Dedicated instance · Hosted in Germany · DPA included

Managed Keycloak Hosting
for complex IAM requirements.

Your own Keycloak instance for SAML, identity brokering, AD federation and separate realms. authhost operates the Java stack on Quarkus, including PostgreSQL and the Infinispan cache.

  • SAML 2.0 as identity provider and service provider
  • LDAP and AD federation with write-back
  • Dedicated instance, not a shared tenant
  • Cancel monthly
GDPR-compliant
8 Regions Worldwide
Open Source & auditable
24/7 Monitoring
ISO 27001 data centers, plus BSI C5 in DE

What Keycloak is built for

Keycloak combines federation, tenant separation and fine-grained authorization for IAM environments with demanding requirements.

  1. 01

    Keycloak is Apache-2.0 licensed, is a CNCF Incubating project and is backed by Red Hat. The application runs with Java on Quarkus. Its broad scope ranges from SAML 2.0 as an identity provider and service provider to identity brokering, directory federation and authorization services.

  2. 02

    It fits tenders, public authorities and corporate subsidiaries, as well as projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms serve as tenant boundaries, while client policies and step-up authentication cover rules for individual use cases.

  3. 03

    authhost operates Authentik, Keycloak and Zitadel. If requirements change, switching the identity provider therefore does not require switching the operations provider. The choice can follow the functional need, not an existing provider relationship.

What your Keycloak instance can do

The functions are particularly suited to federated directories, SAML environments and separated tenants.

SAML 2.0 in both roles

Keycloak works as both an identity provider and a service provider. This matters in enterprise and public-sector environments shaped by SAML.

Identity brokering

External identity sources can be connected through Keycloak in a central sign-in structure.

LDAP and AD federation

Existing LDAP and Active Directory sources can be connected, including write-back.

User Storage SPI

The User Storage SPI lets Keycloak include further user stores in identity management.

Authorization Services

Fine-Grained Authorization Services represent differentiated authorization requirements within the platform.

Realms as tenant boundaries

Separate realms structure tenants within a Keycloak instance.

Client policies

Client policies collect requirements for connected clients and their configuration.

Step-up authentication

Keycloak can require additional authentication for selected situations.

Transparent pricing. No surprises.

Start your own instance in 5 minutes. No per-user fees in any plan.

Select Region

Support

M

Instance size
14,990.00per month

excl. VAT

  • 4 vCPU
  • 8 GB RAM
  • 160 GB NVMe
  • 20 TB traffic

Support: Standard

  • 24-hour response
  • Mon to Fri, 08:00 to 17:00 CET/CEST
  • Ticket system, intake by email
Get started

7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.

L

Instance size
24,990.00per month

excl. VAT

  • 8 vCPU
  • 16 GB RAM
  • 320 GB NVMe
  • 20 TB traffic

Support: Standard

  • 24-hour response
  • Mon to Fri, 08:00 to 17:00 CET/CEST
  • Ticket system, intake by email
Get started

7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.

Keycloak runs on the JVM and needs more memory than a Python or Go stack. The smallest size is therefore not offered for Keycloak.

The instance is sized to your use case. When a size stops being enough, we move you up during operation. Outside Germany, size L has 6 instead of 8 vCPU; the other specs are identical.

Features

  • SSO via OIDC, OAuth2 and SAML 2.0
  • SAML 2.0 as identity provider and service provider
  • Identity brokering to external providers
  • LDAP and AD federation including write-back
  • User storage SPI for your own user sources
  • Realms with no count limit
  • Fine-grained authorization services
  • Client policies and step-up authentication
  • MFA: TOTP, WebAuthn and passkeys

Included in every size

  • Dedicated instance, no shared hosting
  • Users with no count limit
  • Subdomain included (*.authhost.de)
  • Your own domain possible
  • PostgreSQL included
  • 99.9 % availability commitment
  • Automatic backups and updates
  • 24/7 monitoring
  • Hosted in Germany
  • Data processing agreement included
  • No setup fee, cancel monthly

All prices are net, plus statutory VAT. This offer is directed exclusively at businesses within the meaning of § 14 German Civil Code, not at consumers.

What matters in Keycloak operations

The complexity lies mainly in caching, high availability, JVM sizing and controlled upgrades.

PostgreSQL and Infinispan

Keycloak requires PostgreSQL plus an Infinispan cache. Since version 26, persistent sessions are stored in the database.

Complex high availability

An HA setup requires suitable cluster discovery and cache topology. Both layers need to be sized together with the instance.

Upgrades with known break points

The move from version 25 to 26 included a marshalling break that caused session loss. The earlier change from WildFly to Quarkus took place with version 17 in 2022.

Compatibility policy since 2024

Since October 2024, breaking changes in minor releases are opt-in through feature and API versioning. Removals only arrive with a major release. Much of the older criticism of the upgrade cycle comes from the period before this policy.

JVM sizing

As a JVM application, Keycloak needs considerably more RAM than a Python or Go stack. The guideline is at least 1 GB plus JVM tuning.

Backups, monitoring and commitment

Automatic backups stay in the same region and 24/7 monitoring watches the instance. The availability commitment is 99.9 % on every size. Support responds within 24 hours, 4 hours or 30 minutes, depending on the tier.

What managed Keycloak costs elsewhere

Publicly stated prices, as of 2 August 2026. The row that differs most is not the price but what gets capped.

ProviderPrice per monthWhat is capped
authhost, size M149.90 €Nothing. Users and realms with no count limit, dedicated instance
Skycloak Launch149 USDCluster size, users uncapped
zunicode189 €100 users and 2 realms
Cloud-IAMfrom 225 €Billed by total user count
plusserveraround 320 €Per provider information
Phase Two149 to 2,999 USDConcurrent sessions
Elestiofrom 11 USDSelf-service, support billed separately

Competitor prices per their public information, as of 2 August 2026, partly in USD without conversion. Plans change, so please verify before deciding. On a dedicated instance there is no cost basis for user or realm limits, which is why we cap neither. What determines the price is instance size, and that is in the pricing overview.

Data location and processing

The German region runs in data centers with ISO 27001 and BSI C5. The other seven regions run in data centers with ISO 27001 and SOC 2 Type II. Germany is the default region.

You can choose Germany, the Netherlands, the USA, Canada, Singapore, Japan, Australia or India. Every customer instance is dedicated and is not operated as a shared tenant.

The data processing agreement under Article 28 GDPR is included in every plan. Automatic backups remain in the same region as the Keycloak instance.

How you get to your Keycloak instance

From signup to the first connected directory it takes four steps.

  1. 1

    Start the instance

    Pick size, support tier and region, the instance is provisioned. The trial runs for 7 days and a credit card is required at signup.

  2. 2

    Create realms

    Separate tenants the way your organisation needs: per subsidiary, per customer or per environment. The number is not capped.

  3. 3

    Connect directories

    Set up LDAP or AD federation, with write-back where needed, or connect an existing provider through identity brokering.

  4. 4

    Hand over operations

    After the trial the instance converts automatically to the selected plan. Updates, backups and monitoring are ours from then on.

Frequently asked questions about managed Keycloak hosting

What does managed Keycloak hosting cost?+

The price is set after technical sizing of the instance and agreed through direct contact. No fixed Keycloak prices are currently listed. There is no setup fee, the subscription can be cancelled monthly, and the data processing agreement is included.

Who is Keycloak suitable for?+

Keycloak fits tenders, public authorities, corporate subsidiaries and projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms, identity brokering and federation of existing directories are among its defining functions.

Why is Keycloak demanding to operate?+

The stack includes PostgreSQL and Infinispan. High availability requires planning cluster discovery and cache topology. There is also the JVM: as a guideline, Keycloak requires at least 1 GB of RAM plus JVM tuning.

How risky are Keycloak upgrades?+

Upgrades remain an important operational issue. The move from version 25 to 26 included a marshalling break with session loss. Since October 2024, a compatibility policy limits breaking changes in minor releases to opt-in changes through feature and API versioning, with removals only in major releases.

Which federation functions does Keycloak provide?+

Keycloak supports SAML 2.0 as an identity provider and service provider, identity brokering, and LDAP and AD federation including write-back. The User Storage SPI can include further user stores.

Where are data and backups stored?+

The default region is Germany, in data centers with ISO 27001 and BSI C5. Seven further regions are available. Automatic backups stay in the same region as the instance.

What availability and support response apply?+

The availability commitment is 99.9 % on every size. Support responds within 24 hours, 4 hours or 30 minutes, depending on the tier. The instance is monitored around the clock.

How does the 7-day period work?+

The trial runs for 7 days. A credit card is required at signup, and when the trial ends it converts automatically into the selected paid subscription. If you do not want to continue, cancel beforehand.

Have your Keycloak instance sized

Discuss SAML, AD, realm and availability requirements with us. The trial runs for 7 days, a credit card is required, and it then converts automatically into the selected paid subscription.