authentik vs Keycloak
authentik and Keycloak are both self-hosted, open-source identity providers for single sign-on. Keycloak is a Cloud Native Computing Foundation incubating project with a commercially supported Red Hat build, and centres on OpenID Connect, OAuth 2.0 and SAML with identity brokering and LDAP or Active Directory federation. authentik, founded in 2020, covers the same core protocols and adds LDAP, RADIUS and Kerberos providers and an authentication proxy in its free edition, with a paid Enterprise tier.
Updated Sep 2026Summary
Choose authentik if you want one self-hosted system to cover modern SSO as well as LDAP, RADIUS and proxy-based access for older apps, with a low published price for support. Choose Keycloak if you want the longer-established project for OIDC and SAML, with realms, identity brokering and the option of Red Hat support.
Choose authentik if:
- You want LDAP, RADIUS and Kerberos providers in the free edition, for older apps and network devices
- You want an authentication proxy in front of apps that have no SSO of their own
- You want web-based RDP and SSH access
- You want a modern admin interface and flow-based login policies
- You want paid support at a published price: Enterprise is $5 per user a month
Choose Keycloak if:
- You want a longer-established project with a large community and extension ecosystem
- You need identity brokering with social logins and external OIDC or SAML providers
- You run several tenants and want realms to separate them
- You want a commercially supported build from Red Hat
- You deploy on Kubernetes and want an operator for declarative setup
Feature Comparison
| Feature | authentik | Keycloak |
|---|---|---|
| Project | Open source, with a paid Enterprise edition | CNCF incubating project; Red Hat Build of Keycloak by subscription |
| Protocols | OIDC, SAML, SCIM, LDAP, RADIUS, Kerberos, proxy | OpenID Connect, OAuth 2.0, SAML 2.0 |
| Directories | Acts as an LDAP provider | Federates with LDAP and Active Directory |
| Legacy and remote access | Authentication proxy and web-based RDP/SSH | Custom authenticators for adaptive authentication |
| MFA | MFA including WebAuthn passkeys | TOTP and WebAuthn |
| Login customisation | Policy engine with customisable login flows | Customisable login and account themes |
| Paid option | Enterprise $5/user/month, $0.02 per external user/month | Red Hat Build of Keycloak subscription |
| Certification | OpenID Certified for OpenID Connect | CNCF incubating project |