Add on

Keycloak as a Service

Managed Keycloak: security, scalability, and simplicity for your IAM, just a click away.

Keycloak as a Service

Keycloak as a Service is a fully managed Identity and Access Management (IAM) solution, enabling secure and centralized authentication for your applications without the burden of maintenance. Hosted on a dedicated, scalable infrastructure with no shared resources, it supports major IAM standards (OAuth 2.0, OpenID Connect, SAML V2) and offers advanced customization options.

This ready-to-use solution is configured to enhance the security of your applications from the start. Keycloak as a Service comes pre-configured with the most useful settings and plugins, so you can get up and running quickly. You’re free to fine-tune it, add your own themes, plugins, and more.

Managed Keycloak, key highlights

  • Secure authentication and access management
  • Deploy in seconds
  • Fully customizable
  • Compatible with most IAM standards
  • Dedicated, auto-scaling infrastructure tailored to your needs
  • Simplified Application Integration via Proxy Authentication
  • Easy import and export of realms
  • High availability in clustered mode (Secured Multi-Instances) for a critical component
  • IP address filtering by realm and for administrative access
  • Built-in monitoring included, managed from a dedicated dashboard in the Console
  • Continuous updates to recent Keycloak versions, with no client-side upgrades required
  • All features included by default, with no paid add-ons, from a single node to a cluster
people 2

IAM: standards and identity federation

Keycloak as a Service supports most IAM standards and gives you fine-grained control over users and permissions. It integrates seamlessly with user federation tools such as ActiveDirectory, OpenLDAP, and others via the LDAP protocol. It can also delegate authentication to external identity providers using OpenID Connect or SAML V2.

This add-on integrates naturally with your Clever Cloud applications and databases, but you can just as easily use it independently with external services.

Enhanced authentication and registration control

Your managed Keycloak goes beyond standard authentication: it supports multi-factor authentication (TOTP, FIDO, WebAuthn), passkeys and one-time passwords (OTPs) via email. During registration, you can filter authorised accounts by email domain using an allowlist or blocklist.

Your Keycloak as a Service usage: 

  • User management within your information system (Active Directory, LDAP, Kerberos, etc.);
  • Applications: multi-tenancy, multi-factor authentication (TOTP, FIDO, WebAuthn), integration with existing applications, SSO, and more;
  • Manage authentication flows between your different services;
  • Password reset and account recovery.

Managed IAM: your plug-and-play identity solution

Dedicated infrastructure

No resource sharing: your Keycloak as a Service has its own dedicated Java application, database and file system. Depending on your availability requirements, it can be deployed on a single node or in a multi-node cluster. Each component can be resized on the fly, without any loss of connection.

Run-time support and maintenance 

Clever Cloud handles updates to recent Keycloak versions, security, operational maintenance and regular backups of your data. Monitoring is built in and included, with no external tools to deploy, and a dedicated dashboard centralises service management from the Console. Cache sizing adjusts automatically based on machine size and the number of users.

Network security: IP address filtering

Restrict access to your realms at the network level: filter authorised IP addresses on administration, public and provisioning endpoints, on a realm-by-realm basis, with global filtering for administration access. Additional filtering can also be applied directly within the authentication flow at login.

Scalability, performance and high availability

Keycloak as a Service is built to scale effortlessly: handle thousands of simultaneous connections with an infrastructure that grows with you.

You retain control over the sizing of each component: although the baseline resources can already handle heavy workloads, they can be resized at any time, on the fly, with no dropped connections when scaling up. For a component as critical as IAM, the service can be deployed in clustered mode across multiple nodes (Secured Multi-Instances): this architecture ensures load distribution and service continuity as demand increases. It can be configured and managed directly from the Clever Cloud Console.

Easy management and full customization

You have full control over your service, with streamlined management of realms and easy import/export capabilities.

  • Plugins adapt to all your needs: use existing community plugins or develop your own custom ones—for a truly customizable and modular IAM solution.
  • Simplified realm import and export and integration via proxy authentification
  • Custom login page theming

Automation and provisioning

Provision and manage your Keycloak clusters as code: the service integrates with Terraform for reproducible, version-controlled deployment alongside the rest of your Clever Cloud infrastructure.

Managed Keycloak: what’s included

All features are included by default, with no options to enable or additional charges: a single-node deployment offers exactly the same feature set as the largest cluster, including monitoring, metrics, plugins and security.

Keycloak as a Service uses three independently managed Clever Cloud resources, allowing you to precisely tailor the setup to your needs:

  • A PostgreSQL database;
  • A Java image;
  • A File System FSBucket.

Keycloak as a Service experts: Please Open-It

Keycloak as a Service was designed with the help of Please Open-It, experts in SSO, identity management, and authentication.
Leverage their expertise for integration or customization of your service. And if you want to go even further, Please Open-It can help you build a fully tailored IAM solution.

VIDEO

Managed Keycloak demonstration

Discover the presentation of Keycloak as a Service by Mathieu Passenaud from Please Open IT and Horacio Gonzalez from Clever Cloud.
Démo Sales Miniature keycloak en

Pricing

Starts at 47€/month

Legal informations

Keycloak as a Service is an add-on developed in collaboration with Please Open IT, and hosted and operated by Clever Cloud. You can find our General Terms of Service here.

Are you evaluating an identity management solution?

Download our checklist: 11 questions to ask any provider before making your decision.
Last update: August 2026

FAQ

What is Keycloak as a Service?

Keycloak as a Service is a managed identity and access management (IAM) solution that centralises authentication and authorisation for your applications. Clever Cloud hosts, maintains and updates the service, allowing you to focus on using it rather than operating it.

What is the difference between self-hosted and managed Keycloak?

With self-hosted Keycloak, you manage the installation, updates, security, backups and availability yourself. With the managed version, Clever Cloud handles operational maintenance, monitoring and continuous updates on dedicated infrastructure.

Which authentication standards are supported?

The service supports OAuth 2.0, OpenID Connect and SAML v2, as well as directory federation via LDAP (Active Directory and OpenLDAP). It can also delegate authentication to external identity providers.

Is the service suitable for use in regulated sectors?

It provides controls for organisations subject to stringent requirements, such as IP address filtering by realm and for administration access. The Digital Operational Resilience Act (DORA) for the financial sector and the NIS2 Directive are among the relevant regulatory frameworks.

Is the service highly available?

Yes. For a component as critical as IAM, it can be deployed in clustered mode across multiple nodes (Secured Multi-Instances), ensuring load distribution and service continuity during periods of high demand.

Can I import an existing Keycloak configuration?

Yes. Realm import and export are supported, making it easier to take over an existing instance or migrate it.

Are any features available as paid options?

No. All features are included by default, with no optional extras or additional charges. A single-node deployment offers exactly the same feature set as the largest cluster.

Who handles updates and maintenance?

Clever Cloud handles updates to recent Keycloak versions, security, operational maintenance and regular backups. Monitoring is built in and included, with no external tools to deploy.

Who is Please Open-It?

Please Open-It is the specialist partner in SSO (single sign-on), identity management and authentication with which the service was designed. Its expertise is available for integration or customisation.

NEWS

Our blog

Blog

Managed Kubernetes: benefits, limitations and selection criteria

A managed Kubernetes service is an offering in which the cloud provider manages the Kubernetes control plane on the user’s behalf. Provisioning, updates, availability and certificate rotation are handled by the provider. The user retains control over their workloads and node pools but does not administer the cluster’s critical infrastructure.
Engineering Features

Kubernetes Cloud: What It Is, How It Works, and the Main Types of Offerings

People often talk about “Kubernetes cloud” as if it were a single product, or set Kubernetes and the cloud against each other as competing choices. Neither is accurate.
Engineering

Clever Cloud’s partnership strategy: building an open ecosystem for strategic autonomy

When we launched our PaaS, Clever Cloud, our mission was clear: to create a cloud platform that developers would trust and enjoy using, something reliable, intuitive, and well-suited to the evolving demands of modern software development.
Company