惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Martin Fowler
Martin Fowler
The Cloudflare Blog
The Register - Security
The Register - Security
WordPress大学
WordPress大学
量子位
Vercel News
Vercel News
C
Check Point Blog
V
Visual Studio Blog
Microsoft Azure Blog
Microsoft Azure Blog
J
Java Code Geeks
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
PCI Perspectives
PCI Perspectives
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
美团技术团队
Schneier on Security
Schneier on Security
O
OpenAI News
M
MIT News - Artificial intelligence
S
Secure Thoughts
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Security Affairs
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
N
News and Events Feed by Topic
大猫的无限游戏
大猫的无限游戏
Google DeepMind News
Google DeepMind News
Recorded Future
Recorded Future
S
Security @ Cisco Blogs
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cyber Attacks, Cyber Crime and Cyber Security
GbyAI
GbyAI
L
LINUX DO - 最新话题
The Last Watchdog
The Last Watchdog
C
CERT Recently Published Vulnerability Notes
aimingoo的专栏
aimingoo的专栏
V
V2EX
博客园 - 【当耐特】
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
阮一峰的网络日志
阮一峰的网络日志

Cerbos - All Posts

Authentik vs Keycloak: Self-hosted IdP comparison Mapping business requirements to authorization policy for automotive Fine-grained authorization for AI gateways EIC 2026: Stop counting agents, protect what they can touch Agent skill for writing authorization policies in Claude Desktop Identity security in 2026 EIC 2026 takeaways: the identity stack built for humans will not hold up for AI agents Already have authentication? Here's the authorization layer you still need. Tokens are authorization decisions: a guide to policy-driven token issuance What is a Runtime Authorization Platform It's a dimmer switch, not a kill switch. How CISOs are rethinking AI agent governance From maps to bitmaps (and from bitmaps to bitmaps) AuthZEN, Shared Signals, SCIM Events, IPSIE: Notes from the OpenID Enterprise Panel How do you update authorization policies without redeploying your application? IIW42 recap: Where agent authorization got real Cerbos PDP v0.52.0/v0.53.0: Engine performance, security hardening, and CEL path functions Authorization Management Platforms: what they do, how they work, and where they fit PocketOS AI coding agent deleted a production database in 9 seconds Non-Human Identity management still has a blind spot Supabase alternative in 2026: Best open source auth options Benefits of on-premise authorization: Why enterprises are moving toward self-hosted Authorization policies: How to write, test, and validate them (faster with AI) Agent skill for writing authorization policies How much does it cost to build authorization in-house? Why centralized authorization governance reduces incident response time OPA alternative Why AI agents make authorization a right now problem Modernizing legacy application authorization: why it’s your biggest security blind spot How to add authorization to legacy applications without code changes 5 authorization blind spots auditors find, and how to fix them Row-level security for Apache Trino, powered by Cerbos Synapse Top 9 Identity & Access Management (IAM) Tools for 2026 Authelia vs Authentik in 2026: Which self-hosted IdP should you choose Can non-engineers manage authorization policies with Cerbos? Governing AI coding agents with Cerbos Synapse Your AI coding agents need guardrails. Not the kind you think From open-source policy engine to enterprise authorization management platform Mapping business requirements to authorization policy for utilities Introducing Cerbos Synapse: unified authorization context and enforcement across your stack The CISO’s guide to implementing Zero Trust: Making adaptive access control work in practice Automating IAM for compliance, security, and business agility Authorization became the main character at Gartner IAM London How does Cerbos help with compliance audits and certifications? Overcoming IAM blind spots and fragmentation for continuous governance How long does it take to implement Cerbos in production? The four pillars of access control in banking When breach becomes personal. CISOs, identity failures and the road to continuous governance Policy as Code with Azure API Management and Cerbos AI is turning weak permission management into systemic banking risk Query plan adapter for Elasticsearch (Java) Query plan adapter for Drizzle ORM 10 fintech security tools to build a compliant and resilient security stack Fine-grained authorization for AI agents with Cerbos and Aperture by Tailscale Query plan adapter for LangChain.js and ChromaDB Fintech security architectures: where they break and why MCP authorization: Securing Model Context Protocol servers with fine-grained access control Cerbos PDP v0.51.0: Policy lifecycle management, audit enhancements, and scopes Query plan adapter for Convex Best open source auth tools & auth software for enterprises [2026] Cerbos Hub Playground: Recent updates Announcing ePDP Rules: Fine-grained control for embedded policy bundles Mapping business requirements to authorization policy for aviation A shared authorization layer that adapts to context What is authorization as a service? Framework for evaluating authorization providers and solutions Cerbos Hub is now available on-premise Authorization as a continuously governed control Year in review: 2025 When authorization is static, risk accumulates silently OpenID AuthZEN is official, and Cerbos is ready MCP and Zero Trust: Securing AI agents with identity and policy 10 critical challenges CISOs face in 2026 and how to solve them AI Security Platforms (AISP): What they are, why they matter, and how they work Cerbos PDP v0.50.0: Stricter CEL, more predictable scope plans, and faster evaluation Cerbos PDP and Cerbos Hub: Choosing the right setup for your team Gartner IAM Summit 2025: Authorization maturity, AuthZEN momentum, and why identity security is expanding to every workload Zero Trust in cybersecurity - how it works Secure RAG: Implement LLM Access Control with Cerbos Cerbos PDP v0.48: OpenID AuthZEN support, improved query plans, faster bundle loading Key compliance regulations for non-human identities How to implement scalable multitenant authorization Key takeaways from Workload Identity Day 0 at KubeCon What is Cerbos? Cerbos vs. OPA Mongoose adapter for Cerbos Query Plans v2.0 Staying compliant - What you need to know Migrating from OPA and Rego to Cerbos Broken access control still tops the list: OWASP top 10 2025 Platform engineering leaders are racing to enable AI safely - takeaways from KubeCon NA 2025 AuthZEN: Standards-based authorization for enterprises What ISC2 congress 2025 made clear about modern compliance Automate Cerbos policy uploads with the cerbos-store-action GitHub Action Mapping business requirements to authorization policy in HR systems Mapping business requirements to authorization policy for insurance Run Cerbos natively inside AWS Lambda Cerbos PDP v0.47.0: AWS Lambda support, Git-aware Hub uploads, and smarter schema diagnostics What is authorization? Types, examples and definitions Building your own authorization solution vs. buying an off-the-shelf one Zero trust has reached operational reality Modern application architecture trends: AI, microservices, and pragmatic security
Keycloak vs ZITADEL for self hosted IAM
S. B. Writer · 2026-06-17 · via Cerbos - All Posts

Keycloak and ZITADEL are identity providers. Both help teams centralize login, single sign-on, multi-factor authentication, and token-based access across applications. The useful comparison is not whether one supports SSO or MFA and the other does not. Both do. The useful comparison is operating model, federation needs, multi-tenancy, upgrade path, and where authorization stops being an IdP problem.

Keycloak is a mature Java-based IAM system often used in enterprise and legacy environments. ZITADEL is a Go-based cloud native IdP with event-sourced audit logs, built-in multi-org concepts, and automation-friendly APIs. If a team needs fine-grained authorization beyond either IdP, Cerbos PDP can sit beside the chosen identity provider.

Short answer

Choose Keycloak when federation with existing directories and enterprise IAM patterns matter most. Choose ZITADEL when cloud native automation, multi-tenancy, predictable upgrades, and a managed option matter more.

Neither tool should be treated as the full authorization layer for complex apps. Keycloak has limited authorization features, and ZITADEL is primarily an IdP. For resource-level permissions, pair either option with a policy decision point such as Cerbos PDP.

Keycloak profile

Keycloak is a self-hosted Java-based identity and access management system. Keycloak focuses mainly on authentication and supports SSO, MFA, social logins, and federation with external identity providers.

Keycloak is commonly used for federation with LDAP, Active Directory, FreeIPA, and Kerberos. It also provides user self-service, admin consoles, REST APIs, container-friendly deployment, and built-in clustering for high availability and scaling.

The trade-off is operational weight. Keycloak can be complex to set up, performance tuning often needs manual configuration, upgrades and custom extensions can take effort, and documentation gaps can slow teams down. Authorization exists, but it is limited to RBAC and resource-based rules with UMA.

ZITADEL profile

ZITADEL is a cloud native identity provider written in Go. It supports SSO, OAuth2, OIDC, SAML, MFA, passwordless login with WebAuthn and FIDO2, hosted login with branding, and both self-hosted and managed SaaS deployment.

ZITADEL uses an event-sourced architecture, so identity operations are stored as immutable events. This supports auditability and replay, but it also means storage growth should be planned. Organizations, projects, and policies can be scoped and branded independently, which makes ZITADEL a stronger fit for multi-tenant setups.

The limitations are specific. ZITADEL does not provide an LDAP interface, only external LDAP login without sync. Apps without OIDC or SAML support may need oauth2-proxy or a similar component. gRPC APIs depend on HTTP/2, and storage is limited to PostgreSQL and CockroachDB.

Keycloak vs ZITADEL comparison

Keycloak and ZITADEL overlap on the basics. Both cover SSO, MFA, and common identity protocols. The differences appear when teams look at existing infrastructure, tenancy model, automation, and day-two operations.

  • Identity protocols Keycloak supports OIDC, OAuth2, and SAML. ZITADEL supports OIDC, OAuth2, and SAML as well.
  • Federation Keycloak is commonly used for federation with LDAP, Active Directory, FreeIPA, and Kerberos. ZITADEL supports external LDAP login, but not LDAP sync or a full LDAP interface.
  • Multi-tenancy ZITADEL has organizations, projects, and scoped policies built into the product model. Keycloak can support complex setups, but scaling clusters or adding federation rules can become operationally complex.
  • Operations Keycloak is stable once configured, but it can be heavy to tune and maintain. ZITADEL has predictable upgrades and avoids extra workers at runtime, which can reduce maintenance overhead.
  • Automation Keycloak provides REST APIs and admin consoles. ZITADEL provides REST and gRPC APIs, SDKs, and an official Terraform provider.
  • Authorization Keycloak includes limited authorization features. ZITADEL focuses on identity. For fine-grained authorization, evaluate a dedicated policy engine.

When to choose Keycloak

Keycloak fits teams that already operate enterprise IAM patterns or need integration with existing directories. It is the safer pick when federation with LDAP, Active Directory, FreeIPA, or Kerberos is a core requirement.

Keycloak also fits teams that want a long-running, widely adopted identity system and are ready to own the operational work. That work can include clustering, performance tuning, upgrade planning, and custom extension maintenance.

The practical warning is simple. Do not choose Keycloak just because it is well known. Choose Keycloak when its federation depth and enterprise fit justify the operational cost.

When to choose ZITADEL

ZITADEL fits teams that want a cloud native IdP with self-hosted and managed options. It is a good match when automation, Terraform, APIs, and predictable upgrades matter.

ZITADEL is also a good match for multi-tenant products. Organizations, projects, and scoped policies are part of the product model, and login pages can be customized and branded.

The practical warning is also clear. Do not choose ZITADEL if LDAP interface support or broad legacy directory integration is the main requirement. In those cases, Keycloak may be the better fit.

Authorization belongs in a separate layer

Authentication answers who is signing in. Authorization decides what that identity can do after sign-in. Keycloak and ZITADEL can issue identity data, but fine-grained authorization across apps, APIs, services, workloads, and agents is a different job.

Cerbos PDP is an authorization engine that works with any IdP. It externalizes policies from application code, supports policy-driven RBAC, ABAC, and PBAC, logs authorization decisions, and is designed for low-latency policy evaluation.

A common pattern is direct. Keycloak or ZITADEL authenticates the user and issues trusted identity claims. The application sends the principal, resource, action, and context to Cerbos PDP. Cerbos PDP returns an allow or deny decision.

Cerbos Hub gives policy operations structure. It is the control plane for policy authoring UI, programmatic policy management, and interactive playgrounds.

Key takeaways

  • Keycloak and ZITADEL both support SSO, MFA, and standards-based identity integration.
  • Keycloak is usually the better fit for enterprise federation and legacy directory environments.
  • ZITADEL is usually the better fit for cloud native teams, multi-tenancy, automation, and predictable upgrades.
  • Keycloak can be heavy to tune, upgrade, and extend.
  • ZITADEL has specific limits around LDAP interface support, app compatibility, and storage options.
  • Cerbos PDP fits beside either IdP when authorization needs to become fine-grained, contextual, and auditable.