Keycloak vs Authentik
Keycloak and Authentik are both free, open-source identity providers you run yourself. Keycloak is the comprehensive enterprise platform: SAML, OIDC, directory federation and fine-grained authorisation in one large system. Authentik is lighter to deploy, with configurable login flows and a proxy that protects applications lacking their own authentication. Enterprises lean to Keycloak, self-hosters with mixed estates to Authentik.
Choose Keycloak if
you need enterprise depth: LDAP or Active Directory federation without migrating users, fine-grained authorisation, a Kubernetes operator, and the option of a commercially supported Red Hat build.
Read the Keycloak reviewChoose Authentik if
you self-host a mix of modern and legacy applications, want login, enrolment and recovery as configurable flows, and prefer something lighter to deploy and configure than Keycloak.
Read the Authentik reviewKeycloak and Authentik side by side
| Keycloak | Authentik | |
|---|---|---|
| Company | Keycloak (CNCF project, Red Hat originated) | Authentik Security |
| Headquarters | London, United Kingdom | Hamburg, Germany |
| Jurisdiction | Self-hosted; project governance is international | Self-hosted; German origins |
| Where the data sits | Wherever you deploy it | Wherever you deploy it |
| Pricing | Free and open source | Free and open source / Enterprise available |
| Free tier or trial | Free | Free |
| Certifications and checks | GDPR — you remain the controller | GDPR |
| Source code | Open source (Apache 2.0) | Open source |
| Usually replaces | Auth0, Okta | Okta, OneLogin |
| Position in our Identity Management guide | #1 of 7 | #4 of 7 |
Both are listed in our European Identity Management guide. The table is built from the same directory data as those entries; how we check it is described in the editorial process.
Where Keycloak and Authentik differ
Across the four points below, Keycloak has the edge on 2 points and Authentik on 2 points. A count like that is a summary, not a verdict: the point that matters to you may be the one the other product wins.
Depth of authorisation
Keycloak includes fine-grained authorisation services that decide what a user may do, not only whether they may log in, together with adaptive multi-factor policies. Authentik's review states plainly that it offers less depth in fine-grained authorisation than Keycloak. For an organisation whose access rules are complicated, that gap is the main reason to accept Keycloak's extra weight.
Edge: Keycloak
Effort to deploy and configure
Authentik is described as lighter to deploy and configure. Keycloak's configuration surface is large enough to be genuinely complex, and upgrades between major versions need planning, even though its Quarkus base starts fast and uses little memory. In both cases you run, patch and back up the system yourself; the day-one effort is lower with Authentik.
Edge: Authentik
Applications without their own login
Authentik's application proxy puts authentication in front of software that has none, which is the practical situation in an estate mixing OIDC-ready services and older tools. Keycloak's documented strength is federation through OAuth 2.0, OpenID Connect and SAML 2.0 plus identity brokering, for applications that speak those protocols. For the legacy end of an estate, Authentik has the clearer answer.
Edge: Authentik
Backing and support
Both are free under open-source licences, Keycloak under Apache 2.0, and both mean owning operations. Commercial backing differs in form: Red Hat sells a supported build of Keycloak, while Authentik Security offers an enterprise licence with support. Authentik's ecosystem and community are described as smaller. Organisations wanting a large vendor to call will lean towards Keycloak.
Edge: Keycloak
When neither Keycloak nor Authentik fits
Both leave you running the identity system. A small team that wants managed European identity at a predictable price can look at Signward, flat at €3 to €5 per user a month, and developers who want to remove passwords altogether can look at passkey-first Hanko.
Keycloak vs Authentik: questions
It is lighter to deploy and configure, according to our review, while Keycloak has a large and complex configuration surface and major upgrades that need planning. The running costs are the same in kind: with either you patch, back up and scale the service yourself, and the licence costs nothing at any number of users.
Keycloak federates users from LDAP and Active Directory, so the existing directory stays the source of truth and nobody is migrated. Authentik supports LDAP as well, alongside SAML, OAuth2, OpenID Connect and SCIM. Our data does not describe Active Directory federation for Authentik specifically, so check that point against its documentation.
Wherever you deploy them. Both are self-hosted, so residency is your own infrastructure decision and you remain the data controller. Keycloak is a CNCF project that originated at Red Hat, with international governance; Authentik originates from Hamburg and is developed by Authentik Security. Neither holds your users' data for you.