Borrow, Don't Build · Logins
User accounts, two-factor login and single sign-on with Microsoft or Google, handled by a dedicated, well-tested service instead of hand-written login code.
Keycloak sits in front of your applications and handles everything about who someone is: signing in, two-factor, password resets, and signing in with an account people already have.
It supports the standard protocols, OpenID Connect, OAuth 2.0 and SAML 2.0, so almost any system can use it. It can let people sign in with Microsoft or Google, connect to an existing Active Directory or LDAP directory, and be themed to look like your own brand.
It is open source under the Apache 2.0 licence, one of the most permissive there is, and a Cloud Native Computing Foundation incubation project. Details checked against keycloak.org on 9 October 2026.
Staff sign in with the work account they already have, and lose access the moment IT switches it off.
Your portal, your back office and your reporting share one sign-in, so nobody juggles passwords.
Authenticator apps or security keys, switched on for everyone or just for administrators.
Sign-up, email checks, password resets and account pages for your customers, in your own branding.
Use the users and groups already in Active Directory or another directory, rather than keeping a second list.
Your Laravel or PHP application hands sign-in to Keycloak and trusts what comes back, using the standard protocols.
Keycloak runs as its own service. Your application talks to it using standard protocols, and we never change Keycloak itself. More on the approach in borrow, don't build.
The honest summary: for a single small application, the login built into Laravel is enough. Keycloak earns its place once you have several systems, or need single sign-on and two-factor done properly across them.
Yes. It is open source under the Apache 2.0 licence. You pay for setting it up, connecting your systems, and hosting it. Some companies sell paid support for it if you want that too.
Yes. Keycloak can hand sign-in to Microsoft, so staff use their work account and you control access in one place.
It is widely used and actively maintained, and it does the hard parts, like password storage and two-factor, in a way that has been looked at by a lot of people. Like any server software, it needs keeping up to date, which we plan for.
Which systems people sign in to, whether you use Microsoft 365 or Google Workspace, and whether your customers have accounts. If your framework's own login is enough, we will say so.
We reply within one working day.