Login Autonomy with Keycloak

Authentication is, by its very nature, a sensitive topic, and every company must address it as part of its digital transformation and software development efforts. There are a multitude of well-known providers of Identity and Access Management (IAM) solutions on the market. All major software providers—such as Azure (Entra ID), Amazon (AWS Cognito), Google (Google Identity Platform), IBM (IBM Security Verify), and Oracle (Oracle Identity Management)—offer their own IDaaS or IAM solutions. But what does this mean for my company’s digital sovereignty?

Ihre Probleme möchte er haben

Fabian Stein
Fabian beschäftigt sich mit der Digitalisierung in Deutschland und der Entwicklung des Open Source Marktes als CEO von punkt.de.
Reading duration: approx. 2 Minutes

U.S. Providers Dominate the IDaaS and IAM Markets—Keycloak as a Viable Alternative

It’s easy to see that most providers are based in the U.S. and, in many cases, rely on their own cloud infrastructure. For any company that values its independence and is reluctant to trust American companies—especially when it comes to sensitive data such as login or password information—we can offer Keycloak as a genuine alternative.

Keycloak is open source and extremely flexible in terms of its features and integration capabilities. As the “Swiss Army knife” of IAM, Keycloak uses standard protocols (OpenID Connect, OAuth 2.0, SAML 2.0) and supports federation with common directory services such as LDAP or Active Directory (AD). Social login options are also available.

Our CTO, Daniel Lienert, has already written a detailed article on Keycloak and its benefits:

Embody True Independence as a Company—Prevent Vendor Lock-In!


Not only is the management of sensitive data often not in good hands at U.S. companies, but the classic vendor lock-in problem is also increasingly being recognized as such by businesses. This should always be taken into account when deciding for or against a proprietary solution from a major provider. Once the relevant IAM solution has been deeply integrated, it’s often too late, and you’re at the mercy of the providers and their pricing policies.

Keycloak takes a different approach here: Development of Keycloak is now handled by the Cloud Native Computing Foundation (CNCF), which is part of the Linux Foundation. The CNCF is also known for projects such as Kubernetes. This ensures that the project remains open source and can be operated in a platform-agnostic manner. (See also the CNCF Charter: https://github.com/cncf/foundation/blob/main/charter.md.) As a company, you decide where Keycloak is operated, where your data is stored, and who manages the application.

Here at punkt.de, we’ve built our own team of specialists who have already developed numerous IAM solutions and would be happy to manage them for you. It doesn’t matter to us whether this is on our infrastructure or your own. We’d be happy to advise you.

Our Conclusion on IAM Solutions

If your company is looking for a way to maintain control over your data and software solution providers, then you’ve come to the right place. With Keycloak, we offer an IAM solution that leaves nothing to be desired and puts you in control. Even the code we develop ultimately belongs to you.

Share:

More articles

Die Tat unterscheidet das Ziel vom Traum.
Irene Froese de Knorpp, Projektassistenz at punkt.de
Working at punkt.de