This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.
Keycloak is a safe choice: it is open source, mature and backed by Red Hat. Teams look for alternatives for a few recurring reasons:
- Operations. It is a Java service with a lot of configuration surface, and major upgrades and custom themes take real time.
- No managed service from the project. If you don't want to run it, you need a third party.
- Protocol gaps. It can federate users from LDAP and Active Directory, but it can't itself serve LDAP, RADIUS or CAS to legacy apps and devices.
- Authorization. Fine-grained permissions beyond roles mean learning its authorization services or building your own.
Here are five alternatives, and at the end, how to keep Keycloak but stop running it.
Comparison
| Casdoor | authentik | Zitadel | Ory | FusionAuth | |
|---|---|---|---|---|---|
| License | Apache-2.0 | MIT, enterprise features separate | AGPL-3.0 | Apache-2.0 | Proprietary, free Community edition |
| Language | Go | Python | Go | Go | Java |
| Admin console | Yes | Yes | Yes | Hosted only | Yes |
| OIDC and SAML | Yes | Yes | Yes | OIDC; SAML through Ory Polis | Yes |
| Serves LDAP and RADIUS | Yes | Yes | No | No | No |
| CAS | Yes | No | No | No | No |
| Managed cloud from the maintainers | Yes, flat price | No | Yes, per DAU | Yes | Yes |
1. Casdoor
Casdoor is the closest like-for-like replacement: an Apache-2.0 identity server with a full admin console, like Keycloak, but a single Go binary that starts in seconds and runs comfortably on a small VM.
It covers the protocols Keycloak does (OIDC, OAuth 2.0, SAML) and adds CAS, LDAP, RADIUS and SCIM, so the same server can sign users into web apps, VPNs, Wi-Fi and legacy LDAP clients. Permissions come from Casbin, so you can model ACL, RBAC or ABAC rules in the console instead of writing Keycloak authorization policies. A Keycloak syncer imports your existing users and groups.
And if you don't want to run anything, Casdoor Cloud is a managed, dedicated instance from $24.17/month billed yearly ($29 month to month), run by the team that builds Casdoor.
Trade-offs: Keycloak has a larger community, more third-party guides and Red Hat support contracts. Read the full Casdoor vs Keycloak comparison.
2. authentik
authentik is the friendliest option for self-hosters. Login flows are designed visually, and outposts add SSO to apps with no login integration by proxying them. It serves OIDC, SAML, LDAP and RADIUS.
Trade-offs: no managed cloud, and enterprise features are licensed per internal user ($5 per user per month).
3. Zitadel
Zitadel is a Go platform built for multi-tenant B2B SaaS, with organizations and delegated administration built in, and a managed cloud.
Trade-offs: AGPL-3.0 since version 3, and the cloud is priced by daily active users (free up to 100, Pro $100 per month for 25,000).
4. Ory
Ory splits identity into headless services (Kratos, Hydra, Keto, Oathkeeper). Hydra is a battle-tested, OpenID Certified OAuth 2.0 server.
Trade-offs: no admin UI or login pages in the open-source version, and SAML lives in a separate product, Ory Polis. Choose it if you want APIs and will build all the screens yourself.
5. FusionAuth
FusionAuth is a single-tenant server like Keycloak, with a cleaner admin UI and good documentation, and FusionAuth can host it for you.
Trade-offs: it is not open source, and plans with hosting start at $162 per month billed yearly, with Essentials and Enterprise from $2,970 per month.
Or: keep Keycloak and let someone host it
If your apps are deeply tied to Keycloak's features, managed Keycloak hosts give each customer a dedicated cluster for a flat price:
| Host | Entry price | Trial |
|---|---|---|
| Skycloak | $29 per month (Developer), $149 (Launch) | 21 days |
| Phase Two | $149 per month (Starter) | 30 days |
| Cloud-IAM | €225 per month (Starter) | Free tier for 100 users |
These are a reasonable middle ground. If you are going to pay for hosting anyway, it is worth comparing them with Casdoor Cloud, which gives you a dedicated instance from $24.17/month billed yearly and more protocols out of the box.
Migrating from Keycloak to Casdoor
- Run Casdoor next to Keycloak and use the Keycloak syncer to import users and groups.
- Recreate clients as Casdoor applications. OIDC and SAML apps only need a new issuer URL, client ID and secret.
- Move apps over one at a time, starting with the least critical.
- Point LDAP or RADIUS clients at Casdoor if you used to run a separate directory for them.
Talk to us if you'd like help planning a larger migration.
Sources
- Keycloak on GitHub
- Red Hat build of Keycloak subscriptions
- authentik pricing
- Zitadel pricing
- Ory pricing
- Ory Polis announcement
- FusionAuth pricing
- Skycloak pricing
- Phase Two pricing
- Cloud-IAM pricing
Product names are trademarks of their respective owners.