Passkeys and MFA with Keycloak: going passwordless in your customer portal

Passkeys replace the password with a phishing-resistant login via fingerprint or PIN — and Keycloak has supported them officially since version 26.4. This article shows you as a decision-maker how passkeys work, which MFA options Keycloak ships with (OTP, WebAuthn, recovery codes), which tiered model makes sense per user group, and where rollouts stall in practice: fallback, device changes, acceptance.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

What Does Keycloak Really Cost? The Software Is Free — Running It Isn't

Keycloak itself costs nothing: Apache 2.0 license, no per-user fee. What you actually budget is setup (€8,000–60,000 depending on scope) and operations (roughly €150–700 per month, managed from €225). Against Auth0, the math works from a few thousand B2B users; below that, the SaaS route stays cheaper. All ranges: happycoding project experience, all third-party prices as of September 2026.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

Keycloak major upgrades: plan them instead of dreading them

Keycloak ships feature releases on a quarterly rhythm and does not patch older versions, so your support window is roughly three months. Deferred upgrades become a security risk as soon as CVE fixes appear only in the new release. With a staging test, realm exports, a rehearsed rollback path, and a fixed quarterly rhythm, the upgrade becomes a plannable routine: in our experience, 0.5 to 5 person-days instead of an emergency project.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

Keycloak, Auth0, Supabase Auth, or Entra ID? The Comparison for Decision-Makers

Four systems, four pricing models: Keycloak costs operations instead of a license, Auth0 bills per active user, Supabase Auth is included in the platform price, and Entra External ID gives you 50,000 MAU for free before it gets expensive. This comparison shows you, with verified prices (as of September 2026), which solution fits your scenario: startup app, mid-market portal, or enterprise with Active Directory.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

SAML vs. OIDC: the protocol question behind every SSO project, explained

SAML and OIDC solve the same problem from two eras: delegating login to a central identity service. SAML 2.0 (2005, OASIS, XML) is the federation standard of corporate IT; OIDC (2014, OpenID Foundation, JSON/JWT on top of OAuth 2.0) is the standard for new web and mobile applications. The practical rule: enterprise customers dictate SAML, your own applications speak OIDC — a broker like Keycloak serves both at once.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

A trust center for your SaaS: the page procurement wants to see

When enterprise procurement asks for security evidence, your response speed decides the deal. A trust center answers the standard questions up front: a data processing agreement (DPA) to download, a sub-processor list, the hosting location, certificates, a status page. I show you what counts when you sell to EU customers, how Personio, Staffbase and sevdesk handle it, and why structured CMS content beats any PDF archive.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

Training your own AI model: why you almost never need to — and which of the four stages is enough instead

You almost never need your own AI model: training GPT-4 alone cost around 78.4 million USD in compute. What you actually want is delivered by one of four stages: structured prompting, RAG over your data, or LoRA fine-tuning on open-weight models, each of which you can optionally run on EU infrastructure. This guide walks you to the right stage with four guiding questions, backed by sourced numbers instead of gut feeling.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

Elasticsearch Alternatives: An Honest Comparison for Websites and Shops

You rarely need Elasticsearch: for website and shop search, Meilisearch, Typesense, or even Postgres full-text search are usually the better choice – cheaper to run and clear on licensing. Elasticsearch remains right for log analytics, aggregations, and very large data volumes. This comparison gives you the decision matrix with prices and license facts, all checked against primary sources on September 4, 2026.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

What is Keycloak? Open-Source Identity & Access Management Explained (2026)

Keycloak is an open-source identity and access management (IAM) system: single sign-on, user and permission management, OIDC/OAuth2/SAML and AD/LDAP integration — self-hosted instead of rented. It replaces per-user licensed identity services such as Auth0, Okta or Azure AD B2C. Current release: version 26.7.4 (September 2026), four minor releases per year, one major release every two to three years. Three things matter for decision-makers: costs do not scale with the user count, identity data stays on your own EU infrastructure (GDPR), and as a CNCF project with Red Hat origins the project's future is broadly secured. A managed IdP remains the right choice for small teams without operational capacity.

Profilbild Matthias Radscheit (Geschäftsführer)

Matthias Radscheit

Open for select projects

Let's talk about your project

Book a no-obligation call, send us an email, or use the form – we'd love to hear from you.

150+
Completed projects
15
Years of experience
8
Senior‑level team members