One login · every app

One password. Every app. Zero forgotten accounts.

I implement Keycloak on your infrastructure: single sign-on across the tools your team lives in, MFA where it matters, roles instead of favours — and when someone leaves, one click ends their access everywhere.

Open source, no per-user feesYour servers, your dataAudit-friendly by design
sso.yourcompany.com reference flow
role: finance · session 8h
Grafana
GitLab
ERP
AWS
offboarding: 1 account disabled → 4 apps revoked, instantly
Why this exists

Access sprawl is a breach with patience

Every app with its own passwords is another place accounts outlive employees, another admin nobody remembers granting, another line in the audit findings.

Ten apps, ten passwords

Every tool has its own login, so people reuse passwords and share accounts — and support spends its mornings on resets.

Offboarding by memory

Someone leaves, and access removal becomes a checklist from memory. The account everyone forgot still works — quarterly access reviews find it, or worse, an incident does.

"Who has access to what?"

The auditor's first question, and today the answer is a spreadsheet nobody trusts. Role-based access exists in policy, not in software.

What I do

SSO, federation and roles — done properly

Keycloak is powerful and famously easy to misconfigure. The value is in the hardening, the realm design, and the offboarding path that actually works.

Single sign-on rollout

One identity across your apps via OpenID Connect and SAML — rolled out app by app, so nothing breaks on day one.

  • Realm and client design that scales past app #3
  • Laravel, Node, Grafana, GitLab, AWS and more
  • Legacy apps fronted by an auth proxy where needed
  • Branded login pages your users recognise

Federation & migration

Your existing users come along — federated live or migrated in batches, without a "reset your password" day.

  • LDAP / Active Directory federation
  • Google Workspace and Microsoft 365 as identity brokers
  • Existing user tables migrated with hashes intact
  • Staged cut-over: both logins work during transition
  • Auth0, OneLogin & AWS IAM Identity Center too

MFA, roles & the audit trail

Policies that match how you work, and the evidence access reviews ask for — produced by the system, not a spreadsheet.

  • TOTP, WebAuthn/passkeys, conditional MFA policies
  • Role-based access mapped to teams, not favours
  • One-click offboarding across every connected app
  • Login events and admin actions logged for audits
How it works

App by app, without a big-bang cutover

1

A call, and an honest answer

Twenty minutes on your apps, your directory and what the audit or the last offboarding scare exposed. If SSO is overkill for you, I will say so.

Day 0
2

Design the realm, stand it up

Keycloak deployed hardened on your infrastructure, federated with your existing users, MFA policies agreed in writing before anyone logs in.

Week 1
3

Connect apps, one at a time

Least-critical first. Each app moves to SSO, gets verified with real users, then the next follows — both login paths work during the transition.

Weeks 2–4
4

Train, hand over, or stay on watch

Admin training, runbooks and the offboarding drill — then run it yourself, or keep me for upgrades and incidents, month to month.

Ongoing
Before you ask

The questions every team asks

Keycloak is my default recommendation because it is open source, has no per-user fees and keeps identity data on your own servers — but it is not the only tool I work with. I implement and migrate between Auth0, OneLogin and AWS IAM Identity Center (the former AWS SSO) as well. If a managed provider fits your team better, that is what I will recommend; the SSO, MFA and offboarding principles on this page apply to all of them.

Less than you fear, if it is staged. Keycloak federates against what you already have (LDAP, Active Directory, a users table, Google Workspace), so accounts keep working while apps move to SSO one at a time. Users notice a nicer login page, not a migration.

Anything that speaks OpenID Connect or SAML — which today means most things: Laravel, Node, Java and .NET apps, Grafana, GitLab, Nextcloud, AWS SSO, and hundreds more. Legacy apps that speak neither can often be fronted by a proxy that handles the login for them.

Yes. TOTP apps, WebAuthn/passkeys and recovery codes are all supported, and policies are per-realm, per-role or conditional — for example, MFA required for admins and finance, optional for everyone else, or enforced only on logins from new devices.

One disable in Keycloak (or in the upstream directory it federates) ends their access to every connected app at once. That single point of deprovisioning is usually the strongest argument for SSO — offboarding stops being a checklist of forgotten accounts, which is exactly what access-control audits look for.

It runs on your infrastructure — a VM, container or cluster in your cloud or server room — sized and configured for high availability when uptime matters, because if the login service sleeps, everything sleeps. I set it up, harden it, keep it patched, and document the recovery path.

Yes. Handover includes realm documentation, admin training and runbooks for the routine tasks — adding an app, adjusting a policy, resetting MFA. Keep me on a monthly arrangement for upgrades and incidents, or take it fully in-house; month-to-month either way.

Could you offboard someone in one click?

If the answer is a pause, let's talk. Twenty minutes on your apps and your directory, and an honest answer about whether SSO pays for itself in your setup.