Managed Keycloak Hosting
for complex IAM requirements.
Your own Keycloak instance for SAML, identity brokering, AD federation and separate realms. authhost operates the Java stack on Quarkus, including PostgreSQL and the Infinispan cache.
- SAML 2.0 as identity provider and service provider
- LDAP and AD federation with write-back
- Dedicated instance, not a shared tenant
- Cancel monthly
What Keycloak is built for
Keycloak combines federation, tenant separation and fine-grained authorization for IAM environments with demanding requirements.
- 01
Keycloak is Apache-2.0 licensed, is a CNCF Incubating project and is backed by Red Hat. The application runs with Java on Quarkus. Its broad scope ranges from SAML 2.0 as an identity provider and service provider to identity brokering, directory federation and authorization services.
- 02
It fits tenders, public authorities and corporate subsidiaries, as well as projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms serve as tenant boundaries, while client policies and step-up authentication cover rules for individual use cases.
- 03
authhost operates Authentik, Keycloak and Zitadel. If requirements change, switching the identity provider therefore does not require switching the operations provider. The choice can follow the functional need, not an existing provider relationship.
What your Keycloak instance can do
The functions are particularly suited to federated directories, SAML environments and separated tenants.
SAML 2.0 in both roles
Keycloak works as both an identity provider and a service provider. This matters in enterprise and public-sector environments shaped by SAML.
Identity brokering
External identity sources can be connected through Keycloak in a central sign-in structure.
LDAP and AD federation
Existing LDAP and Active Directory sources can be connected, including write-back.
User Storage SPI
The User Storage SPI lets Keycloak include further user stores in identity management.
Authorization Services
Fine-Grained Authorization Services represent differentiated authorization requirements within the platform.
Realms as tenant boundaries
Separate realms structure tenants within a Keycloak instance.
Client policies
Client policies collect requirements for connected clients and their configuration.
Step-up authentication
Keycloak can require additional authentication for selected situations.
Transparent pricing. No surprises.
Start your own instance in 5 minutes. No per-user fees in any plan.
Select Region
Support
M
Instance sizeexcl. VAT
- 4 vCPU
- 8 GB RAM
- 160 GB NVMe
- 20 TB traffic
Support: Standard
- 24-hour response
- Mon to Fri, 08:00 to 17:00 CET/CEST
- Ticket system, intake by email
7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.
L
Instance sizeexcl. VAT
- 8 vCPU
- 16 GB RAM
- 320 GB NVMe
- 20 TB traffic
Support: Standard
- 24-hour response
- Mon to Fri, 08:00 to 17:00 CET/CEST
- Ticket system, intake by email
7-day trial. Credit card required, converts to a paid plan automatically, cancel monthly.
Keycloak runs on the JVM and needs more memory than a Python or Go stack. The smallest size is therefore not offered for Keycloak.
The instance is sized to your use case. When a size stops being enough, we move you up during operation. Outside Germany, size L has 6 instead of 8 vCPU; the other specs are identical.
Features
- SSO via OIDC, OAuth2 and SAML 2.0
- SAML 2.0 as identity provider and service provider
- Identity brokering to external providers
- LDAP and AD federation including write-back
- User storage SPI for your own user sources
- Realms with no count limit
- Fine-grained authorization services
- Client policies and step-up authentication
- MFA: TOTP, WebAuthn and passkeys
Included in every size
- Dedicated instance, no shared hosting
- Users with no count limit
- Subdomain included (*.authhost.de)
- Your own domain possible
- PostgreSQL included
- 99.9 % availability commitment
- Automatic backups and updates
- 24/7 monitoring
- Hosted in Germany
- Data processing agreement included
- No setup fee, cancel monthly
All prices are net, plus statutory VAT. This offer is directed exclusively at businesses within the meaning of § 14 German Civil Code, not at consumers.
What matters in Keycloak operations
The complexity lies mainly in caching, high availability, JVM sizing and controlled upgrades.
PostgreSQL and Infinispan
Keycloak requires PostgreSQL plus an Infinispan cache. Since version 26, persistent sessions are stored in the database.
Complex high availability
An HA setup requires suitable cluster discovery and cache topology. Both layers need to be sized together with the instance.
Upgrades with known break points
The move from version 25 to 26 included a marshalling break that caused session loss. The earlier change from WildFly to Quarkus took place with version 17 in 2022.
Compatibility policy since 2024
Since October 2024, breaking changes in minor releases are opt-in through feature and API versioning. Removals only arrive with a major release. Much of the older criticism of the upgrade cycle comes from the period before this policy.
JVM sizing
As a JVM application, Keycloak needs considerably more RAM than a Python or Go stack. The guideline is at least 1 GB plus JVM tuning.
Backups, monitoring and commitment
Automatic backups stay in the same region and 24/7 monitoring watches the instance. The availability commitment is 99.9 % on every size. Support responds within 24 hours, 4 hours or 30 minutes, depending on the tier.
What managed Keycloak costs elsewhere
Publicly stated prices, as of 2 August 2026. The row that differs most is not the price but what gets capped.
| Provider | Price per month | What is capped |
|---|---|---|
| authhost, size M | 149.90 € | Nothing. Users and realms with no count limit, dedicated instance |
| Skycloak Launch | 149 USD | Cluster size, users uncapped |
| zunicode | 189 € | 100 users and 2 realms |
| Cloud-IAM | from 225 € | Billed by total user count |
| plusserver | around 320 € | Per provider information |
| Phase Two | 149 to 2,999 USD | Concurrent sessions |
| Elestio | from 11 USD | Self-service, support billed separately |
Competitor prices per their public information, as of 2 August 2026, partly in USD without conversion. Plans change, so please verify before deciding. On a dedicated instance there is no cost basis for user or realm limits, which is why we cap neither. What determines the price is instance size, and that is in the pricing overview.
Data location and processing
The German region runs in data centers with ISO 27001 and BSI C5. The other seven regions run in data centers with ISO 27001 and SOC 2 Type II. Germany is the default region.
You can choose Germany, the Netherlands, the USA, Canada, Singapore, Japan, Australia or India. Every customer instance is dedicated and is not operated as a shared tenant.
The data processing agreement under Article 28 GDPR is included in every plan. Automatic backups remain in the same region as the Keycloak instance.
How you get to your Keycloak instance
From signup to the first connected directory it takes four steps.
- 1
Start the instance
Pick size, support tier and region, the instance is provisioned. The trial runs for 7 days and a credit card is required at signup.
- 2
Create realms
Separate tenants the way your organisation needs: per subsidiary, per customer or per environment. The number is not capped.
- 3
Connect directories
Set up LDAP or AD federation, with write-back where needed, or connect an existing provider through identity brokering.
- 4
Hand over operations
After the trial the instance converts automatically to the selected plan. Updates, backups and monitoring are ours from then on.
Read on
Managed Authentik hosting
For conventional mid-sized companies that need central sign-in and a managed dedicated instance.
Managed Zitadel hosting
For software vendors and SaaS providers using organizations, an audit log and an API-first approach.
Which identity provider fits?
Authentik, Authelia and Keycloak compared directly with a decision matrix.
Frequently asked questions about managed Keycloak hosting
What does managed Keycloak hosting cost?+
The price is set after technical sizing of the instance and agreed through direct contact. No fixed Keycloak prices are currently listed. There is no setup fee, the subscription can be cancelled monthly, and the data processing agreement is included.
Who is Keycloak suitable for?+
Keycloak fits tenders, public authorities, corporate subsidiaries and projects with SAML, eIDAS, AD federation or multi-tenant requirements. Realms, identity brokering and federation of existing directories are among its defining functions.
Why is Keycloak demanding to operate?+
The stack includes PostgreSQL and Infinispan. High availability requires planning cluster discovery and cache topology. There is also the JVM: as a guideline, Keycloak requires at least 1 GB of RAM plus JVM tuning.
How risky are Keycloak upgrades?+
Upgrades remain an important operational issue. The move from version 25 to 26 included a marshalling break with session loss. Since October 2024, a compatibility policy limits breaking changes in minor releases to opt-in changes through feature and API versioning, with removals only in major releases.
Which federation functions does Keycloak provide?+
Keycloak supports SAML 2.0 as an identity provider and service provider, identity brokering, and LDAP and AD federation including write-back. The User Storage SPI can include further user stores.
Where are data and backups stored?+
The default region is Germany, in data centers with ISO 27001 and BSI C5. Seven further regions are available. Automatic backups stay in the same region as the instance.
What availability and support response apply?+
The availability commitment is 99.9 % on every size. Support responds within 24 hours, 4 hours or 30 minutes, depending on the tier. The instance is monitored around the clock.
How does the 7-day period work?+
The trial runs for 7 days. A credit card is required at signup, and when the trial ends it converts automatically into the selected paid subscription. If you do not want to continue, cancel beforehand.
Have your Keycloak instance sized
Discuss SAML, AD, realm and availability requirements with us. The trial runs for 7 days, a credit card is required, and it then converts automatically into the selected paid subscription.