Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

authentik vs Keycloak

authentik and Keycloak are both self-hosted, open-source identity providers for single sign-on. Keycloak is a Cloud Native Computing Foundation incubating project with a commercially supported Red Hat build, and centres on OpenID Connect, OAuth 2.0 and SAML with identity brokering and LDAP or Active Directory federation. authentik, founded in 2020, covers the same core protocols and adds LDAP, RADIUS and Kerberos providers and an authentication proxy in its free edition, with a paid Enterprise tier.

Updated Sep 2026

Summary

Choose authentik if you want one self-hosted system to cover modern SSO as well as LDAP, RADIUS and proxy-based access for older apps, with a low published price for support. Choose Keycloak if you want the longer-established project for OIDC and SAML, with realms, identity brokering and the option of Red Hat support.

Choose authentik if:

  • You want LDAP, RADIUS and Kerberos providers in the free edition, for older apps and network devices
  • You want an authentication proxy in front of apps that have no SSO of their own
  • You want web-based RDP and SSH access
  • You want a modern admin interface and flow-based login policies
  • You want paid support at a published price: Enterprise is $5 per user a month

Choose Keycloak if:

  • You want a longer-established project with a large community and extension ecosystem
  • You need identity brokering with social logins and external OIDC or SAML providers
  • You run several tenants and want realms to separate them
  • You want a commercially supported build from Red Hat
  • You deploy on Kubernetes and want an operator for declarative setup

Feature Comparison

FeatureauthentikKeycloak
ProjectOpen source, with a paid Enterprise editionCNCF incubating project; Red Hat Build of Keycloak by subscription
ProtocolsOIDC, SAML, SCIM, LDAP, RADIUS, Kerberos, proxyOpenID Connect, OAuth 2.0, SAML 2.0
DirectoriesActs as an LDAP providerFederates with LDAP and Active Directory
Legacy and remote accessAuthentication proxy and web-based RDP/SSHCustom authenticators for adaptive authentication
MFAMFA including WebAuthn passkeysTOTP and WebAuthn
Login customisationPolicy engine with customisable login flowsCustomisable login and account themes
Paid optionEnterprise $5/user/month, $0.02 per external user/monthRed Hat Build of Keycloak subscription
CertificationOpenID Certified for OpenID ConnectCNCF incubating project