Keycloak support & maintenance
A specialist team behind your instance, every month.
We tell you which CVEs actually affect your configuration, apply the patches, and test every upgrade in pre-production before touching production — without depending on someone on your team remembering to check.
We reply within 24 business hours
Need Keycloak support right now?
Production incident, an unpatched CVE or an upgrade stuck halfway? Write to us. We reply within 24 business hours.
Production incident
Logins failing, sessions not holding, federation or SSO broken after a change.
Unpatched CVE
Your Keycloak version carries known vulnerabilities and nobody is tracking the project's security advisories.
Blocked upgrade
An upgrade that failed, a broken theme, or a jump off WildFly nobody dares to touch.
Support & maintenance plans
Monthly billing, fully remote. These are starting prices in euros, VAT not included: the perimeter shown on each plan is indicative and the firm price is confirmed once we validate your environment. All three plans carry a −10% discount for annual payment. If none of them fits your case, we design a plan around it.
Monitoring
We apply no changes: we assess and document. For teams with their own Keycloak admin who need to know what affects them — and be able to prove it in an audit.
VAT not incl.
- Perimeter
- 1 inventoried environment
- SLA · response
- CVE 2 business days · support next business day
What's included
- Automatic inventory of your environment through a read-only service account, with no access to user data
- An applicability verdict for every published CVE: whether it affects you, why, and its real severity in your configuration
- Documented temporary mitigation where one exists, while you plan the upgrade
- Signed monthly posture report: version drift, open CVEs and recommended action
- Valid as evidence of a vulnerability management process for ISO 27001, ENS or end-customer audits
- We apply no patches or upgrades: that starts with the Maintenance plan
A CVE feed is free. Knowing which ones actually affect you, signed off, is not. It is also the only plan that applies if a third party operates your Keycloak.
Request this planMaintenance
The reference plan. Your instance always on the latest version with security support, without your team having to deal with it.
VAT not incl.
12-month term- Perimeter
- 2 environments · 10 critical configurations · 2 customizations
- SLA · response
- CVE 2 business days · support 8 business hours
Everything in Monitoring, plus:
- Security micro-patches applied with priority (e.g. 26.6.2 → 26.6.3)
- Every minor version released, up to 4 upgrade windows per year (e.g. 26.6 → 26.7)
- Upgrade in pre-production first, with a documented go/no-go criterion
- Binary compatibility analysis of your customizations against the target version, before upgrading
- Prior snapshot —run by your systems team, coordinated by us—, tested rollback plan and regression suite over your critical configurations
- Major version jump billed separately
Requires a representative pre-production environment. If you don't have one, we help you set it up so upgrades can be tested safely (billed separately).
Request this planAll-Inclusive
A stable fee with no surprise invoices. The major version jump is prorated into the fee, over the contracted perimeter.
VAT not incl.
12-month term- Perimeter
- 3 environments · 15 critical configurations · 6 customizations
- SLA · response
- CVE 2 business days · support 4 business hours
Everything in Maintenance, plus:
- Major version jump included and prorated, over the contracted perimeter
- Test bench*: we recompile your customizations against every new version before touching anything
- Up to 8 h/year of adaptation* for customizations broken by API changes
- Extended integration testing and federation verification
- Upgrade windows outside business hours at no extra charge
* Test bench and adaptation require you to hand over the source code of the customization. Anything beyond 8 h/year is quoted separately, with a written estimate up front.
Request this plan- These are starting prices: the firm price is confirmed after we validate your environment, and requires your Keycloak to run a supported version.
- Each plan's perimeter (environments, critical configurations and customizations) is what the fee covers. Anything beyond it is quoted separately, always with a written estimate up front.
- All three plans carry a −10% discount for annual payment. Maintenance and All-Inclusive are contracted with a 12-month minimum term; Monitoring is month to month, with no minimum term.
- Not sure which plan fits? We start with a 30-minute call and tell you straight, no strings attached.
- Need 24/7 coverage, a contractual SLA or on-call rotations? Not part of these plans, but we design it for you.
Two conditions before you sign
Starting prices assume a maintainable environment. Keeping an instance current when it is several versions behind — or carries undocumented customizations — is not the same job, so we'd rather say it up front.
Your Keycloak must run a supported version
These plans cover instances on a version the project still supports and reasonably up to date. If you are several versions behind or still on WildFly, we run the upgrade first and the instance moves into ongoing maintenance afterwards.
We validate your environment before quoting a firm price
We review version and database, how it is deployed (containers, Kubernetes, on-premise), custom themes and SPIs, integrations, and the number of realms and clients. That validation is what sets the final plan and price.
The validation is free and comes with no strings attached
It happens on the intro call plus a short technical review. If your environment fits, we confirm the starting price; if it doesn't, we propose the preparatory work with a fixed scope and cost.
Running an outdated instance? Start with the upgrade, then move into a support plan.
See the Keycloak upgrade serviceIncluded in every plan
- Continuous tracking of Keycloak security advisories and releases
- A team that knows your instance, not a ticket in a queue
- Technical documentation for every intervention
- Signed monthly posture report: version drift, open CVEs and recommended action
- Remote support in English and Spanish
- Your deployment, wherever it runs: AWS, Azure, GCP, Kubernetes or on-premise
We work with teams inside and outside Europe
Headquartered in Sevilla (Spain) and fully remote. We support teams in English and Spanish across European, US and LATAM time zones. Your instance and your data stay wherever you decide: Keycloak is open source and runs on your infrastructure, not ours.
Support questions
Why are the prices "from"?
What is a plan's perimeter?
Which Keycloak versions do you support?
What counts as a minor upgrade?
What about the major version jump?
Do the plans include consulting hours?
Is support 24/7?
Do I have to give you access to my instance?
What if a third party operates my Keycloak?
Is there a minimum term?
Can I change plans?
What if I only need one-off help?
Let's talk about your instance
Tell us which Keycloak version you run, how it's deployed and what worries you. We reply within 24 business hours.