Connector · Open-source identity server

Keycloak, running inside your platform.

How our authentication module and admin backoffice use Keycloak, the open-source identity server: what it does for customers and staff, and how we run it with you.

Website
keycloak.org
Modules
Authentication, Admin backoffice
Licence
Open source

What Keycloak is

Keycloak is an open-source identity and access management server, released under the Apache License 2.0. It speaks OpenID Connect, OAuth 2.0 and SAML 2.0, brokers sign-in from other identity providers and social networks, connects to existing LDAP and Active Directory servers, and supports one-time codes and passkeys.

It grew up under Red Hat's stewardship and joined the Cloud Native Computing Foundation as an incubating project in 2023. Companies choose it to keep identity on their own infrastructure, which is why it is one of the identity providers our authentication module and backoffice connect to.

What it does in your platform

  • Authentication

    Signs your customers in on your own servers, over OpenID Connect. Keycloak holds the accounts and the sign-in methods, from passwords to passkeys; the module adds trusted devices, sessions and the second factor on payments.

  • Admin backoffice

    Signs your staff in to the backoffice. Keycloak can hold the staff accounts itself or pass sign-in through to your Active Directory or LDAP, and the groups it sends decide each person's role.

How the connection works

The authentication module talks to Keycloak over OpenID Connect. Keycloak runs in your platform, so accounts, credentials and the keys that sign its tokens stay on your infrastructure.

  1. The app asks Keycloak

    The app sends a standard OpenID Connect request to your Keycloak realm, the isolated space that holds your customers and their credentials.

  2. Keycloak checks them

    With a password and a one-time code, a passkey, or an account brokered from Google or another OpenID Connect or SAML provider. Brute-force detection locks out repeated guessing.

  3. Tokens come back

    Keycloak returns signed tokens. The module checks them against the realm's public keys and opens a session tied to the customer's device.

  4. A payment asks for more

    When the customer confirms a transfer or a card payment, the module asks for the second factor strong customer authentication requires, on top of the Keycloak session.

  5. Everything is on record

    Keycloak records login and admin events as audit streams, and the module's sign-in and session events show up in the backoffice.

Next to other providers

Staff and customers do not have to share an identity provider. Keycloak can sign in your staff while customers use the module's own passkey sign-in, or sign in customers while staff keep the directory your company already runs.

Because the module speaks OpenID Connect and SAML rather than Keycloak's own interfaces, moving from Keycloak to a hosted provider later, or the other way round, does not change your apps. Sessions, devices and sign-in history stay in the platform.

When Keycloak fits best

A strong fit when

  • You want identity on your own infrastructure, with no outside service holding your customers' credentials.
  • You need OpenID Connect, SAML, LDAP and Active Directory in one server, for customers and staff alike.
  • You want to own your identity server, with us running it next to the rest of your platform.

Also worth a look

  • A hosted identity provider such as Okta, Auth0 or Microsoft Entra ID, when you would rather not run identity yourselves.
  • The module's own sign-in server, when you need no separate identity product at all.

How we get you live

  • The deployment

    We deploy Keycloak in your platform, in the region your data has to stay in, with its database, backups and monitoring next to the rest of your services.

  • The realms

    We set up the realms with you: the sign-in methods, your password, lockout and session policies, and the groups that become backoffice roles.

  • The keys

    Client secrets and admin credentials go into your platform's secrets and nowhere else, and the keys that sign Keycloak's tokens never leave Keycloak.

  • A full test run

    A staging copy of Keycloak runs the whole flow, from sign-up to a confirmed payment and a staff sign-in, before your first real customer.

Questions

Asked about this connector.

How do we get started with Keycloak?

Talk to us. We deploy Keycloak in your platform, set up the realms and sign-in methods with you, connect it to the authentication module and the backoffice, and test the whole flow on a staging copy first.

Who runs Keycloak once we are live?

We deploy it and run it with the rest of your platform, and keep it up to date. It is open source under the Apache License 2.0, so your own team can take it over at any time.

Can staff sign in with our Active Directory?

Yes. Keycloak connects to Active Directory and LDAP servers and can sync users from them, and the groups it passes on can decide each person's role in the backoffice.

Where does our users' data live?

In your platform. Keycloak runs on your infrastructure with its own database, so credentials and profiles stay there, and the module keeps the sessions and the sign-in history.

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?