mobile apps, APIs, service accounts and administrative access.
TLS, reverse proxy, rate limits, network rules and separated administration paths.
LDAP/AD, social or enterprise IdPs plus defined federation and broker flows.
Realms, clients, sessions, roles, MFA, flows and token issuance.
Persistent configuration, sessions and, where needed, cluster cache for the target availability.
OIDC, OAuth and SAML integrations with tested login, logout and failure paths.
Metrics, events, logs, alerts and optional forwarding to SIEM or central observability.
Identity is a shared dependency. Changes are therefore planned with staging, defined rollback steps and emergency access.
Answers about migration, SSO, high availability and operations.
Yes. We assess version, realms, clients, themes, SPIs, database and connected identity providers, then plan test upgrade, backup, cutover and fallback.
Yes. We integrate applications using the appropriate standard protocol and test login, token refresh, logout, role transfer and failure cases with application teams.
Yes. We design connection, attributes, groups, synchronisation mode and behaviour during outages. The customer defines the business meaning of groups and roles.
When several business-critical applications depend on login and tolerated downtime is low. Keycloak, database, cache, proxy and upstream IdPs must then be considered as one chain.
We assess release notes and extensions, back up relevant data, test critical flows in a suitable environment and plan maintenance windows and rollback steps.
Yes. Themes, user-storage providers, event listeners and other extensions are versioned, tested and included in the upgrade process as separate development services.
This depends on the federation or broker model. We document dependencies and design technical emergency access, monitoring and recovery without bypassing business access controls.
Whether you run Keycloak in-house or need to host confidentiality-professional data §203-ready - we build, operate and maintain Keycloak on an encrypted on-site server. Data never leaves the building in cleartext.
See Keycloak on-premise
11.05.2026
On 3 May 2026 the Vaultwarden maintainer team released version 1.36.0 — closing six security advisories, one of which is a server-side request forgery that...
01.04.2026
If you're looking for an Okta or Auth0 alternative, two open-source projects quickly rise to the top: Authentik and Zitadel. Both solve the same problem...
These solutions are often used together with Keycloak
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
