Udibo vs Keycloak
Keycloak is a complete identity server you download and run: realms, OpenID Connect and SAML, LDAP and Active Directory federation, and an authorization engine, under the Apache 2.0 license with no per-user price. Udibo gives you hosted sign-in behind a standard OAuth 2.0 boundary, with organizations, roles, and per-resource permissions included on every plan. The difference that decides most evaluations: Keycloak's price is the infrastructure and the engineer's time it takes to run it, and Udibo's is a usage bill.
Checked September 7, 2026 against keycloak.org, the Keycloak guides, and Red Hat's subscription note for its supported build. Udibo Identity is in private beta, and its prices are a preview, not an adopted rate card.
The short version
| If you need | Start with |
|---|---|
| SAML, LDAP or Active Directory users, or identity that stays on your servers | Keycloak |
| An identity server with no license cost and the team to operate it | Keycloak |
| Hosted sign-in that nobody on your team upgrades, clusters, or patches | Udibo |
| Organizations, custom roles, and a per-resource permission check, hosted | Udibo |
| Passkeys at launch | Keycloak, or another provider that ships them today |
| A bill that scales with usage rather than with servers and an engineer | Udibo |
| A production dependency available today without beta access | Keycloak, until the Udibo hosted service opens to the public |
Why teams pick Udibo over Keycloak
Nobody on your team runs the identity server. Keycloak's production guide expects TLS, a public hostname, a reverse proxy, a production-grade database, "two or more Keycloak instances", and distributed caches between them; its upgrading guide has you review migration changes, migrate the database, and update themes on each release. Udibo runs the service: upgrades, availability, abuse controls, email delivery, and audit retention are on the bill, not on your calendar.
A vocabulary sized for a product. Keycloak's model is realms, clients, realm roles, client roles, composite roles, groups, and an authorization engine of resources, scopes, policies, and permissions. Udibo's is organizations, memberships, roles, and the permissions your application interprets, assignable across a tenant, inside one organization, or on one resource.
A hosted check your server calls. Register the permissions your application interprets, attach them to roles, and read the result from the token or ask
POST /api/checkabout one resource. Keycloak's Authorization Services can express resource-level permissions too; they come with a policy model to learn and a policy enforcer to deploy beside your application.Growth costs usage, not headcount. Udibo's preview rate is $3 per 1,000 retained users past the allowance. Keycloak's software is $0 at any user count; what grows with it is the database, the cluster, and the time someone spends keeping both healthy.
The operational pieces come built. Signed webhooks with retries and redrive, at least 90 days of audit history exportable as CSV or NDJSON, your own email sender never metered, and a custom session policy on every plan. Keycloak stores login and admin events in its database with an expiration you set and sends email through an SMTP server you configure: workable, and yours to keep working.
Your brand at the door with no theme to maintain. Your name, logo, and colors on the hosted pages with no vendor badge on any plan. Keycloak's themes are yours to write and to carry through each upgrade.
Why Keycloak may still be the right choice
SAML, LDAP, and Active Directory. Keycloak brokers to SAML 2.0 and OpenID Connect identity providers and federates users from LDAP and Active Directory. Udibo connects to any OpenID Connect provider with no per-connection fee and does not offer SAML, SCIM, or directory federation today.
Control of where it runs. Keycloak deploys on your servers or your Kubernetes cluster, and the user data stays there. Udibo is a hosted service; an open-source identity core is planned (MIT) for when the hosted service opens, and it is not available yet.
No license cost, with a supported build if you want one. Keycloak is Apache 2.0 with no per-user price. Red Hat build of Keycloak is included with Red Hat Runtimes, Application Foundations, and OpenShift Container Platform subscriptions rather than sold on its own, and Red Hat commits to at least two years of support for a 26.x major and three years from 27.x.
Passkeys and a deep extension model. Keycloak 26.7 ships passkeys enabled by default, and custom authenticators, mappers, and policies are part of the design. Udibo does not offer hosted passkeys.
Generally available. Keycloak is a production dependency you can download this afternoon. Udibo Identity is in private beta.
Pricing side by side
Keycloak publishes no price list: the software is free and the cost is what you run it on. The rows below put Udibo's pricing preview beside what Keycloak includes and what it leaves to you.
| You need | Udibo (preview) | Keycloak |
|---|---|---|
| Free plan | 500 retained users, 25,000 hosted permission checks, 1,000 emails | The software, Apache 2.0, at any user count; hosting is yours |
| First paid plan | $5 a month plus usage: 5,000 users, 250,000 checks, 10,000 emails included | None from the project; Red Hat build of Keycloak comes inside Red Hat Runtimes, Application Foundations, and OpenShift subscriptions, by quote |
| Multi-factor authentication | Included on Free | Included: TOTP/HOTP, recovery codes, WebAuthn, passkeys |
| Custom roles and permissions | Included on Free, across a tenant, an organization, or one resource | Included: realm and client roles, composite roles, groups, and Authorization Services |
| Organizations and members | No cap | Included: organizations within a realm, enabled by default |
| Remove vendor branding | Included on Free | Themes are yours to write and maintain |
| Custom session lifetime | Included on Free | Included: realm session and token timeouts |
| Enterprise SSO connections | No per-connection fee for OpenID Connect providers; SAML not yet available | Included: OpenID Connect and SAML 2.0 brokering, LDAP and Active Directory federation |
| Audit or application log history | At least 90 days on every plan | Login and admin events in your database, with an expiration you set |
| Sign-in email | 1,000 on Free and 10,000 on Standard, then $1 per 1,000; your own sender is never metered | Sent through an SMTP server you configure and pay for |
| Users beyond the allowance | $3 per 1,000 retained users | $0 in software; more database and cluster capacity |
| Hosted permission checks | $10 per 1,000,000 past the allowance | No per-check charge; Authorization Services run on your cluster |
| Machine-to-machine tokens | No per-token charge; technical and abuse limits apply | No per-token charge; issued by the server you run |
Three worked examples, with the same assumptions on both sides:
| Scenario | Udibo (preview) | Keycloak |
|---|---|---|
| Consumer app: 10,000 retained users, 5,000 sign-in emails, MFA on, your own branding | $20 (Standard base plus 5,000 users above allowance) | $0 in software, plus hosting, a database, an SMTP provider, and the hours to run and upgrade |
| B2B app: 200 users, 5 organizations of 30 members, custom roles, MFA | $0 on Free, or $5 on Standard | $0 in software; realms, organizations, groups, and roles configured and hosted by you |
| Consumer app at 100,000 retained users | About $290 | $0 in software; a clustered deployment sized by you, and the operations to match |
Sources: keycloak.org, the production configuration guide, Red Hat's subscription note, and Udibo's pricing preview. Both change; check the vendor's current page before you decide.
Cost at scale
Users only, same definition on both sides. Udibo's figures are preview rates; Keycloak has no per-user figure to compute.
| Retained users | Udibo (preview) | Keycloak |
|---|---|---|
| 1,000 | $5 (Standard) | $0 in software; hosting and operations yours |
| 10,000 | $20 | $0 in software; hosting and operations yours |
| 100,000 | About $290 | $0 in software; hosting and operations yours |
| 1,000,000 | About $2,990 | $0 in software; hosting and operations yours |
There is no crossover, because self-hosted software has no per-user price. What you pay instead is the list from Keycloak's own production guide: servers for two or more instances, a production database and its backups, a reverse proxy and TLS, distributed caches between the nodes, an upgrade on each release with its database migration, an SMTP provider for the email, and the engineer whose time all of that takes; a Red Hat subscription if you want a supported build, by quote. Whether that beats $20 or $2,990 a month depends on whether those servers and that person already exist, so price the engineer's hours before deciding.
What the integration looks like
With Udibo, register an application and its callback, send people to the hosted sign-in page, and finish the authorization-code flow on your server. Your backend holds the session and the browser gets a cookie, never a token. The first-login guide walks each checkpoint, and the organizations and permissions guides cover a person with a different role in each of two organizations.
With Keycloak, create a realm and a client, then integrate with an OpenID Connect or SAML library. Keycloak's own guidance is to prefer the libraries already in your application's ecosystem and to treat its client adapters as "a last resort" (securing applications). Both products put an OAuth 2.0 and OpenID Connect boundary between identity and your application, which is why a move in either direction is mostly an issuer change on the client side and mostly data on the server side.
Neither approach removes your responsibility to protect application data on the server. A valid session says who someone is; your backend still decides what they may read.
Where Udibo needs a closer look
Udibo does not currently offer SAML, SCIM, LDAP or Active Directory federation,
hosted passkeys, or a self-hosted edition; the open-source identity core is
planned for when the hosted service opens. Organizations are flat, so Keycloak
groups that nest will need a mapping rather than a copy. The @udibo/oauth2
package is a separate option for application-owned authentication, not a
Keycloak realm you can run yourself. Tenant-management calls need administrator
credentials rather than an application's machine token. If your product needs a
particular account-management screen, test that whole journey before committing;
a successful login alone does not establish parity.
Moving an existing Keycloak application
Inventory realms, clients, roles, groups, mappers, authentication flows, and upstream identity providers. A realm, an organization, and a client application are different concepts; design an explicit mapping before moving data. Custom mappers and authenticators can change both claims and login behavior, so reproduce those dependencies in tests before changing token issuers.
Passwords need their own plan. Keycloak has hashed new passwords with Argon2 by default since 25.0 in a non-FIPS environment, and Udibo's importer does not accept Argon2; PBKDF2 hashes from older realms can come across in an accepted encoding and are upgraded on first sign-in, and every other account needs a reset path. MFA enrollment and sessions do not move with a profile. If you only need a different client integration, an identity-provider migration may be unnecessary; evaluate the smallest change that meets the requirement. See migration planning and user import.
Try next: complete one Udibo login, then give a person two organizations and a different role in each. If you are on the waitlist, the agent integration brief lets your coding assistant prepare the integration in the meantime.
Frequently asked questions
Is Udibo cheaper than Keycloak? At the license line, no: Keycloak's software is free. The honest comparison is Udibo's bill against the servers, database, upgrade cycle, and engineer's hours that running Keycloak takes. For a team without an operations function, $5 to $20 a month is usually less than those hours; for a team that already runs a cluster, the answer can go the other way.
Does Udibo support SAML or LDAP like Keycloak? Not today. Udibo connects to any OpenID Connect provider with no per-connection fee. SAML federation, LDAP and Active Directory user federation, SCIM provisioning, and hosted passkeys are not available.
Can I move from Keycloak to Udibo? Profiles and social identities can be imported and linked by the provider's stable subject, and realms, groups, and roles need an explicit mapping onto organizations and roles. Password hashes depend on the algorithm: Argon2, Keycloak's default since 25.0, is not accepted, and PBKDF2 hashes are. MFA enrollments and sessions do not move. See migration planning.
Is there a self-hosted Udibo? Not yet. An open-source identity core is
planned under the MIT license for when the hosted service opens. The
@udibo/oauth2 package exists today for building OAuth 2.0 and OpenID Connect
into an application you operate, and it is a toolkit rather than a server with
an administration console.
Last verified 2026-09-07.

