An Okta alternative you own

Identity and single sign-on

Single sign-on and multi-factor authentication on Keycloak, with your directory as the source of truth and the identity layer inside your network.

Replace OktaBook a 30-minute briefing

Replacing
Okta, by Okta, Inc.
With
Keycloak
Runs on
Your servers, or Pilae Cloud in Switzerland and the EU
Migration
Included in onboarding, at a fixed price

Why teams leave Okta

The key to every other system

Whoever runs sign-on can open every application behind it. With Keycloak, the identity layer runs on machines you control, in the country you choose.

No per-user bill

Growth is a question of machine size, not of seats. Contractors, students and partner accounts cost nothing extra to add.

Internal applications stay internal

Keycloak answers on your private network, next to your directory. The login page for an internal tool never has to be published to the internet.

Okta vs Keycloak operated by Pilae

What is being comparedOktaPilae
Where identities are heldIn Okta cloud infrastructure, in regional cells that include the EU.On your premises or on dedicated machines in any of 12 Pilae Cloud regions, six of them in Switzerland and the EU. Air-gapped on request.
ProtocolsSAML, OIDC, WS-Federation and SCIM provisioning.OIDC and SAML in the same realm, with LDAP and Active Directory federation.
Ready-made integrationsA catalogue of thousands of pre-built application integrations, set up from the admin console.Any application that speaks OIDC or SAML. We configure and test each client during onboarding.
Multi-factor authenticationOkta Verify push, adaptive policies and a range of other factors.One-time codes, WebAuthn security keys and passkeys, enforced per group or per application.
DirectoryUniversal Directory, with agents to sync Active Directory and LDAP.Your Active Directory, LDAP or Entra ID stays the source of truth. Keycloak federates it or brokers to it.
Pricing modelPer user per month, by product.On request, for the operated platform. No charge per user.
OperationFully run by Okta as a SaaS product.Upgrades planned by the Pilae Agent and tested against a copy of your realm, verified backups, 60-second probes and alerts that reach Pilae engineers around the clock.

Self-hosted single sign-on

Okta is a mature identity platform with a large catalogue of ready-made integrations. It also means the service that decides who may open every application runs on someone else’s infrastructure and is billed per user.

Keycloak covers the core of what most organisations use Okta for: single sign-on over OIDC and SAML, multi-factor authentication with passkeys and security keys, and federation with the directory you already have. The difference is where it runs. Pilae deploys it on your premises or on dedicated machines in Switzerland and the EU, and it answers only on your private network. Where data sits is set out on our data residency page.

Keycloak, operated for you

A self-hosted identity layer has to be more reliable than anything behind it. We run Keycloak with Postgres, clustered where your plan calls for it, with daily encrypted backups and a restore test every month. The Pilae Agent plans each upgrade, tests it against a copy of your realm, waits for your approval and applies it in your window.

Our identity service moves your applications across one by one, whether you land on Keycloak alone or keep Entra ID as the directory. Pricing is on request and has no per-user component. Tell us what signs in through Okta today.

Moving from Okta to Keycloak

  1. List the applications that sign in

    Every SAML and OIDC application configured in Okta, with its attribute mappings and group rules. The list in the console is the starting point, the sign-in logs say which ones are live.

  2. Connect the directory

    Keycloak federates your Active Directory or LDAP, or brokers to Entra ID. Where the directory holds the passwords, users keep the one they already have.

  3. Move applications one at a time

    Each application is pointed at Keycloak and tested with real accounts from each group. Okta stays live for the rest until the last one has moved.

  4. Enrol second factors, then end the contract

    Users enrol a new second factor at their next sign-in. When the Okta logs show no more traffic, the subscription ends.

The app that replace Okta

Questions

Is Keycloak open source?

Yes. Keycloak is licensed under Apache-2.0 and is a Cloud Native Computing Foundation project. There is no paid edition with features held back.

Can we move user passwords out of Okta?

Okta does not generally hand out password hashes. If your directory holds the passwords, nothing changes for users. If Okta was the only store, users set a new password on first sign-in to Keycloak, and we plan that step with you so it happens by group rather than all at once.

Does Keycloak do SCIM provisioning to SaaS apps?

Not out of the box. Since release 26.7, Keycloak has a SCIM API, still in preview, for receiving users and groups from another system such as Entra ID or an HR platform. Pushing accounts into SaaS apps is not built in: it is done through the directory, through the application's own sync, or through an extension where one fits. We map this for every application during onboarding and tell you where it needs a different answer.

Can we keep Microsoft Entra ID?

Yes. Keycloak can broker to Entra ID, so Microsoft stays the directory while the applications you run yourself sign in through Keycloak on your own network. Our identity service covers both set-ups.

What happens to our identity setup if we leave Pilae?

Your realm is exported to a file in your repository, with the compose files and the runbook. Rebuilding it elsewhere is an import.

Also replaced: 1Password, Airtable, Calendly, ChatGPT Enterprise, Google Drive, HubSpot CRM, Jira, Make, Microsoft 365, Microsoft 365 Copilot, Notion, Retool, SharePoint, Slack, Tableau, Microsoft Teams, Zapier.

Leave Okta with a plan, not a weekend.

An inventory of what you actually use, the app that replaces it, and a fixed price for the move.