Keycloak vs Authentik

Keycloak and Authentik are both free, open-source identity providers you run yourself. Keycloak is the comprehensive enterprise platform: SAML, OIDC, directory federation and fine-grained authorisation in one large system. Authentik is lighter to deploy, with configurable login flows and a proxy that protects applications lacking their own authentication. Enterprises lean to Keycloak, self-hosters with mixed estates to Authentik.

Choose Keycloak if

you need enterprise depth: LDAP or Active Directory federation without migrating users, fine-grained authorisation, a Kubernetes operator, and the option of a commercially supported Red Hat build.

Read the Keycloak review

Choose Authentik if

you self-host a mix of modern and legacy applications, want login, enrolment and recovery as configurable flows, and prefer something lighter to deploy and configure than Keycloak.

Read the Authentik review

Keycloak and Authentik side by side

Keycloak and Authentik compared on company, jurisdiction, data residency, pricing and source code
 KeycloakAuthentik
Company Keycloak (CNCF project, Red Hat originated) Authentik Security
Headquarters London, United Kingdom Hamburg, Germany
Jurisdiction Self-hosted; project governance is international Self-hosted; German origins
Where the data sits Wherever you deploy it Wherever you deploy it
Pricing Free and open source Free and open source / Enterprise available
Free tier or trial Free Free
Certifications and checks GDPR — you remain the controller GDPR
Source code Open source (Apache 2.0) Open source
Usually replaces Auth0, Okta Okta, OneLogin
Position in our Identity Management guide #1 of 7 #4 of 7

Both are listed in our European Identity Management guide. The table is built from the same directory data as those entries; how we check it is described in the editorial process.

Where Keycloak and Authentik differ

Across the four points below, Keycloak has the edge on 2 points and Authentik on 2 points. A count like that is a summary, not a verdict: the point that matters to you may be the one the other product wins.

Depth of authorisation

Keycloak includes fine-grained authorisation services that decide what a user may do, not only whether they may log in, together with adaptive multi-factor policies. Authentik's review states plainly that it offers less depth in fine-grained authorisation than Keycloak. For an organisation whose access rules are complicated, that gap is the main reason to accept Keycloak's extra weight.

Edge: Keycloak

Effort to deploy and configure

Authentik is described as lighter to deploy and configure. Keycloak's configuration surface is large enough to be genuinely complex, and upgrades between major versions need planning, even though its Quarkus base starts fast and uses little memory. In both cases you run, patch and back up the system yourself; the day-one effort is lower with Authentik.

Edge: Authentik

Applications without their own login

Authentik's application proxy puts authentication in front of software that has none, which is the practical situation in an estate mixing OIDC-ready services and older tools. Keycloak's documented strength is federation through OAuth 2.0, OpenID Connect and SAML 2.0 plus identity brokering, for applications that speak those protocols. For the legacy end of an estate, Authentik has the clearer answer.

Edge: Authentik

Backing and support

Both are free under open-source licences, Keycloak under Apache 2.0, and both mean owning operations. Commercial backing differs in form: Red Hat sells a supported build of Keycloak, while Authentik Security offers an enterprise licence with support. Authentik's ecosystem and community are described as smaller. Organisations wanting a large vendor to call will lean towards Keycloak.

Edge: Keycloak

When neither Keycloak nor Authentik fits

Both leave you running the identity system. A small team that wants managed European identity at a predictable price can look at Signward, flat at €3 to €5 per user a month, and developers who want to remove passwords altogether can look at passkey-first Hanko.

Keycloak vs Authentik: questions

It is lighter to deploy and configure, according to our review, while Keycloak has a large and complex configuration surface and major upgrades that need planning. The running costs are the same in kind: with either you patch, back up and scale the service yourself, and the licence costs nothing at any number of users.

Keycloak federates users from LDAP and Active Directory, so the existing directory stays the source of truth and nobody is migrated. Authentik supports LDAP as well, alongside SAML, OAuth2, OpenID Connect and SCIM. Our data does not describe Active Directory federation for Authentik specifically, so check that point against its documentation.

Wherever you deploy them. Both are self-hosted, so residency is your own infrastructure decision and you remain the data controller. Keycloak is a CNCF project that originated at Red Hat, with international governance; Authentik originates from Hamburg and is developed by Authentik Security. Neither holds your users' data for you.