One password. Every app. Zero forgotten accounts.
I implement Keycloak on your infrastructure: single sign-on across the tools your team lives in, MFA where it matters, roles instead of favours — and when someone leaves, one click ends their access everywhere.
Access sprawl is a breach with patience
Every app with its own passwords is another place accounts outlive employees, another admin nobody remembers granting, another line in the audit findings.
Ten apps, ten passwords
Every tool has its own login, so people reuse passwords and share accounts — and support spends its mornings on resets.
Offboarding by memory
Someone leaves, and access removal becomes a checklist from memory. The account everyone forgot still works — quarterly access reviews find it, or worse, an incident does.
"Who has access to what?"
The auditor's first question, and today the answer is a spreadsheet nobody trusts. Role-based access exists in policy, not in software.
SSO, federation and roles — done properly
Keycloak is powerful and famously easy to misconfigure. The value is in the hardening, the realm design, and the offboarding path that actually works.
Single sign-on rollout
One identity across your apps via OpenID Connect and SAML — rolled out app by app, so nothing breaks on day one.
- Realm and client design that scales past app #3
- Laravel, Node, Grafana, GitLab, AWS and more
- Legacy apps fronted by an auth proxy where needed
- Branded login pages your users recognise
Federation & migration
Your existing users come along — federated live or migrated in batches, without a "reset your password" day.
- LDAP / Active Directory federation
- Google Workspace and Microsoft 365 as identity brokers
- Existing user tables migrated with hashes intact
- Staged cut-over: both logins work during transition
- Auth0, OneLogin & AWS IAM Identity Center too
MFA, roles & the audit trail
Policies that match how you work, and the evidence access reviews ask for — produced by the system, not a spreadsheet.
- TOTP, WebAuthn/passkeys, conditional MFA policies
- Role-based access mapped to teams, not favours
- One-click offboarding across every connected app
- Login events and admin actions logged for audits
App by app, without a big-bang cutover
A call, and an honest answer
Twenty minutes on your apps, your directory and what the audit or the last offboarding scare exposed. If SSO is overkill for you, I will say so.
Design the realm, stand it up
Keycloak deployed hardened on your infrastructure, federated with your existing users, MFA policies agreed in writing before anyone logs in.
Connect apps, one at a time
Least-critical first. Each app moves to SSO, gets verified with real users, then the next follows — both login paths work during the transition.
Train, hand over, or stay on watch
Admin training, runbooks and the offboarding drill — then run it yourself, or keep me for upgrades and incidents, month to month.
The questions every team asks
Could you offboard someone in one click?
If the answer is a pause, let's talk. Twenty minutes on your apps and your directory, and an honest answer about whether SSO pays for itself in your setup.