Keycloak – Open-Source Identity & Access Management
Central authentication for all your applications – open source, self-hosted and GDPR-compliant.
Keycloak is our standard for identity & access management – with everything you need for secure logins and access control.
Keycloak: Central Authentication
Open-source identity provider with SSO, MFA and federation – operated and secured by RiKuWe.
- Single Sign-On (SSO) via OIDC & SAML
- Multi-Factor Authentication (MFA)
- Central user & role management with Admin UI
Why Keycloak?
Keycloak is the leading open-source identity provider – developed under the umbrella of Red Hat and the CNCF:
- Single Sign-On for web, mobile and API applications
- Standard protocols such as OIDC, SAML 2.0 and OAuth 2.0
- Federation with existing directory services (LDAP, Active Directory)
- Social login via Google, Microsoft, GitHub & more – optional and configurable
Keycloak replaces fragmented login solutions with a single, traceable instance.
Typical Use Cases
- Central login for custom-built web applications
- SSO across multiple internal services (Gitea, Harbor, Grafana, etc.)
- Multi-tenant setups with separate realms per client or department
- Migration from LDAP/AD to a modern, web-based solution
- API security via token-based authentication
Features in Detail
- Admin console for users, groups, roles & policies
- Account management as self-service for end users
- MFA via TOTP, WebAuthn or SMS
- Brute-force protection & session management
- Event logging & audit trails for compliance
- Themes & branding – customizable to match your corporate design
Integration into Your Stack
We operate Keycloak as the central identity provider in your infrastructure – integrated into:
- Kubernetes clusters as a containerized service
- Git & CI/CD – SSO for Gitea, GitLab & Woodpecker
- Container Registries – access control for Harbor
- Monitoring – protected dashboards in Grafana
- Custom web applications via OIDC or SAML
Why RiKuWe?
- Full operations including setup, updates, backup & support
- Secure configuration – hardened and documented
- GDPR-compliant – all data remains under your control
- Scalable – from a handful of users to thousands of accounts
- Integrated into your existing infrastructure, not as an isolated solution
We make authentication a reliable part of your operations – not a risk.
Real-World Example
An Austrian NGO uses Keycloak as the central authentication for its on-premises web application – read the case study.