Skip to content

Udibo vs Keycloak

Keycloak is a complete identity server you download and run: realms, OpenID Connect and SAML, LDAP and Active Directory federation, and an authorization engine, under the Apache 2.0 license with no per-user price. Udibo gives you hosted sign-in behind a standard OAuth 2.0 boundary, with organizations, roles, and per-resource permissions included on every plan. The difference that decides most evaluations: Keycloak's price is the infrastructure and the engineer's time it takes to run it, and Udibo's is a usage bill.

Checked September 7, 2026 against keycloak.org, the Keycloak guides, and Red Hat's subscription note for its supported build. Udibo Identity is in private beta, and its prices are a preview, not an adopted rate card.

The short version

If you needStart with
SAML, LDAP or Active Directory users, or identity that stays on your serversKeycloak
An identity server with no license cost and the team to operate itKeycloak
Hosted sign-in that nobody on your team upgrades, clusters, or patchesUdibo
Organizations, custom roles, and a per-resource permission check, hostedUdibo
Passkeys at launchKeycloak, or another provider that ships them today
A bill that scales with usage rather than with servers and an engineerUdibo
A production dependency available today without beta accessKeycloak, until the Udibo hosted service opens to the public

Why teams pick Udibo over Keycloak

  • Nobody on your team runs the identity server. Keycloak's production guide expects TLS, a public hostname, a reverse proxy, a production-grade database, "two or more Keycloak instances", and distributed caches between them; its upgrading guide has you review migration changes, migrate the database, and update themes on each release. Udibo runs the service: upgrades, availability, abuse controls, email delivery, and audit retention are on the bill, not on your calendar.

  • A vocabulary sized for a product. Keycloak's model is realms, clients, realm roles, client roles, composite roles, groups, and an authorization engine of resources, scopes, policies, and permissions. Udibo's is organizations, memberships, roles, and the permissions your application interprets, assignable across a tenant, inside one organization, or on one resource.

  • A hosted check your server calls. Register the permissions your application interprets, attach them to roles, and read the result from the token or ask POST /api/check about one resource. Keycloak's Authorization Services can express resource-level permissions too; they come with a policy model to learn and a policy enforcer to deploy beside your application.

  • Growth costs usage, not headcount. Udibo's preview rate is $3 per 1,000 retained users past the allowance. Keycloak's software is $0 at any user count; what grows with it is the database, the cluster, and the time someone spends keeping both healthy.

  • The operational pieces come built. Signed webhooks with retries and redrive, at least 90 days of audit history exportable as CSV or NDJSON, your own email sender never metered, and a custom session policy on every plan. Keycloak stores login and admin events in its database with an expiration you set and sends email through an SMTP server you configure: workable, and yours to keep working.

  • Your brand at the door with no theme to maintain. Your name, logo, and colors on the hosted pages with no vendor badge on any plan. Keycloak's themes are yours to write and to carry through each upgrade.

Why Keycloak may still be the right choice

  • SAML, LDAP, and Active Directory. Keycloak brokers to SAML 2.0 and OpenID Connect identity providers and federates users from LDAP and Active Directory. Udibo connects to any OpenID Connect provider with no per-connection fee and does not offer SAML, SCIM, or directory federation today.

  • Control of where it runs. Keycloak deploys on your servers or your Kubernetes cluster, and the user data stays there. Udibo is a hosted service; an open-source identity core is planned (MIT) for when the hosted service opens, and it is not available yet.

  • No license cost, with a supported build if you want one. Keycloak is Apache 2.0 with no per-user price. Red Hat build of Keycloak is included with Red Hat Runtimes, Application Foundations, and OpenShift Container Platform subscriptions rather than sold on its own, and Red Hat commits to at least two years of support for a 26.x major and three years from 27.x.

  • Passkeys and a deep extension model. Keycloak 26.7 ships passkeys enabled by default, and custom authenticators, mappers, and policies are part of the design. Udibo does not offer hosted passkeys.

  • Generally available. Keycloak is a production dependency you can download this afternoon. Udibo Identity is in private beta.

Pricing side by side

Keycloak publishes no price list: the software is free and the cost is what you run it on. The rows below put Udibo's pricing preview beside what Keycloak includes and what it leaves to you.

You needUdibo (preview)Keycloak
Free plan500 retained users, 25,000 hosted permission checks, 1,000 emailsThe software, Apache 2.0, at any user count; hosting is yours
First paid plan$5 a month plus usage: 5,000 users, 250,000 checks, 10,000 emails includedNone from the project; Red Hat build of Keycloak comes inside Red Hat Runtimes, Application Foundations, and OpenShift subscriptions, by quote
Multi-factor authenticationIncluded on FreeIncluded: TOTP/HOTP, recovery codes, WebAuthn, passkeys
Custom roles and permissionsIncluded on Free, across a tenant, an organization, or one resourceIncluded: realm and client roles, composite roles, groups, and Authorization Services
Organizations and membersNo capIncluded: organizations within a realm, enabled by default
Remove vendor brandingIncluded on FreeThemes are yours to write and maintain
Custom session lifetimeIncluded on FreeIncluded: realm session and token timeouts
Enterprise SSO connectionsNo per-connection fee for OpenID Connect providers; SAML not yet availableIncluded: OpenID Connect and SAML 2.0 brokering, LDAP and Active Directory federation
Audit or application log historyAt least 90 days on every planLogin and admin events in your database, with an expiration you set
Sign-in email1,000 on Free and 10,000 on Standard, then $1 per 1,000; your own sender is never meteredSent through an SMTP server you configure and pay for
Users beyond the allowance$3 per 1,000 retained users$0 in software; more database and cluster capacity
Hosted permission checks$10 per 1,000,000 past the allowanceNo per-check charge; Authorization Services run on your cluster
Machine-to-machine tokensNo per-token charge; technical and abuse limits applyNo per-token charge; issued by the server you run

Three worked examples, with the same assumptions on both sides:

ScenarioUdibo (preview)Keycloak
Consumer app: 10,000 retained users, 5,000 sign-in emails, MFA on, your own branding$20 (Standard base plus 5,000 users above allowance)$0 in software, plus hosting, a database, an SMTP provider, and the hours to run and upgrade
B2B app: 200 users, 5 organizations of 30 members, custom roles, MFA$0 on Free, or $5 on Standard$0 in software; realms, organizations, groups, and roles configured and hosted by you
Consumer app at 100,000 retained usersAbout $290$0 in software; a clustered deployment sized by you, and the operations to match

Sources: keycloak.org, the production configuration guide, Red Hat's subscription note, and Udibo's pricing preview. Both change; check the vendor's current page before you decide.

Cost at scale

Users only, same definition on both sides. Udibo's figures are preview rates; Keycloak has no per-user figure to compute.

Retained usersUdibo (preview)Keycloak
1,000$5 (Standard)$0 in software; hosting and operations yours
10,000$20$0 in software; hosting and operations yours
100,000About $290$0 in software; hosting and operations yours
1,000,000About $2,990$0 in software; hosting and operations yours

There is no crossover, because self-hosted software has no per-user price. What you pay instead is the list from Keycloak's own production guide: servers for two or more instances, a production database and its backups, a reverse proxy and TLS, distributed caches between the nodes, an upgrade on each release with its database migration, an SMTP provider for the email, and the engineer whose time all of that takes; a Red Hat subscription if you want a supported build, by quote. Whether that beats $20 or $2,990 a month depends on whether those servers and that person already exist, so price the engineer's hours before deciding.

What the integration looks like

With Udibo, register an application and its callback, send people to the hosted sign-in page, and finish the authorization-code flow on your server. Your backend holds the session and the browser gets a cookie, never a token. The first-login guide walks each checkpoint, and the organizations and permissions guides cover a person with a different role in each of two organizations.

With Keycloak, create a realm and a client, then integrate with an OpenID Connect or SAML library. Keycloak's own guidance is to prefer the libraries already in your application's ecosystem and to treat its client adapters as "a last resort" (securing applications). Both products put an OAuth 2.0 and OpenID Connect boundary between identity and your application, which is why a move in either direction is mostly an issuer change on the client side and mostly data on the server side.

Neither approach removes your responsibility to protect application data on the server. A valid session says who someone is; your backend still decides what they may read.

Where Udibo needs a closer look

Udibo does not currently offer SAML, SCIM, LDAP or Active Directory federation, hosted passkeys, or a self-hosted edition; the open-source identity core is planned for when the hosted service opens. Organizations are flat, so Keycloak groups that nest will need a mapping rather than a copy. The @udibo/oauth2 package is a separate option for application-owned authentication, not a Keycloak realm you can run yourself. Tenant-management calls need administrator credentials rather than an application's machine token. If your product needs a particular account-management screen, test that whole journey before committing; a successful login alone does not establish parity.

Moving an existing Keycloak application

Inventory realms, clients, roles, groups, mappers, authentication flows, and upstream identity providers. A realm, an organization, and a client application are different concepts; design an explicit mapping before moving data. Custom mappers and authenticators can change both claims and login behavior, so reproduce those dependencies in tests before changing token issuers.

Passwords need their own plan. Keycloak has hashed new passwords with Argon2 by default since 25.0 in a non-FIPS environment, and Udibo's importer does not accept Argon2; PBKDF2 hashes from older realms can come across in an accepted encoding and are upgraded on first sign-in, and every other account needs a reset path. MFA enrollment and sessions do not move with a profile. If you only need a different client integration, an identity-provider migration may be unnecessary; evaluate the smallest change that meets the requirement. See migration planning and user import.

Try next: complete one Udibo login, then give a person two organizations and a different role in each. If you are on the waitlist, the agent integration brief lets your coding assistant prepare the integration in the meantime.

Frequently asked questions

Is Udibo cheaper than Keycloak? At the license line, no: Keycloak's software is free. The honest comparison is Udibo's bill against the servers, database, upgrade cycle, and engineer's hours that running Keycloak takes. For a team without an operations function, $5 to $20 a month is usually less than those hours; for a team that already runs a cluster, the answer can go the other way.

Does Udibo support SAML or LDAP like Keycloak? Not today. Udibo connects to any OpenID Connect provider with no per-connection fee. SAML federation, LDAP and Active Directory user federation, SCIM provisioning, and hosted passkeys are not available.

Can I move from Keycloak to Udibo? Profiles and social identities can be imported and linked by the provider's stable subject, and realms, groups, and roles need an explicit mapping onto organizations and roles. Password hashes depend on the algorithm: Argon2, Keycloak's default since 25.0, is not accepted, and PBKDF2 hashes are. MFA enrollments and sessions do not move. See migration planning.

Is there a self-hosted Udibo? Not yet. An open-source identity core is planned under the MIT license for when the hosted service opens. The @udibo/oauth2 package exists today for building OAuth 2.0 and OpenID Connect into an application you operate, and it is a toolkit rather than a server with an administration console.

Last verified 2026-09-07.