Auth0 vs Keycloak.
Last verified 2026-08-19
When Auth0 wins
- Time-to-first-login and the largest CIAM community
- SOC 2, ISO 27001, HIPAA, FedRAMP via Okta; Keycloak attestations are yours to earn
- Auth0 FGA and packaged agent identity (AI Agents, Auth for MCP)
- No stateful service to patch, theme, or incident-respond
When Keycloak wins
- Apache 2.0, self-hosted, no per-MAU line item, unconstrained data residency
- On-prem and sovereign deployments Auth0 cannot do
- Mature SAML / OIDC bridges for the IdP long tail, including public-sector estates
- Outbound migration is easier (2/5) than leaving Auth0 Actions (4/5)
Both win
- Both support WebAuthn passkeys natively; neither orchestrates them well (Auth0 3/5, Keycloak theming required)
- Both support social login and enterprise federation
- Both will run production login; only one of them is someone else's pager
Pricing comparison
| MAU band | Auth0 | Keycloak |
|---|---|---|
| 10,000 MAU | $240/mo | $250/mo |
| 100,000 MAU | $1,200/mo | $800/mo |
| 500,000 MAU | $4,500/mo | $2,500/mo |
| 1,000,000 MAU | $9,500/mo | $5,000/mo |
Developer experience & lock-in
Editorial 1–5 scores and migration effort, on the same axes for both. Lower migration effort is better (easier to adopt, less lock-in).
| Signal | Auth0 | Keycloak |
|---|---|---|
| DX overallDeveloper experience | 5/5✓ | 3/5 |
| Docs qualityDocumentation | 5/5✓ | 4/5 |
| Passkey orchestrationPasskey / WebAuthn depth | 3/5✓ | 2/5 |
| Adoption effortMigrating in | Moderate✓ | Involved |
| Lock-in (exit effort)Migrating out | Involved | Easy✓ |
Enterprise readiness
Computed across the enterprise pillars from the capability matrix. See the enterprise-ready pillars.
| Pillar | Auth0 | Keycloak |
|---|---|---|
| Overall | Enterprise-ready · 100 | Mostly ready · 71 |
| Enterprise SSO | 100 | 100 |
| Directory sync (SCIM) | 100✓ | 50 |
| Organizations & tenancy | 100✓ | 70 |
| RBAC & custom roles | 100 | 100 |
| Audit logs & streaming | 100 | 100 |
| Compliance certifications | 100✓ | 0 |
| Security posture | 100✓ | 57 |
Side-by-side capability matrix
| Capability | Auth0 | Keycloak |
|---|---|---|
| Password authentication | ✓ Yes | ✓ Yes |
| Social login | ✓ Yes | ✓ Yes |
| Magic links | ✓ Yes | ~ Partial |
| SMS OTP | ✓ Yes | ~ Partial |
| Email OTP | ✓ Yes | ✓ Yes |
| TOTP (authenticator app) | ✓ Yes | ✓ Yes |
| Push MFA | ✓ Yes | ✕ No |
| WebAuthn / passkeys | ✓ Yes | ✓ Yes |
| Biometric | ✓ Yes | ✓ Yes |
| Hardware security keys | ✓ Yes | ✓ Yes |
| SAML SSO | ✓ Yes | ✓ Yes |
| OIDC SSO | ✓ Yes | ✓ Yes |
| OAuth 2.0 SSO | ✓ Yes | ✓ Yes |
| Enterprise federation | ✓ Yes | ✓ Yes |
| Passwordless-only flows | ✓ Yes | ~ Partial |
| Adaptive MFA | ✓ Yes | ~ Partial |
| Step-up auth | ✓ Yes | ✓ Yes |
| Capability | Auth0 | Keycloak |
|---|---|---|
| RBAC | ✓ Yes | ✓ Yes |
| ABAC | ~ Partial | ✓ Yes |
| ReBAC | ✕ No | ✕ No |
| FGA engine | ✓ Yes | ✕ No |
| API authorization | ✓ Yes | ✓ Yes |
| Fine-grained permissions | ✓ Yes | ✓ Yes |
| Capability | Auth0 | Keycloak |
|---|---|---|
| Self-service registration | ✓ Yes | ✓ Yes |
| Progressive profiling | ✓ Yes | ✓ Yes |
| Self-service account | ✓ Yes | ✓ Yes |
| Bulk user import | ✓ Yes | ✓ Yes |
| Admin user search | ✓ Yes | ✓ Yes |
| Custom user metadata | ✓ Yes | ✓ Yes |
| Organizations / tenants | ✓ Yes | ~ Partial |
| Multi-tenancy | ✓ Yes | ✓ Yes |
| SCIM provisioning | ✓ Yes | ~ Partial |
| Capability | Auth0 | Keycloak |
|---|---|---|
| REST API | ✓ Yes | ✓ Yes |
| GraphQL API | ✕ No | ✕ No |
| SDKs | 16 listed | 6 listed |
| CLI | ✓ Yes | ✓ Yes |
| Terraform provider | ✓ Yes | ✓ Yes |
| Local emulator | ✕ No | ✓ Yes |
| Extension model | Actions (Node.js serverless) | SPI extensions (Java) + custom themes |
| Capability | Auth0 | Keycloak |
|---|---|---|
| Bot detection | ✓ Yes | ✕ No |
| Breached password detection | ✓ Yes | ~ Partial |
| Brute-force protection | ✓ Yes | ✓ Yes |
| Anomaly detection | ✓ Yes | ✕ No |
| Log streams | ✓ Yes | ✓ Yes |
| Audit logs | ✓ Yes | ✓ Yes |
| GDPR data export | ✓ Yes | ✓ Yes |
| PII minimization | ~ Partial | ~ Partial |
| Post-quantum roadmap | ✕ No | ✕ No |
| Capability | Auth0 | Keycloak |
|---|---|---|
| MCP support | ✓ Yes | ✕ No |
| OAuth 2.1 | ✓ Yes | ✓ Yes |
| Dynamic client registration | ✓ Yes | ✓ Yes |
| Agent vs human token separation | ✓ Yes | ✕ No |
| Web Bot Auth | ✕ No | ✕ No |
| Capability | Auth0 | Keycloak |
|---|---|---|
| SOC 2 Type II | ✓ Yes | ✕ No |
| ISO 27001 | ✓ Yes | ✕ No |
| ISO 27018 | ✓ Yes | ✕ No |
| HIPAA | ✓ Yes | ✕ No |
| PCI DSS | Level 1 (with config) | ✕ No |
| GDPR | ✓ Yes | ✓ Yes |
| CCPA | ✓ Yes | ✓ Yes |
| FedRAMP | High (via Okta) | ✕ No |
| EU data residency | ✓ Yes | ✓ Yes |
| Capability | Auth0 | Keycloak |
|---|---|---|
| Consent management | ~ Partial | ~ Partial |
| Preference center | ~ Partial | ~ Partial |
| Purpose-specific consent | ✕ No | ~ Partial |
| Integrates with CMPs | 2 listed | n/a |
| Capability | Auth0 | Keycloak |
|---|---|---|
| Multi-region deployment | ✓ Yes | ~ Partial |
| Data residency control | ✓ Yes | ✓ Yes |
| Proven at high scale (1M+ MAU) | ✓ Yes | ✓ Yes |
| Capability | Auth0 | Keycloak |
|---|---|---|
| Password-hash import | ✓ Yes | ✓ Yes |
| Lazy / just-in-time migration | ✓ Yes | ~ Partial |
| Account linking & dedup | ✓ Yes | ✓ Yes |
| Custom domains per brand | ✓ Yes | ✓ Yes |
| Per-brand theming of all flows | ✓ Yes | ~ Partial |
| Per-brand consent partitioning | ~ Partial | ✕ No |
| Deletion webhooks / cascade | ✓ Yes | ~ Partial |
| Event streaming / webhooks | ✓ Yes | ~ Partial |
| Documented rate limits | ✓ Yes | ~ Partial |
FAQ
- Is Keycloak actually free compared with Auth0?
- The license is free. The operating cost is not. A typical 1M MAU Keycloak deployment is $3,000 to $8,000 a month in infrastructure and amortized engineering. Auth0 at the same band is about $9,500 on Compass TCO assumptions, before Enterprise SSO extras. Keycloak wins unit economics if you already run Java services. It loses if the 0.5 FTE is a person you do not have.
- Does Keycloak have SOC 2?
- The software does not. Your deployment might, if you attest it. Auth0's SOC 2, ISO, HIPAA, and FedRAMP-via-Okta are the vendor's. Public-sector buyers who need the vendor's attestation stay on Auth0, Entra, or Ping. Public-sector buyers who need the data on-prem stay on Keycloak or Red Hat's build.
- Can Keycloak replace Auth0 Organizations?
- Realms and groups can be bent into tenancy. They are not Auth0 Organizations. B2B SaaS that wants invitations, per-org SSO, and SCIM as a product should not pick Keycloak to save the MAU bill. Use WorkOS, or stay on Auth0, or self-host FusionAuth if ops is the constraint rather than sovereignty.
- Should I switch from Auth0 to Keycloak?
- Switch if sovereignty or the 1M MAU invoice is the actual constraint, and you will staff the service. Do not switch for DX or passkeys. Budget a program, not a sprint. Inbound migration difficulty on Keycloak is 4/5. FusionAuth is the lighter-ops self-host if Keycloak's stack is the fear.
Auth0 is a product. Keycloak is a platform you operate. The protocol overlap is almost total. The operating model is not.
Choose Auth0 when the team should not own an IdP, compliance has to be a PDF from the vendor, or agent SKUs are on the 2026 roadmap. Choose Keycloak when the data cannot leave the building, the MAU math at consumer scale is absurd, and you already run Java in production.
If you want self-host without Keycloak's operational weight, look at FusionAuth. If you want B2B SSO without either, look at WorkOS.
Profiles: Auth0, Keycloak. Adjacent: Keycloak vs FusionAuth.