3 ms·
Firstly let me say that we like both Auth0 and Keycloak - as others have commented the solutions are widely used and have both unique advantages. We built an o
by mffap 4y ago
Firstly let me say that we like both Auth0 and Keycloak - as others have commented the solutions are widely used and have both unique advantages.
We built an open source alternative to Auth0 which fully supports self-hosting (today on K8s, soon as all-in-one binary on multiple platforms). Regarding Keycloak, it is a great project with high maturity and a lot of features, but lacks in support for B2B, cloud-native and manufacturer support. We wrote a blog comparing Auth0 and Keycloak in more detail, when you might want to consider ZITADEL as alternative. Hope that helps.
- mooreds 4y ago@mffap, are these the blog posts you are referencing? https://zitadel.com/blog/zitadel-vs-keycloak https://zitadel.com/blog/zitadel-vs-keycloak https://zitadel.com/blog/zitadel-vs-auth0 https://zitadel.com/blog/zitadel-vs-auth0
- mffap 4y agoyes, that's it
- arinlen 4y ago> Regarding Keycloak, it is a great project with high maturity and a lot of features, but lacks in support for B2B, cloud-native and manufacturer support. Is this really true though? Last time I checked Keycloak was a RedHat project, meets the definition of cloud-native, and RedHat does provide RedHat Single Sign-On, a Keycloak-based service that is as B2B as it gets. Also, further down the discussion you commented that the project doesn't even provide a Docker image, and instead you mention an ongoing rewrite that might provide a stand-alone binary. https://news.ycombinator.com/item?id=31409609 https://news.ycombinator.com/item?id=31409609 How does that miss allow the project to even be considered cloud-ready, let alone could native?
- ffo 4y agoCurrently we provide a container image as well as K8s support. The v2 will allow us to extend our support to a plain binary as well as serverless containers (Knative et. al) Keycloak is a great tool but definitely not has B2B features like user management for each business customer, self service and delegated access management as well as self service federation. If you feel that I am mistaken, feel free to point out the docs to that ;-)
- piaste 4y ago> Keycloak is a great tool but definitely not has B2B features like user management for each business customer, self service and delegated access management as well as self service federation. (See also: https://zitadel.com/blog/zitadel-vs-keycloak https://zitadel.com/blog/zitadel-vs-keycloak) I might be misreading your post and/or the linked blog post, but I got the impression that both assume that different business customers will share the same KC realm and will only be divided by groups/roles/etc. Is that correct? We use Keycloak in a multi-tenant scenario, so each new business customer spawns its own realm, meaning it can have a fully independent configuration (SSO, OAuth2 integration, 2FA, roles, etc.). While we provide a simplified UI in our product, a sufficiently technical customer can in principle be granted a realm-level administrator user to manage their own configuration.
- ffo 4y agoFrom the IAM perspective (If the service is an IAM) I agree. But as SaaS provider I don’t want to use multiple realms because in that case my client would need to understand multiple issuers. Also Keycloak has a cutoff of around 400 ish realms last time I checked ;-)