Single sign-on and multi-factor authentication on Keycloak, with your directory as the source of truth and the identity layer inside your network.
- Replacing
- Okta, by Okta, Inc.
- With
- Keycloak
- Runs on
- Your servers, or Pilae Cloud in Switzerland and the EU
- Migration
- Included in onboarding, at a fixed price
Why teams leave Okta
The key to every other system
Whoever runs sign-on can open every application behind it. With Keycloak, the identity layer runs on machines you control, in the country you choose.
No per-user bill
Growth is a question of machine size, not of seats. Contractors, students and partner accounts cost nothing extra to add.
Internal applications stay internal
Keycloak answers on your private network, next to your directory. The login page for an internal tool never has to be published to the internet.
Okta vs Keycloak operated by Pilae
| What is being compared | Okta | Pilae |
|---|---|---|
| Where identities are held | In Okta cloud infrastructure, in regional cells that include the EU. | On your premises or on dedicated machines in any of 12 Pilae Cloud regions, six of them in Switzerland and the EU. Air-gapped on request. |
| Protocols | SAML, OIDC, WS-Federation and SCIM provisioning. | OIDC and SAML in the same realm, with LDAP and Active Directory federation. |
| Ready-made integrations | A catalogue of thousands of pre-built application integrations, set up from the admin console. | Any application that speaks OIDC or SAML. We configure and test each client during onboarding. |
| Multi-factor authentication | Okta Verify push, adaptive policies and a range of other factors. | One-time codes, WebAuthn security keys and passkeys, enforced per group or per application. |
| Directory | Universal Directory, with agents to sync Active Directory and LDAP. | Your Active Directory, LDAP or Entra ID stays the source of truth. Keycloak federates it or brokers to it. |
| Pricing model | Per user per month, by product. | On request, for the operated platform. No charge per user. |
| Operation | Fully run by Okta as a SaaS product. | Upgrades planned by the Pilae Agent and tested against a copy of your realm, verified backups, 60-second probes and alerts that reach Pilae engineers around the clock. |
Self-hosted single sign-on
Okta is a mature identity platform with a large catalogue of ready-made integrations. It also means the service that decides who may open every application runs on someone else’s infrastructure and is billed per user.
Keycloak covers the core of what most organisations use Okta for: single sign-on over OIDC and SAML, multi-factor authentication with passkeys and security keys, and federation with the directory you already have. The difference is where it runs. Pilae deploys it on your premises or on dedicated machines in Switzerland and the EU, and it answers only on your private network. Where data sits is set out on our data residency page.
Keycloak, operated for you
A self-hosted identity layer has to be more reliable than anything behind it. We run Keycloak with Postgres, clustered where your plan calls for it, with daily encrypted backups and a restore test every month. The Pilae Agent plans each upgrade, tests it against a copy of your realm, waits for your approval and applies it in your window.
Our identity service moves your applications across one by one, whether you land on Keycloak alone or keep Entra ID as the directory. Pricing is on request and has no per-user component. Tell us what signs in through Okta today.
Moving from Okta to Keycloak
List the applications that sign in
Every SAML and OIDC application configured in Okta, with its attribute mappings and group rules. The list in the console is the starting point, the sign-in logs say which ones are live.
Connect the directory
Keycloak federates your Active Directory or LDAP, or brokers to Entra ID. Where the directory holds the passwords, users keep the one they already have.
Move applications one at a time
Each application is pointed at Keycloak and tested with real accounts from each group. Okta stays live for the rest until the last one has moved.
Enrol second factors, then end the contract
Users enrol a new second factor at their next sign-in. When the Okta logs show no more traffic, the subscription ends.