The short answer: €0 license — and a budget anyway
"Keycloak is free, so why is there a five-figure sum in the proposal?" We hear this question in almost every IAM project. The answer up front: the software really does cost nothing — no license, no per-user fee, Apache 2.0 licensed. What you pay for is setup and operations. If you only compare the license column, you underestimate the project; if you ignore the SaaS providers' per-user fees, you overestimate it.
| Cost block | Range | Basis |
|---|---|---|
| License | €0 | Apache 2.0 license, no user fees (keycloak.org) |
| Setup: concept, branding, integrations | €8,000–60,000 one-off | happycoding project experience |
| Ongoing operations: hosting, updates, monitoring | €150–700 per month | Project experience; managed offerings from €225/month (as of September 2026) |
Why this split? Because "free" in open source is a statement about the license, not about the project. The costs move from the license column into two other columns: one-off into setup, monthly into operations. Those are exactly the two columns we break down now — item by item, with numbers instead of ballpark prose.
Two reading notes for everything that follows: ranges from our projects are marked as project experience — empirical values, not list prices. And every external figure comes with a source and a date, because pricing pages change faster than blog posts.
What Keycloak actually is and which systems it replaces is covered in our overview What is Keycloak? — here it is all about the money: what does the road to a production Keycloak cost, and when does it pay off against Auth0 and friends?
The setup: four line items, honestly broken down
What belongs in a setup quote? Four items that show up in almost every project. To set the frame: the following ranges are happycoding project experience from customer portals and B2B applications — net, one-off, dependent on scope. Your project may land below or above; the items themselves stay the same.
Realm design and role concept: €2,000–6,000
Before anything gets configured, you need a concept: which tenants (realms) exist, say customers separated from employees? Which roles and groups map your business? How long do sessions and tokens live? Mistakes here are the most expensive ones — a role model rebuilt after the fact ripples through every connected application.
Theme and branding: €1,500–5,000
The login is the most sensitive moment of the user relationship, and Keycloak's default interface looks like Keycloak. A custom login theme brings logo, colors and tone up to brand level. The range depends on whether an adapted standard theme is enough or whether registration, password reset and email templates get designed too — for customer portals with white-label ambitions, usually the latter.
Integrations: €1,000–3,000 per application
Every application connects as a client: OIDC configuration, redirect URIs, token claims, role mapping, tests. A Next.js app is connected in one to two days; an older ERP that only speaks SAML can cost a week. Multiply honestly: five applications are five integrations, not one.
SSO and directory connections: €2,000–8,000
Active Directory or LDAP via user federation, "Sign in with Google", SAML connections to partners: this is where the biggest variance sits. A single social login is done in hours; an AD federation with attribute mapping and gradual password migration is a subproject of its own.
A situational fifth item: migrating existing user bases. Exports from Auth0, Cognito or your own database can be imported; Keycloak takes over password hashes directly or gradually on first login, depending on the source format. In our projects, a migration lands between €2,000 and €10,000 depending on data quality and application count (project experience) — for a greenfield build, it drops away entirely.
In total, this matches our project classification: €8,000–20,000 for a focused setup with a handful of applications, €20,000–60,000 for full portal integration with federation and migration. How these items play out in a real project is something we have walked through in our field report on the Supabase and Keycloak stack.
Ongoing costs: hosting, updates, monitoring
The second half of the truth: Keycloak does not run itself. Four blocks determine the monthly bill — three when you self-host, one as the shortcut.
Hosting: €10–150 infrastructure (project experience)
A single instance with a Postgres database runs in our projects on an EU cloud server for €10–30 a month, typically at Hetzner. High availability means two nodes, a load balancer and a managed database: €60–150 monthly. Sizing, by the way, follows login peaks, not the total number of accounts.
For portals with mandatory login we recommend the HA variant — if the IdP goes down, every connected application stops at the same time. That includes backups worthy of the name: daily database dumps, configuration as code, and at least one rehearsed restore per year. A backup that has never been restored is not a backup. Our guide Keycloak self-hosting shows which operating models exist and how to choose one.
Updates and patches: the underestimated block
Keycloak ships four minor releases per year and a major release every two to three years, with patch releases for security issues in between (see keycloak.org). An IdP without patches is a security risk with an admin console. Plan for one to two maintenance windows per quarter; in our operations retainers, this care share sits at €150–500 per month depending on SLA (project experience). Deferred upgrades compound badly — more on that later.
Monitoring: small tools, real responsibility
Uptime checks, error alerts, certificate and backup monitoring: the tools cost little to nothing, what matters is the responsibility behind them. Someone has to be reachable when the login goes down at night. In our projects, monitoring is therefore part of the operations retainer, not a separate invoice.
The shortcut: managed Keycloak from €225/month
If you want to outsource operations, you rent Keycloak as a managed service. Cloud-IAM starts with a dedicated cluster and a 99% SLA from €225/month (as of September 2026). Skycloak begins at $29/month for developer setups, the business package costs $599/month (as of September 2026). Both bill by infrastructure, not per user — so the structural cost advantage over SaaS IdPs stays intact.
What to watch for with managed offerings: the SLA tiers. Cloud-IAM, for instance, distinguishes 99% availability with community support, 99.9% with ticket support and 99.95% with 24/7 on-call (as of September 2026). The price difference buys reaction time when it counts — for a portal with mandatory login, that is not a footnote, it is the actual product.
The comparison: Keycloak vs. Auth0 at 1,000, 10,000 and 50,000 users
Now for the question behind the question: does the effort pay off against a SaaS IdP? We use Auth0 as the benchmark, the best-known provider — the logic carries over to Okta, Entra External ID and others. Our overview Keycloak alternatives sorts out which other providers are worth a look.
What Auth0 costs (as of September 2026)
Auth0 bills per monthly active user (MAU). According to the Auth0 pricing page (as of September 2026), the B2C Essentials plan costs $70/month at 1,000 MAU, $700 at 10,000 and $3,500 at 50,000. The B2B Essentials plan, which customer portals with organization features usually need, sits at $300 (1,000 MAU) and $2,100 (10,000 MAU); from 20,000 MAU, Auth0 points you to sales.
The honest aside: Auth0 runs a free plan up to 25,000 MAU (as of September 2026) — with limits on features, support and SLA, but it does exist. If you fit inside it permanently, you simply pay nothing. The cost comparison starts where free ends: B2B organizations, enterprise connections, SLA obligations or data sovereignty requirements.
The three-year calculation
We compare full costs over 36 months. For Keycloak, that means: setup of €8,000–20,000 one-off plus €150–700 operations per month, both happycoding project experience. We deliberately do not convert the dollar amounts — the exchange rate does not change the order of magnitude.
| Users (MAU) | Auth0 B2C Essentials, 3 years | Auth0 B2B Essentials, 3 years | Keycloak self-operated, 3 years |
|---|---|---|---|
| 1,000 | $2,520 (or $0 on the free plan) | $10,800 | €13,400–45,200 |
| 10,000 | $25,200 | $75,600 | €13,400–45,200 |
| 50,000 | $126,000 | on request only | €13,400–45,200 |
Table sources: Auth0 pricing page, as of September 2026; the Keycloak column comes from our project experience. Infrastructure grows with load, not with user accounts — which is why the jump from 10,000 to 50,000 accounts barely moves the Keycloak column.
What the table leaves out: the SaaS route is not a zero-effort project either. Login flows, role mapping and migrations take integration work on Auth0 too; you only drop operations and patches. The fair comparison reads: similar integration costs on both sides, plus setup and operations for Keycloak, plus the MAU bill for the SaaS IdP.
The middle way belongs in the picture too: managed Keycloak at Cloud-IAM costs from €225/month, so from €8,100 over three years plus setup (prices as of September 2026). That also clearly beats Auth0 B2B at 10,000 MAU — without you owning patches and on-call yourself. Keycloak's cost advantage does not hang on self-hosting, it hangs on the billing model.
The break-even logic, read honestly: at 1,000 B2C users, Keycloak never pays off on price. At 10,000 B2B users, the picture flips — $75,600 stands against €13,400–45,200, with amortization in the first or second year. And at 50,000 B2C users, the SaaS route runs six figures while the Keycloak costs simply stand still.
Sometimes the calculation tips before any break-even: namely when data sovereignty or an EU server location is mandatory anyway and a US SaaS is off the table. Then the price comparison stops being one.
The hidden items
Four items rarely feature prominently in any proposal and belong in the budget anyway:
Key and secret rotation: signing keys, client secrets and certificates want to be swapped on a schedule. Keycloak supports rotation, but someone has to plan it and test the connected applications afterwards. If your first encounter with rotation is an expired certificate, you will experience it as a full outage.
Compliance evidence: a SaaS IdP hands you SOC 2 and ISO reports; when you self-host, you produce the evidence yourself — audit logging, an access concept, backup tests, possibly a pentest. For ISO 27001 shops that is routine, for everyone else it is a real annual line item.
Key-person risk: Keycloak knowledge must not hang on a single person. Documentation, a second knowledge holder or an external retainer cost plannable money; the unplanned exit of your only admin costs unplannably more.
Upgrade debt: skip releases and you pay in bulk. Three deferred versions are no longer a maintenance window but a migration project — including theme adjustments and regression tests across every connected client.
When Keycloak does not pay off
Radical honesty is part of this format, so: in four cases we advise against Keycloak.
Few users, no special requirements: up to a few thousand B2C accounts without enterprise needs, you stay cheaper on a SaaS IdP's free or Essentials plan. A five-figure setup budget cannot be argued against $0 to $70 a month.
A single application: without SSO needs, the framework's auth solution or Supabase Auth is usually enough. A dedicated IdP for a single app is infrastructure without a mission.
The prototype with an open outcome: an MVP that may be shut down in six months does not deserve its own identity infrastructure. Build it on a SaaS IdP or Supabase Auth; you can migrate once the product has proven its right to exist.
Nobody owns operations: identity is critical infrastructure; updates, availability and alerting have to be settled. Without your own team and without a retainer, a managed service or a SaaS IdP is the more honest choice.
The takeaway in one sentence: Keycloak does not save money because the software is free. It saves money when user counts, SSO breadth or data sovereignty blow up the SaaS bill.
Next steps
Planning a customer portal, or looking for a way out of your identity provider's MAU bill? Then replace this article's ranges with your scenario: user counts, application landscape, compliance obligations. Building customer portals on Keycloak is exactly the kind of project we do at happycoding.
Or we run the numbers together: in a free 30-minute intro call, you get an honest assessment of whether Keycloak carries its weight in your scenario — or does not. Book a slot directly.
