Enterprise-Grade Identity Management

 cidaas – the sovereign European
Keycloak alternative

Keycloak is an SSO toolkit you build on and run yourself. cidaas brings Identity & Access Management, digital sovereignty and enterprise support together in one cloud-native platform – without the operational burden of running it yourself.

GDPR DSGVO
EU-hosted Sovereign by Design
Vollumfängliche Plattform Feature-complete platform
ISO 27001 ISO 27001 Certified
Fully managed SaaS Fully managed SaaS

Companies that already trust cidaas

cidaas is Europe´s leading Identity & Access Management solution and it offers a secure alternative to Keycloak.

Kaufland – cidaas customer
Hornbach – cidaas customer
Takko Fashion – cidaas customer
Europa Park – cidaas customer
ProSiebenSat.1 – cidaas customer
REHAU – cidaas customer
RATIONAL AG – cidaas customer
1. FSV Mainz 05 – cidaas customer
EWE AG – cidaas customer
SachsenEnergie – cidaas customer
Creditplus Bank – cidaas customer
die Bayerische – cidaas customer

Why a Keycloak alternative: scalability instead of administrative effort

Operations and maintenance effort

Complex configurations and upgrades

Community-based Support, with commercial support only through third parties

Full responsibility for infrastructure, updates and availability

How cidaas solves these challenges

1

Fast deployment

Start right away: no environment to build, no clusters to configure. cidaas is ready to use as a managed service – go live in days, not months.

2

24/7 managed operations

Hosting, scaling, patching and upgrades – run around the clock as a managed SaaS. No on-call duty for your identity infrastructure.

3

Integrated support

SLA-backed support in German and English during European business hours, with direct access to the European product team.

4

Comprehensive features

Identity verification, adaptive MFA, no-code orchestration, consent management and more – built into the platform instead of assembled from extensions.

5

GDPR compliance & full control

EU hosting with dedicated German server locations, built-in consent management and a European vendor accountable for the platform.

6

Predictable costs

Transparent pricing per registered user – instead of free software with unpredictable operating costs for infrastructure, engineering and maintenance.

Leading analysts recognize cidaas

The KuppingerCole analysts recommend cidaas in the current Leadership Compass reports:

cidaas is recognized as an Overall, Product and Innovation Leader in the latest KuppingerCole Leadership Compass reports for CIAM, B2B IAM and IGA.

This recognition across categories reflects what sets cidaas apart: one holistic European identity platform instead of stitched-together point solutions. Certifications such as ISO 27001 and awards from Frost & Sullivan and the European Identity & Cloud Awards complete the picture.

Leadership Compass B2B IAM 2026: cidaas is overall leader
Leadership Compass IGA 2026: cidaas is overall leader
Leadership Compass CIAM 2026: cidaas is overall leader

Feature-complete – this is what cidaas delivers.

cidaas covers everything you run Keycloak for today – and everything you would otherwise have to build around it. One platform for modern IAM and CIAM, with digital sovereignty, GDPR compliance, high security standards and user experience at its core.

Single Sign-On (SSO)

One login, secure access to all applications and services. Centralized Identity Management that improves user experience and strengthens security.

Passwordless authentication & passkeys

ace ID, Touch ID, passkeys, OTP or authenticator app – modern login methods that improve security and user experience at the same time.

Multi-factor & adaptive authentication

Flexible MFA with 16+ methods, made smart through adaptive, risk-based authentication that responds to device, location and behaviour.

Consent Management

Users view and manage their consents transparently and in line with GDPR. Changes to privacy policies or terms are easily communicated and documented.

AI-based fraud detection

Machine learning identifies suspicious activity and anomalies early – protecting users, applications and digital identities from fraud and abuse.

Integrated identity verification (IDV)

The cidaas ID validator enables AI-based digital identity verification directly within the platform – no external provider required.

Identity orchestration & lifecycle

Orchestrate identities across their entire lifecycle with cnips – from registration and onboarding to role changes and offboarding. Integrate your applications easily, all without custom development.

Group & multi-tenant management

Manage users, groups and permissions, with typed groups, hierarchies and delegated administration for B2B and B2C.

Social Login, Progressive Profiling & Real-World Identification

From social login and progressive profiling to linking digital and physical identities – innovative capabilities beyond classic login.

And it doesn’t stop there:

Securing AI Agents, automated provisioning, and the scalability to serve mid-sized companies as well as global enterprises with millions of users.

More reasons to switch:
Keycloak´s dependencies

Open source is often chosen for reasons of independence – but that independence deserves a closer look.

Keycloak development is concentrated within the Red Hat and IBM ecosystems. Analyses based on Linux Foundation Insights show that the overwhelming majority of contributions come from these two organizations, and the Linux Foundation itself states that the project is primarily dependent on them.

As a result, the direction and pace of the Keycloak roadmap are determined outside your organization – and outside Europe.

cidaas

There is also a technical dependency. Keycloak covers the SSO core, while many capabilities organizations require beyond that are added through custom SPIs, extensions, and themes. Each of these becomes code that your team is responsible for maintaining, testing, and revalidating with every upgrade, gradually tying your architecture more closely to Keycloak.

The result is a different type of lock-in – not through licensing, but through operations and custom code.

cidaas follows a different approach: a European vendor with a transparent, independent roadmap, capabilities that are built into the platform instead of being custom-developed around it, and open standards (OIDC, OAuth 2.0, SAML) that ensure application portability without protocol lock-in.

Comparison

cidaas vs. Keycloak

Feature
cidaas logo
keycloak logo
Sovereign EU hosting & data residency (EU + dedicated German/KRITIS locations) i cidaas runs on sovereign European cloud infrastructure with dedicated German server locations for sectors with heightened requirements (KRITIS, finance, public sector), with EU data residency guaranteed. Keycloak can be hosted in the EU, but whether a given deployment is EU-resident and sovereign depends entirely on how and where the operator runs it.
Security & compliance certifications (e.g. ISO 27001) i cidaas operates on certified, audited infrastructure (e.g. ISO 27001). Keycloak is software, not a service – any certification applies to the environment the operator builds and maintains around it, not to Keycloak itself.
GDPR Compliance, Guaranteed & Built-in i With cidaas, GDPR-relevant safeguards are built in and delivered on compliant infrastructure. With self-hosted Keycloak, GDPR compliance depends on the operator’s configuration, hosting choices and processes.
Built-in GDPR Consent Management i cidaas provides built-in, GDPR-compliant consent management where end users can transparently view and manage their consents and preferences. Keycloak has no native consent management; a compliant consent layer must be added through community extensions or custom development.
Sovereign European Vendor i cidaas is developed and controlled by a European company with a transparent roadmap and a clear line of accountability. Keycloak’s development is concentrated in the Red Hat and IBM ecosystems – Linux Foundation Insights notes the project relies mainly on these two organizations. This concerns who strategically controls and evolves the product.
Passkeys i Both platforms support passkeys natively.
Passwordless Authentication i cidaas provides a broad range of passwordless methods across the full login journey. Keycloak’s native passwordless support is essentially WebAuthn/passkey-based.
Adaptive / Risk-based MFA i cidaas includes risk-based adaptive MFA that factors in context such as device, location and behaviour. Keycloak supports MFA (OTP, WebAuthn), but risk-based, adaptive logic requires custom authentication flows or third-party extensions.
Biometric Authentication (WebAuthn/FIDO2) i Both platforms support biometric authentication via WebAuthn/FIDO2 (e.g. Touch ID, Face ID). cidaas additionally offers native device-biometrics integration for mobile apps.
Breadth of Authentication Methods (16+, incl. Smart Push & QR-Code Login) i cidaas supports 16+ authentication methods, including OTP, TOTP, push, biometrics, FIDO2, Smart Push and QR-code login. Keycloak supports a smaller set of native methods; additional methods typically require extensions or custom flows.
Real-World Identification (QR/NFC, Digital ↔ Physical Identity) i cidaas links digital and physical identity via QR/NFC – for example to grant access to rooms, buildings, parking facilities or events. Keycloak has no native concept for connecting digital and physical identity.
AI/ML-based Fraud & Anomaly Detection i cidaas applies machine learning to detect suspicious activity, fraud and anomalies – continuously improved as part of the managed platform. Keycloak offers basic protections such as brute-force detection, but no ML-based fraud or anomaly detection.
Community i Keycloak benefits from a large, mature open-source community. cidaas has a growing community, backed by a curated partner ecosystem and direct vendor support.
Open Standards (OIDC, OAuth2, SAML) i Both platforms fully support open identity standards including OIDC, OAuth2 and SAML, so applications and identities can be integrated without proprietary protocol lock-in.
Brand Awareness i Keycloak is widely known among developers worldwide, in large part thanks to its open-source nature. cidaas is an established and growing brand, with particular strength in the European market.
Group & Multi-Tenant Management i cidaas goes beyond tenant isolation: users belong to groups, and each group can be assigned a type that defines role restrictions. With delegated user administration, hierarchies and custom group-level fields, cidaas models any kind of group – B2B company structures as well as B2C scenarios like Family & Friends – without custom code. Keycloak offers multi-tenancy via separate realms or its Organizations feature, but complex group structures and per-organization roles require custom configuration and development.
Fine-Grained Authorization (RBAC/ABAC/ReBAC/PBAC, AuthZEN) i cidaas provides RBAC, ABAC, ReBAC and PBAC with AuthZEN support. Keycloak offers RBAC and UMA-based authorization; ABAC is implemented through JavaScript policies, and ReBAC is not natively supported.
Identity Orchestration (AI-Powered, No-Code Visual Flows) i cidaas includes identity orchestration through an AI-assisted, no-code visual flow designer (cnips), making it easy to build and adapt user journeys – the AI-powered approach is a particular differentiator. Keycloak does not offer a comparable identity-orchestration capability.
IGA-Light for B2B & B2C i cidaas offers IGA-Light – access recertification or approval workflows (AuthManager) – as an add-on, usable in both workforce and CIAM scenarios (for example, a business customer’s admin periodically reviewing and recertifying their users’ access). Keycloak offers only limited governance capabilities, which typically require custom development.
Integrated Identity Verification (IDV) i The cidaas ID validator enables AI-based digital identity verification directly within the platform. Keycloak does not offer integrated IDV – external providers must be connected separately.
AI Agent Identity / Agentic Readiness i With cidaas, identity for AI agents is part of the platform, and agents can be embedded directly into orchestration flows – increasingly critical as organizations adopt agentic AI. Keycloak provides generic machine-to-machine service accounts but no dedicated AI-agent identity capability.
Financial-Grade Security (FAPI 2.0) i Both cidaas and Keycloak support FAPI 2.0 (incl. PAR, DPoP, JARM, mTLS) for highly regulated use cases such as open banking and PSD2.
Predictable Total Cost of Ownership i cidaas offers transparent pricing per registered user. Keycloak has no licence cost, but the total cost of ownership includes infrastructure, high-availability operations, security patching and engineering effort – which is why ‘free to download’ rarely means ‘free to operate’.
Fully Managed SaaS i cidaas is delivered as a fully managed SaaS – hosting, scaling, patching and upgrades are handled for you. Keycloak is self-hosted software: the customer operates it, or pays a third party to do so, while the underlying platform and its feature limits remain Keycloak’s.
Contractual Uptime SLA i cidaas provides a contractual uptime SLA as part of the managed service. Keycloak is software and offers no uptime guarantee of its own – availability depends entirely on the environment the operator builds and runs.
Support (DE/EN, EU Business Hours) i cidaas provides support in German and English during European business hours, with access to the European product team. The Keycloak project itself offers community support only; commercial support is available solely through third parties such as Red Hat or hosting providers.
Fast Time-to-Value i cidaas is available immediately, with no environment to build. Standing up a production-ready Keycloak environment – clustering, database, high availability, theming – typically takes an experienced engineer several days.
Single Accountable Vendor i With cidaas, one European vendor is accountable for the platform, its operation and its support. With Keycloak, responsibility is split across the open-source project, your own operations team and any third-party hosting or support providers.
Full Support
Partial / Limited
Not Available

Why a Keycloak alternative: scalability instead of administrative effort

More than managed Hosting

eycloak-as-a-Service providers take over hosting and operations and that solves one part of the equation. But the platform itself remains Keycloak: capabilities like integrated identity verification, adaptive MFA, consent management or no-code orchestration don’t appear because someone else runs the servers – and the roadmap remains outside their influence. Managed hosting changes who operates Keycloak – not what Keycloak is.

Migration path from Keycloak to cidaas

01

Set up

Your cidaas environment is available immediately – no infrastructure to build. Configure authentication methods, flows and branding to your needs.

02

Migration

User data is transferred with out-of-the-box migration tooling – including password hashes, so your users keep their passwords, with no forced reset.

03

Integration

Because both cidaas and Keycloak build on open standards, applications are switched over with minimal changes – client by client, at your pace.

Good to know

During the migration, both systems run in parallel – end users are not affected at any point, and the switch happens without downtime.

The Keycloak alternative with digital sovereignty built in

When choosing an IAM solution, digital Sovereignty, data protection and long-term control over identities and data re decisive. cidaas delivers all of this by design – built into service, not something you have to build and maintain yourself.

  • Developed and operated in Europe: by a European vendor with an independent roadmap and clear accountability.
  • EU hosting with dedicated German server locations: data residency guaranteed, including options for sectors with heightened requirements such as KRITIS, finance and the public sector.
  • Open standards for long-term flexibility: OIDC, OAuth2 and SAML keep your environment interoperable and your investment secure, with no protocol lock-in.
Keycloak
cidaas

The regulatory bar keeps rising

NIS2 and DORA increasingly demand demonstrable accountability for identity and access infrastructure – who operates it, who patches it, who answers for it. With cidaas, that accountability is contractually anchored with one European vendor. With self-operated open source, it remains entirely with your organization.

European identities deserve European solutions

Protect your users, data and applications with cidaas – the leading European identity platform under European control.

FAQs: cidaas as a Keycloak alternative

Keycloak is a well-known open-source solution for single sign-on. It covers the SSO core, but everything around it is the operator’s responsibility: infrastructure, upgrades, security patching, availability and support. Many teams evaluating Keycloak alternatives are looking for exactly what a managed platform like cidaas provides: a broader, CIAM-ready feature set, predictable operations and a single accountable vendor. Also read: Keycloak-as-a-Service – Open Source Vendor-LockIn?
As a fully managed Software-as-a-Service solution, cidaas provides customers with a comprehensive, worry-free package. Organizations benefit from enterprise-grade support without having to manage operations themselves. The platform includes a comprehensive feature set and is both developed and hosted in Europe.

– A wide range of authentication options for passwordless authentication and multi-factor authentication
– Group management to support B2B as well as Family & Friends scenarios
– A mature consent management solution for capturing user consent, along with many other innovative features
– Data sovereignty under European legislation with exclusive hosting in Europe
The software licence is free – running it is not. A production-grade Keycloak deployment requires infrastructure, high availability, security patching, upgrades and ongoing engineering capacity, which together form the real total cost of ownership. cidaas takes a different approach: transparent pricing per registered user, with operations included.
No. Keycloak-as-a-Service providers take over hosting and operations, but the platform itself remains Keycloak: capabilities such as integrated identity verification, adaptive MFA, consent management or no-code orchestration are not part of it, and the roadmap remains outside their influence. Managed hosting changes who operates Keycloak – not what Keycloak is.
Yes. cidaas provides out-of-the-box migration tooling that transfers user data including password hashes, so your users keep their passwords. During the migration both systems run in parallel without downtime and without impact on end users.
cidaas is developed and operated by a German company, hosts on sovereign European cloud infrastructure with dedicated German server locations, and includes built-in consent management. Privacy and GDPR requirements are part of the platform’s design, it is not something you have to configure and certify around it, as with a self-operated deployment.
Scroll to Top