Identity that ships at your pace.
A polished admin console, a TypeScript SDK, a Terraform provider, and true config-as-code. Realms, clients, and flows are versioned like the rest of your stack — reviewed in a PR, applied in CI.
A console people enjoy
A modern, Keycloak-class admin console covers realms, applications, users, roles, sessions, flows, keys, and events — clear enough to hand to non-experts.
- Realms, apps, users, roles, groups
- Visual auth-flow editor
- Sessions, events & audit
- Health & observability dashboard
SDKs & quickstarts
Wire login in minutes with the official TypeScript SDK and framework adapters. A 5-minute quickstart gets you from zero to a working flow.
- Official TypeScript SDK
- Framework adapters
- 5-minute quickstart
- OpenAPI + Swagger UI
Identity as code
Declare everything. The Terraform provider and full config-as-code import/export make realms reproducible across dev, staging, and prod — with env-var secrets.
- Terraform provider (IaC)
- Config-as-code (import/export)
- Env-var secret substitution
- Drop-in realm folder loader
Migrate off Keycloak
A Keycloak importer brings your realms, clients, and users across, and SCIM 2.0 keeps downstream systems in sync. No big-bang cutover.
- Keycloak realm importer
- SCIM 2.0 (in & out)
- Dynamic client registration
- Bulk user import
See HelixIAM on your own stack.
A 30-minute demo: realms, agents, workload identity, and a live migration off Keycloak — mapped to your use case.
No credit card. Self-hostable. Engineered in Europe.