I help B2B SaaS teams ship enterprise SAML and OIDC SSO on Keycloak, and turn shaky Keycloak deployments into hardened production systems - without losing a quarter to identity work.
The realm works, but privileged access and token policy create real production risk. The tenant role model will get harder to govern with every enterprise customer you add.
Three situations bring SaaS teams here. Recognize any of them?
A strategic customer requires SAML or OIDC SSO, reliable claims and role mapping, and a credible onboarding plan. You have a deadline, a contract waiting on it, and no identity specialist free to own the implementation.
It works, so nobody has gone back to review admin access, authentication flows, token and session policy, clients, proxy and TLS settings, backups, or upgrade readiness. You do not want the first real review to come from a customer's security team.
Realms, clients, roles, groups and identity-provider mappings grew organically. When a customer asks how tenants are isolated, nobody on the team can answer with confidence.
Here is the honest split - including when not to hire me.
You need to ship fast, want someone else running most of the identity stack, and the managed-service cost works at your connection volume.
You need self-hosting, data residency, flexible federation, deeper customization, or more predictable cost as enterprise connections grow - and you have a realistic plan to operate it.
Authentication is not your product. Hand-rolled OIDC and SAML create security risk and permanent maintenance debt.
The Readiness Audit shows whether Keycloak is viable, where it will fail scrutiny, and what to do next.
Start with the audit when the problem is unclear. Go straight to implementation when the scope and deadline are already defined.
A focused diagnostic review of one Keycloak realm. You get severity-ranked findings, a remediation plan in priority order, and a call where I walk your team through what to fix and why.
I harden an existing Keycloak deployment across privileged access, MFA, authentication protections, token and session policy, client configuration, proxy and TLS posture, and the operational safeguards you need before something goes wrong at 2am.
Implement enterprise SAML or OIDC SSO for your product: two enterprise identity-provider connections, claims and role mapping, a tenant-aware integration approach, testing, and a repeatable process so your team can onboard the next customer without me.
Implementation engagements are fixed price for the agreed scope. If I underestimate that scope, your invoice does not grow. New requirements and out-of-scope work require written approval before they begin.
After implementation, ongoing Keycloak support is available from $2,000/month for operational guidance, troubleshooting, planned maintenance and advisory, with defined monthly capacity and response times. Larger upgrades, new integrations and customer-specific projects are separately scoped.
Three steps from an unclear Keycloak problem to a defensible next decision.
On a 20-minute call we confirm the deadline, what is blocked, and the smallest sensible paid next step. If Keycloak or I am the wrong answer, I will say so.
You receive the agreed scope and invoice. Once payment, intake and access arrangements are complete, the engagement begins. For the audit, you normally provide a sanitized realm export and supporting evidence.
You receive severity-ranked findings, a prioritized remediation path, and a review call. Then your team can move forward with confidence: remediate internally, engage AuthAdvisory, or change direction early.
AuthAdvisory is a specialist Keycloak and enterprise SSO practice. You work directly with the senior engineer responsible for the engagement - no account managers, no junior consultants learning on your stack.
AuthAdvisory operates under an established software company, so engagements are properly contracted, documented and commercially accountable, and built to leave your team in control of the result.
One Keycloak realm, reviewed against production-readiness, enterprise SSO and security criteria. You get severity-ranked findings, a prioritized remediation roadmap and one follow-up call. It does not include production changes, remediation work or coordination with your customers.
For the audit, normally no. It runs on a sanitized realm export plus a short intake. Implementation work is scoped around whatever access model your security team is comfortable with, including pairing with your engineers rather than me holding credentials. NDAs, least-privilege access and secure evidence handling are standard.
First, a short scoping call. If the audit is the right next step, you complete the intake and securely provide the agreed evidence - normally a sanitized realm export and limited supporting information. The report follows 3–5 business days later. Fast Track typically runs 1–3 weeks. Because I take a limited number of engagements at a time, start dates depend on current capacity, which we confirm on the call.
Yes. The full $1,250 comes off a Hardening or Fast Track engagement of $4,500 or more, signed within 30 days of the audit.
Then you have a documented, defensible position for the next enterprise security questionnaire, and you can stop spending attention on it. That is a good result. In practice, a first review almost always surfaces something worth fixing before a customer finds it instead.
A scanner tells you what differs from a default. It cannot tell you whether that matters for your architecture, your enterprise requirements or the way your team operates. The audit is evidence review plus judgement: which findings are material, how severe they really are, and what order to fix them in. Tool output may inform the analysis; it is not the deliverable.
Fair question, and the reason every engagement ends in written handover. The delivered system uses standard Keycloak capabilities and open protocols, with documented configuration, decisions and operating steps. Your production system does not depend on proprietary AuthAdvisory runtime tooling. Engagements are contracted through my software company rather than with me personally, and scoped in short blocks so you are never mid-way through a six-month commitment. Your team retains control of its environments, repositories, credentials and deployment artifacts, so the work can be operated internally or handed to another qualified Keycloak provider.
Yes. The scoping call can help determine whether Keycloak is a credible fit for your requirements. The fixed $1,250 Readiness Audit applies to an existing Keycloak realm; a planned architecture or broader platform evaluation is separately scoped. If a managed platform is the better answer, I will tell you before proposing paid work.
No. Fast Track covers SAML and OIDC SSO with two enterprise IdP connections. SCIM is a separately scoped extension - mention it on the call if a customer is asking for it and I will price it.
The fixed $1,250 audit covers one Keycloak realm. Additional realms, environments, infrastructure or implementation work require separate scope and written approval.
Book a 20-minute Keycloak scoping call. We will confirm what is blocked, the deadline, and the right next step. No technical work begins until the scope is agreed.