Managed Keycloak Hosting
for complex IAM requirements.
Your own Keycloak instance for SAML, identity brokering, AD federation and separate realms. authhost operates the Java stack on Quarkus, including PostgreSQL and the Infinispan cache.
- SAML 2.0 as identity provider and service provider
- LDAP and AD federation with write-back
- Dedicated instance, not a shared tenant
- Cancel monthly
Your instance is ready within 5 minutes of ordering in the portal.
7-day trial. Credit card required. Automatically becomes a paid subscription unless you cancel beforehand. Cancel monthly.
What Keycloak is built for
Keycloak combines federation, tenant separation and fine-grained authorization for IAM environments with demanding requirements.
- 01
Keycloak is Apache-2.0 licensed, is a CNCF Incubating project and is backed by Red Hat. The application runs with Java on Quarkus. Its broad scope ranges from SAML 2.0 as an identity provider and service provider to identity brokering, directory federation and authorization services.
- 02
It fits tenders, public authorities and corporate subsidiaries, as well as projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms serve as tenant boundaries, while client policies and step-up authentication cover rules for individual use cases.
- 03
authhost operates Authentik, Keycloak and Zitadel. If requirements change, switching the identity provider therefore does not require switching the operations provider. The choice can follow the functional need, not an existing provider relationship.
What your Keycloak instance can do
The functions are particularly suited to federated directories, SAML environments and separated tenants.
SAML 2.0 in both roles
Keycloak works as both an identity provider and a service provider. This matters in enterprise and public-sector environments shaped by SAML.
Identity brokering
External identity sources can be connected through Keycloak in a central sign-in structure.
LDAP and AD federation
Existing LDAP and Active Directory sources can be connected, including write-back.
User Storage SPI
The User Storage SPI lets Keycloak include further user stores in identity management.
Authorization Services
Fine-Grained Authorization Services represent differentiated authorization requirements within the platform.
Realms as tenant boundaries
Separate realms structure tenants within a Keycloak instance.
Client policies
Client policies collect requirements for connected clients and their configuration.
Step-up authentication
Keycloak can require additional authentication for selected situations.
Transparent pricing. No surprises.
Start your own instance in 5 minutes. No per-user fees in any plan.
Select Region
Included in every tier
Features
- SSO via OIDC, OAuth2 and SAML 2.0
- SAML 2.0 as identity provider and service provider
- Identity brokering to external providers
- LDAP and AD federation including write-back
- User storage SPI for your own user sources
- Realms with no count limit
- Fine-grained authorization services
- Client policies and step-up authentication
- MFA: TOTP, WebAuthn and passkeys
- SCIM API for provisioning (preview, behind a feature flag)
The feature scope follows the respective open source project and can change with new releases. The official documentation is authoritative; all details without warranty: keycloak.org/documentation
Included in the hosting
- Dedicated instance, no shared hosting
- Users with no count limit
- Subdomain included (*.authhost.de)
- Your own domain possible
- PostgreSQL included
Operations
Automatic backups and updates · 24/7 monitoring · 99.9 % availability commitment · Hosted in Germany · Data processing agreement included · No setup fee, cancel monthly
Choose your support
Everything above is included in every tier. You only decide how quickly we are available.
Choose your instance size
The size determines compute and memory, not the feature scope. When a size stops being enough, we move you up during operation.
M
Instance sizeexcl. VAT · incl. support Essential
- 4 vCPU
- 8 GB RAM
- 160 GB NVMe
- 20 TB traffic
Your instance is ready within 5 minutes of ordering in the portal.
7-day trial. Credit card required. Automatically becomes a paid subscription unless you cancel beforehand. Cancel monthly.
L
Instance sizeexcl. VAT · incl. support Essential
- 8 vCPU
- 16 GB RAM
- 320 GB NVMe
- 20 TB traffic
Your instance is ready within 5 minutes of ordering in the portal.
7-day trial. Credit card required. Automatically becomes a paid subscription unless you cancel beforehand. Cancel monthly.
Keycloak runs on the JVM and needs more memory than a Python or Go stack. The smallest size is therefore not offered for Keycloak.
Outside Germany, size L has 6 instead of 8 vCPU; the other specs are identical.
Hosting alone if that is all you need. Additional help from Timo and the WZ-IT expert network when needed, at reduced hourly and daily rates for hosting customers. Explore expert support
All prices are net, plus statutory VAT. This offer is directed exclusively at businesses within the meaning of § 14 German Civil Code, not at consumers.
What matters in Keycloak operations
The complexity lies mainly in caching, high availability, JVM sizing and controlled upgrades.
PostgreSQL and Infinispan
Keycloak requires PostgreSQL plus an Infinispan cache. Since version 26, persistent sessions are stored in the database.
Complex high availability
An HA setup requires suitable cluster discovery and cache topology. Both layers need to be sized together with the instance.
Upgrades with known break points
The move from version 25 to 26 included a marshalling break that caused session loss. The earlier change from WildFly to Quarkus took place with version 17 in 2022.
Compatibility policy since 2024
Since October 2024, breaking changes in minor releases are opt-in through feature and API versioning. Removals only arrive with a major release. Much of the older criticism of the upgrade cycle comes from the period before this policy.
JVM sizing
As a JVM application, Keycloak needs considerably more RAM than a Python or Go stack. The guideline is at least 1 GB plus JVM tuning.
Backups, monitoring and commitment
Automatic backups stay in the same region and 24/7 monitoring watches the instance. The availability commitment is 99.9 % on every size. Support responds within 24 hours on Essential, 4 hours on Business, 1 hour on Priority or 60 minutes around the clock on Enterprise, depending on the tier.
Data location and processing
The German region runs in data centers with ISO 27001 and BSI C5. The other seven regions run in data centers with ISO 27001 and SOC 2 Type II. Germany is the default region.
You can choose Germany, the Netherlands, the USA, Canada, Singapore, Japan, Australia or India. Every customer instance is dedicated and is not operated as a shared tenant.
The data processing agreement under Article 28 GDPR is included in every plan. Automatic backups remain in the same region as the Keycloak instance.
How you get to your Keycloak instance
From signup to the first connected directory it takes four steps.
- 1
Start the instance
Pick size, support tier and region, the instance is provisioned. The trial runs for 7 days and a credit card is required at signup.
- 2
Create realms
Separate tenants the way your organisation needs: per subsidiary, per customer or per environment. The number is not capped.
- 3
Connect directories
Set up LDAP or AD federation, with write-back where needed, or connect an existing provider through identity brokering.
- 4
Hand over operations
After the trial the instance converts automatically to the selected plan. Updates, backups and monitoring are ours from then on.
Managed hosting with direct access to expertise
IAM hosting with a direct point of contact.
Founder, merkaio
LinkedIn profileAt authhost, you book managed hosting for Authentik, Keycloak or Zitadel. Discuss instance sizing and operations directly with me, Timo Wevelsiep. We do not currently offer IAM migrations or the transfer of existing users or application integrations.
I have delivered hundreds of complex infrastructure, IoT and networking projects. As managing director of WZ-IT, I bring that experience to your project and can involve our expert network across infrastructure, cloud, IoT and networking.
A clear scope for your operations
We operate your dedicated instance. Your identity workflows, user directories and connected applications remain the responsibility of your team or implementation partner.
Hosting support is subject to the response times and service hours of your selected support tier.
A 15-minute introductory call to discuss your requirements.
Read on
Managed Authentik hosting
For conventional mid-sized companies that need central sign-in and a managed dedicated instance.
Managed Zitadel hosting
For software vendors and SaaS providers using organizations, an audit log and an API-first approach.
Which identity provider fits?
Authentik, Authelia and Keycloak compared directly with a decision matrix.
Frequently asked questions about managed Keycloak hosting
What does managed Keycloak hosting cost?+
Managed Keycloak hosting starts at €149.90 net per month in Germany with size M, and at €169.90 in the other regions. You select the instance size and support tier to match your requirements. There is no setup fee, the subscription can be cancelled monthly, and the data processing agreement is included.
Who is Keycloak suitable for?+
Keycloak fits tenders, public authorities, corporate subsidiaries and projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms, identity brokering and federation of existing directories are among its defining functions.
Why is Keycloak demanding to operate?+
The stack includes PostgreSQL and Infinispan. High availability requires planning cluster discovery and cache topology. There is also the JVM: as a guideline, Keycloak requires at least 1 GB of RAM plus JVM tuning.
How risky are Keycloak upgrades?+
Upgrades remain an important operational issue. The move from version 25 to 26 included a marshalling break with session loss. Since October 2024, a compatibility policy limits breaking changes in minor releases to opt-in changes through feature and API versioning, with removals only in major releases.
Which federation functions does Keycloak provide?+
Keycloak supports SAML 2.0 as an identity provider and service provider, identity brokering, and LDAP and AD federation including write-back. The User Storage SPI can include further user stores.
Where are data and backups stored?+
The default region is Germany, in data centers with ISO 27001 and BSI C5. Seven further regions are available. Automatic backups stay in the same region as the instance.
What availability and support response apply?+
The availability commitment is 99.9 % on every size. Support responds within 24 hours on Essential, 4 hours on Business, 1 hour on Priority or 60 minutes around the clock on Enterprise, depending on the tier. The instance is monitored around the clock.
How does the 7-day period work?+
The trial runs for 7 days. A credit card is required at signup, and when the trial ends it converts automatically into the selected paid subscription. If you do not want to continue, cancel beforehand.
Have your Keycloak instance sized
Discuss SAML, AD, realm and availability requirements with us. The trial runs for 7 days, a credit card is required, and it then converts automatically into the selected paid subscription.
Your instance is ready within 5 minutes of ordering in the portal.
7-day trial. Credit card required. Automatically becomes a paid subscription unless you cancel beforehand. Cancel monthly.