IDPTrust
IDPTrust
idptrust.com

Frequently asked questions about our Keycloak services

We integrate with your existing provider or team to extend capabilities: specialized consulting, ongoing support and maintenance, version upgrades, and custom plugins.

Get started

Book a 30-minute call with a Keycloak architect and receive a free initial assessment.

We define scope, timeline, and risks. If applicable, we run a focused PoC (1–2 weeks).

Support & maintenance

Monthly plans from €290/month: an applicability verdict for every published CVE, security patches, minor upgrades tested in pre-production, and the major version jump included.

Three tiers (Monitoring, Maintenance and All-Inclusive) depending on how much you want to delegate: only assess and document, keep the instance current, or a stable fee with the major version included. Full pricing on the support page.

These are starting prices: the firm price is confirmed after we validate your environment, and they require your Keycloak to run a supported version. If it doesn't, we start with the upgrade.

Plugins & custom SPIs

Licensed plugins that install into your own Keycloak instance: Context-Based Authentication (risk-based access control), User Management (advanced user operations), and Observability (persistent, exportable audit).

It is not a SaaS: the software runs on your infrastructure. When none of them fits, we build the custom SPI you need.

Specialized consulting

Realm configuration and customization, advanced authentication flows with MFA, security audits, and upgrades from legacy versions.

Flexible formats: hours package, fixed-scope project, monthly retainer, or one-time audit.

Keycloak upgrade

Complete 5-phase upgrade: environment assessment, target instance deployment (Quarkus), configuration and data migration, adaptation of themes, emails and custom SPIs with exhaustive validation, and production cutover with a rollback plan.

The service is the version upgrade: migrating data and configuration is part of it, because the database schema changes between versions.

Includes 4 weeks of post-upgrade support, technical documentation, and team training.

Managed operations & DRP

Ongoing maintenance of your instance: controlled upgrades, backups, observability, and incident response.

Disaster Recovery Plan (DRP) with regular drills and evidence reports.

What sets us apart

100% specialized in Keycloak. We don't do identity in general — we do Keycloak, done right.

Enterprise experience in EU/US/LATAM with strict compliance (PCI-DSS, PSD2, ISO 27001).

Frequently asked questions

Do you work with our existing provider/team?
Yes. We integrate with your existing provider/team and extend capabilities without replacing them.
How much does Keycloak support cost?
Our monthly plans start at €290/month and go up to €1,290/month, VAT not included, with a −10% discount for annual payment. These are starting prices: the firm price is confirmed after we validate your environment, and it requires your instance to run a supported Keycloak version. All three plans include an applicability verdict for every CVE and a signed monthly posture report.
Do the support plans have a minimum term?
Monitoring is month to month with no minimum term. Maintenance and All-Inclusive are contracted with a 12-month minimum term, because they include the year's upgrades and — on All-Inclusive — the major version jump prorated into the monthly fee.
What is the difference between a support plan and an hours package?
An hours package is consumed by you when something comes up. A support plan is proactive and has a defined scope: we monitor CVEs and releases, judge which ones actually affect you, plan and test the upgrades, and report every month. It is not an hours package and does not include one.
What is Context-Based Authentication?
A licensed plugin that installs into your instance and evaluates real-time signals (geolocation, IP, device, behavior) against a configurable risk matrix to decide whether to allow, require additional MFA, or block access.
What does the User Management plugin include?
Advanced user management: bulk CSV import/export, filters by attributes, roles, groups, sessions and credentials, bulk actions, automatic deactivation by inactivity, and historical change log.
What does the Observability plugin offer?
Persistent audit in a dedicated database with human-readable descriptions, advanced search, CSV/PDF export, and ready for GDPR, SOC2, and ISO 27001.
What does the Compliance plugin offer?
It audits compliance with OAuth 2.1, FAPI 2.0, and SAML 2.0 security profiles in your Keycloak instance, with the ability to schedule periodic compliance reports.
Do you handle upgrades from legacy Keycloak versions?
Yes, it is a service of its own. Complete 5-phase upgrade: environment assessment, new Quarkus instance, configuration and data migration, adaptation of themes and SPIs with exhaustive validation, and cutover with 4 weeks of post-upgrade support.
Which versions can you upgrade from?
Any version, including very old WildFly-based instances or unsupported databases. We upgrade to the latest stable version on Quarkus with PostgreSQL.
Does the upgrade include data migration?
Yes, and it is part of the upgrade rather than a separate project: the database schema changes between versions. We run it on a mirror environment first, verify the result against the source, and keep a rollback plan for the cutover.
Do you offer 24/7 support?
The published plans cover business hours. If you need 24/7 coverage, on-call rotations or a contractual SLA, we design it for you — tell us about your case.
Can you operate in our infrastructure?
Yes: AWS, Azure, GCP, or on-prem.
Compliance readiness?
Yes. Traceability, logging, separation of duties, and documentation aligned with ISO, PCI-DSS, and internal policies.
Can we start with a security audit?
Yes. We review your instance, validate the configuration against best practices, and deliver a report with prioritized findings and a remediation plan.
What collaboration formats do you offer?
Hours package for specific queries, fixed-scope implementation projects, monthly retainer for ongoing support, or one-time audit and code review.
Do you include team training?
Yes. Hands-on training, full documentation, and knowledge transfer with runbooks.
Typical project timelines?
Audit: 1–2 weeks. Implementation project or full upgrade: 4–6 weeks depending on scope. Retainer: ongoing.
How do plugin licenses work?
Annual license per plugin with support included. They install into your own Keycloak instance: it is not a SaaS and your data never leaves your infrastructure.
SIEM/SOAR integration?
Yes. The Observability plugin exports events that can be integrated with your current security stack.
Do you include instance hardening?
Yes: TLS/HSTS, security policies, brute-force protection, key rotation, and least privilege.
Do you support MFA with FIDO2?
Yes. Keycloak natively includes FIDO2 WebAuthn/Passkeys and OTP (TOTP/HOTP). We configure and optimize these flows in your instance, and our Context-Based Authentication plugin complements them by deciding when to require a second factor based on risk.
Talk to an expert