Add on
Keycloak as a Service
This ready-to-use solution is configured to enhance the security of your applications from the start. Keycloak as a Service comes pre-configured with the most useful settings and plugins, so you can get up and running quickly. You’re free to fine-tune it, add your own themes, plugins, and more.
Managed Keycloak, key highlights
- Secure authentication and access management
- Deploy in seconds
- Fully customizable
- Compatible with most IAM standards
- Dedicated, auto-scaling infrastructure tailored to your needs
- Simplified Application Integration via Proxy Authentication
- Easy import and export of realms
- High availability in clustered mode (Secured Multi-Instances) for a critical component
- IP address filtering by realm and for administrative access
- Built-in monitoring included, managed from a dedicated dashboard in the Console
- Continuous updates to recent Keycloak versions, with no client-side upgrades required
- All features included by default, with no paid add-ons, from a single node to a cluster

IAM: standards and identity federation
Keycloak as a Service supports most IAM standards and gives you fine-grained control over users and permissions. It integrates seamlessly with user federation tools such as ActiveDirectory, OpenLDAP, and others via the LDAP protocol. It can also delegate authentication to external identity providers using OpenID Connect or SAML V2.
This add-on integrates naturally with your Clever Cloud applications and databases, but you can just as easily use it independently with external services.
Enhanced authentication and registration control
Your managed Keycloak goes beyond standard authentication: it supports multi-factor authentication (TOTP, FIDO, WebAuthn), passkeys and one-time passwords (OTPs) via email. During registration, you can filter authorised accounts by email domain using an allowlist or blocklist.
Your Keycloak as a Service usage:
- User management within your information system (Active Directory, LDAP, Kerberos, etc.);
- Applications: multi-tenancy, multi-factor authentication (TOTP, FIDO, WebAuthn), integration with existing applications, SSO, and more;
- Manage authentication flows between your different services;
- Password reset and account recovery.
Managed IAM: your plug-and-play identity solution
Dedicated infrastructure
No resource sharing: your Keycloak as a Service has its own dedicated Java application, database and file system. Depending on your availability requirements, it can be deployed on a single node or in a multi-node cluster. Each component can be resized on the fly, without any loss of connection.
Run-time support and maintenance
Clever Cloud handles updates to recent Keycloak versions, security, operational maintenance and regular backups of your data. Monitoring is built in and included, with no external tools to deploy, and a dedicated dashboard centralises service management from the Console. Cache sizing adjusts automatically based on machine size and the number of users.
Network security: IP address filtering
Restrict access to your realms at the network level: filter authorised IP addresses on administration, public and provisioning endpoints, on a realm-by-realm basis, with global filtering for administration access. Additional filtering can also be applied directly within the authentication flow at login.
Scalability, performance and high availability
Keycloak as a Service is built to scale effortlessly: handle thousands of simultaneous connections with an infrastructure that grows with you.
You retain control over the sizing of each component: although the baseline resources can already handle heavy workloads, they can be resized at any time, on the fly, with no dropped connections when scaling up. For a component as critical as IAM, the service can be deployed in clustered mode across multiple nodes (Secured Multi-Instances): this architecture ensures load distribution and service continuity as demand increases. It can be configured and managed directly from the Clever Cloud Console.
Easy management and full customization
You have full control over your service, with streamlined management of realms and easy import/export capabilities.
- Plugins adapt to all your needs: use existing community plugins or develop your own custom ones—for a truly customizable and modular IAM solution.
- Simplified realm import and export and integration via proxy authentification
- Custom login page theming
Automation and provisioning
Provision and manage your Keycloak clusters as code: the service integrates with Terraform for reproducible, version-controlled deployment alongside the rest of your Clever Cloud infrastructure.
Managed Keycloak: what’s included
All features are included by default, with no options to enable or additional charges: a single-node deployment offers exactly the same feature set as the largest cluster, including monitoring, metrics, plugins and security.
Keycloak as a Service uses three independently managed Clever Cloud resources, allowing you to precisely tailor the setup to your needs:
- A PostgreSQL database;
- A Java image;
- A File System FSBucket.
Keycloak as a Service experts: Please Open-It

Keycloak as a Service was designed with the help of Please Open-It, experts in SSO, identity management, and authentication.
Leverage their expertise for integration or customization of your service. And if you want to go even further, Please Open-It can help you build a fully tailored IAM solution.
VIDEO
Managed Keycloak demonstration
Pricing
Starts at 47€/month
Legal informations
Keycloak as a Service is an add-on developed in collaboration with Please Open IT, and hosted and operated by Clever Cloud. You can find our General Terms of Service here.
Are you evaluating an identity management solution?
Download our checklist: 11 questions to ask any provider before making your decision.
Last update: August 2026
FAQ
What is Keycloak as a Service?
Keycloak as a Service is a managed identity and access management (IAM) solution that centralises authentication and authorisation for your applications. Clever Cloud hosts, maintains and updates the service, allowing you to focus on using it rather than operating it.
What is the difference between self-hosted and managed Keycloak?
With self-hosted Keycloak, you manage the installation, updates, security, backups and availability yourself. With the managed version, Clever Cloud handles operational maintenance, monitoring and continuous updates on dedicated infrastructure.
Which authentication standards are supported?
The service supports OAuth 2.0, OpenID Connect and SAML v2, as well as directory federation via LDAP (Active Directory and OpenLDAP). It can also delegate authentication to external identity providers.
Is the service suitable for use in regulated sectors?
It provides controls for organisations subject to stringent requirements, such as IP address filtering by realm and for administration access. The Digital Operational Resilience Act (DORA) for the financial sector and the NIS2 Directive are among the relevant regulatory frameworks.
Is the service highly available?
Yes. For a component as critical as IAM, it can be deployed in clustered mode across multiple nodes (Secured Multi-Instances), ensuring load distribution and service continuity during periods of high demand.
Can I import an existing Keycloak configuration?
Yes. Realm import and export are supported, making it easier to take over an existing instance or migrate it.
Are any features available as paid options?
No. All features are included by default, with no optional extras or additional charges. A single-node deployment offers exactly the same feature set as the largest cluster.
Who handles updates and maintenance?
Clever Cloud handles updates to recent Keycloak versions, security, operational maintenance and regular backups. Monitoring is built in and included, with no external tools to deploy.
Who is Please Open-It?
Please Open-It is the specialist partner in SSO (single sign-on), identity management and authentication with which the service was designed. Its expertise is available for integration or customisation.
NEWS