Home › Custom Software › Open-Source Customisation › Borrow, Don't Build › Keycloak

Borrow, Don't Build · Logins

Keycloak for logins and single sign-on

User accounts, two-factor login and single sign-on with Microsoft or Google, handled by a dedicated, well-tested service instead of hand-written login code.

Rob Sherwood, co-founder of Dev Partners
Straight answer: login code is where security goes wrong, and every system needs it. Keycloak is a mature open-source identity service used by large organisations. Putting your logins through it means password resets, two-factor and Microsoft sign-in are done properly, once, for all your systems.

One place for logins, across all your systems

Keycloak sits in front of your applications and handles everything about who someone is: signing in, two-factor, password resets, and signing in with an account people already have.

It supports the standard protocols, OpenID Connect, OAuth 2.0 and SAML 2.0, so almost any system can use it. It can let people sign in with Microsoft or Google, connect to an existing Active Directory or LDAP directory, and be themed to look like your own brand.

It is open source under the Apache 2.0 licence, one of the most permissive there is, and a Cloud Native Computing Foundation incubation project. Details checked against keycloak.org on 9 October 2026.

What we use it for

  • Sign in with Microsoft or Google

    Staff sign in with the work account they already have, and lose access the moment IT switches it off.

  • One login for several systems

    Your portal, your back office and your reporting share one sign-in, so nobody juggles passwords.

  • Two-factor login

    Authenticator apps or security keys, switched on for everyone or just for administrators.

  • Customer accounts

    Sign-up, email checks, password resets and account pages for your customers, in your own branding.

  • Connected to your directory

    Use the users and groups already in Active Directory or another directory, rather than keeping a second list.

  • Wired into your software

    Your Laravel or PHP application hands sign-in to Keycloak and trusts what comes back, using the standard protocols.

Keycloak runs as its own service. Your application talks to it using standard protocols, and we never change Keycloak itself. More on the approach in borrow, don't build.

Is Keycloak right for you?

A good fit when

  • You have more than one system people sign in to
  • Staff should sign in with their Microsoft or Google account
  • You need two-factor login done properly
  • You have customer accounts and want them handled securely

Think twice when

  • One small application with one kind of user: the framework's own login is fine
  • Microsoft Entra ID already does everything you need
  • Nobody can run and update another service
  • You only need social login on a single site

The honest summary: for a single small application, the login built into Laravel is enough. Keycloak earns its place once you have several systems, or need single sign-on and two-factor done properly across them.

What people ask us

Yes. It is open source under the Apache 2.0 licence. You pay for setting it up, connecting your systems, and hosting it. Some companies sell paid support for it if you want that too.

Yes. Keycloak can hand sign-in to Microsoft, so staff use their work account and you control access in one place.

It is widely used and actively maintained, and it does the hard parts, like password storage and two-factor, in a way that has been looked at by a lot of people. Like any server software, it needs keeping up to date, which we plan for.

Too many passwords, too many systems?

Tell us who signs in to what.

Which systems people sign in to, whether you use Microsoft 365 or Google Workspace, and whether your customers have accounts. If your framework's own login is enough, we will say so.

We reply within one working day.

Get in touch