Skip to main content
🇩🇪GDPR-compliant
Find the right

Keycloak Experts in Germany

for secure identity systems, matched in minutes with vetted freelance professionals

Hire experts who secure applications with Keycloak, design SSO and OAuth 2.0 integrations, and connect identity flows across cloud and enterprise systems. FRATCH matches you quickly and precisely with vetted, available freelancers who fit your technical needs.

Meet FRATCH Experts in Germany, who have recently used Keycloak

Verified expert

Kiriakos K.

View profile

Platform Engineering Tech Lead / Architect

Nickenich
Kiriakos K.

Last position:

Tech Lead / Architect : OTTO API Platform at OTTO

Maturing their API practices on both a business and technology level. My role covers strategy, architecture, developer advocacy as well as hands-on software engineering, enabling both technical teams and business leadership to adopt and act on API-centric principles effectively. Coincidentally, we also establish GitOps, DX and platform best practices with this project.

Highlights:

  • Aligning executives with the initiative by clarifying strategy, replacing misconceptions and myths with facts, clarifying the value of existing assets and enabling informed decision-making
  • Formulating a way forward for API Lifecycle Management at OTTO
  • Driving platform progress and fostering developer engagement by hands-on engineering work towards strategic goals

API Lifecycle Management, Team Topologies, Organizational Evolution, Regulatory, Platform Advocate, Developer Platform, Communities of Practice, Terraform, Kotlin, Kafka, Kong, WSO2, Apigee, Gravitee, Backstage, AsyncAPI, OpenAPI, API Design, AWS, React, Node.js, TypeScript, Redocly, reactive programming, CDC, Golang, Gin, GitOps, DX (developer experience), stakeholder management, roadmaps, workshops, discovery.

Verified expert

Shamaila M.

View profile

Senior Software and Platform Architect

Heilbronn
Shamaila M.

Last position:

Founder/Kubernetes and Cloud Architect at Kubekanvas

  • Developed a browser-based platform for Kubernetes no-code deployment and cluster management
  • Developed a CLI in TypeScript to deploy resources in the cluster without leaving the browser UI.
  • Implemented DevSecOps pipelines: image scanning, SBOM, policy enforcement, supply-chain security, and used Kyverno. Implemented IAM integration for the command-line utility tool.
  • Designed role and permission models for Keycloak, OAuth/OIDC, and social login flows.
  • Used LLMs to convert user intent into diagrams.
  • Worked on integration with multiple sovereign clouds like StackIT, Hetzner, CIVO, UpCloud, plus public clouds like AWS, GCP, and Azure
  • The technology stack includes Java, Spring Boot, Kubernetes, OpenAI, Kubernetes multi-tenancy using vCluster, Karpenter, RBAC for CLI, Helm, React
Verified expert

Karen M.

View profile

Senior .NET Backend Engineer | Applied AI | Agentic Systems, RAG & Distributed Architecture

Munich
Karen M.

Last position:

Personal AI Engineering Project — Croky AI at Crocky AI

Product:

  • Built a production-ready AI platform for generating brand-aware marketing images and videos from product data, user requirements, and uploaded media.
  • Own the platform architecture, technical roadmap, API design, security, deployment workflow, operational reliability, and model-provider strategy.
  • Developed the core platform in .NET and built supporting AI and workflow prototypes in Python, applying language-independent API contracts and structured interfaces between services and model providers.
  • Implemented reliable background processing with RabbitMQ, persisted workflow state, idempotent handling, retries, failure recovery, logging, secure storage, authorization, and credit accounting.
  • Made pragmatic build-versus-buy and model-routing decisions based on reliability, latency, cost, and maintainability rather than novelty.

Agent Orchestration & RAG Systems

  • Built and compared agent workflows using Microsoft Agent Framework, LangGraph, and LangChain, including tool use, conditional routing, clarification steps, state management, and hand-offs between agents.
  • Implemented reusable .NET components for agents, prompts, tools, model providers, structured responses, and retrieval with pyvector, making it easier to change AI providers without rewriting the core workflow.
Verified expert

Christoph T.

View profile

Architect, Business Analyst, Developer

Magdeburg
Christoph T.

Last position:

Backend Software Developer (Java) at German Football Association (DFB) e. V.

  • Client: Prime Force Group GmbH

Technologies used: Java 25, Spring Boot 4, MapStruct, JSpecify, PostgreSQL, Redis, Liquibase, REST/OpenAPI, Apache Kafka, Apache Solr, OpenID Connect via IronGate/Keycloak, SAP Customer Data Cloud, JUnit, Testcontainers, Karate, Playwright, GitLab monorepo with CI/CD, Jenkins, JFrog Artifactory, FluxCD, Docker, Kubernetes on Azure, OpenTelemetry, arc42, Jira, Confluence

The Team Management Center is the new central platform of the DFB for planning, managing, and carrying out team activities for the national teams - from squad selection and training camps to communication with players, clubs, and legal guardians. The platform is designed for multi-tenancy for the DFB and regional associations; player, club, and master data are intentionally not copied, but connected at runtime via the DFBnet APIs.

I have been involved in the project continuously since the architecture and concept phase (Sprint 0) and work in a distributed Scrum team in two-week sprints. In addition to implementation, my focus is on architecture alignment, connecting the DFBnet interfaces, as well as code reviews and test automation as quality assurance in the team.

Focus areas:

  • Development and implementation of the multi-tenancy concept (tenant model for the DFB and regional associations), including data model, access layer, and Liquibase migrations.
  • Design of the person service and the search concept based on Apache Solr.
  • Integration of the DFBnet APIs (player, person, and club search, club data), including authentication and synchronous master data synchronization.
  • Hardening the integration through resilience patterns: separate read timeouts for each search path, correction of circuit breaker counting, limiting parallel requests, and a club cache to reduce load on the external system.
  • Development of self-service endpoints for players (own activities, activity details, games), including an access concept for participants, as well as person documents and file uploads.
  • Standardization of API design: OpenAPI annotations, nullability model via a custom ModelConverter, JSpecify migration of the DTOs, and documented API guidelines.
  • Build and maintenance of Karate-based API and integration tests, integration tests with Testcontainers, test guidelines, and bug triage from the integration and reference environments.
  • Code reviews via merge requests, architecture documentation according to arc42, and architecture decisions (ADRs) in Confluence.
  • Automated deployment to the integration and reference environments, analysis of login and OIDC issues in combination with IronGate.

Status: ongoing - as of 08/2026 in Sprint 17, around 940 person hours worked; testable delivery to the integration environment every two weeks.

Verified expert

Boris S.

View profile

Senior Software Developer

Ratingen
Boris S.

Last position:

Generalist expert for software development at Mercor

  • Training AI models, evaluating images and text UI/UX, turning the provided data into insights through OpenAI Feather as part of the machine learning workflow

Technologies: OpenAI Feather

Verified expert

Osman T.

View profile

Senior Developer and Consultant

Aschaffenburg
Osman T.

Last position:

Senior Architect, DevOps Engineer at genPsoft GmbH

IT consulting, analysis, architecture design, new and further development, code review, test automation, continuous integration, continuous delivery in backend and frontend areas for Automotive Project Instavalo.

Frontend:

  • Implementation of UI components according to specifications, especially style guides and responsive design eith React and Typescript
  • Component testing
  • Code documentation
  • CI/CD with Gitlab Pipeline

Backend / IoT:

  • Analysis and architectural design with AWS Greengrass IoT on Edge Devices
  • Setting up Microservices containers with Docker Compose on Edge device with AWS Greengrass and AWS IoT IAM, Token Exchange Service, Ansible
  • CI/CD with Gitlab Pipeline, Terraform, AWS ECR
  • Logging with Fluentbit Lua Language for AWS Cloudwatch
  • Python Lambda for AWS Greengrass Recipe deployment on Edge Devices
  • Implementation of test-driven development with JUnit, Mockito, and code Coverage
  • Jacoco
  • Definition of REST interfaces with OpenAPI / Swagger
  • Development and enhancement of software based on Java Quarkus, Typescript NestJs NodeJs and Python
  • Authentication and authorization in Aws IAM
  • Development of REST and gRPC interfaces for the frontend and backend
  • Implementation of Maven dependencies with DevSecOps OWASP
  • Spring AI, Jetbrains AI Assistant, Junie, Github Copilot, Claude Code, Agents, Skills, Command, Hooks, Subagents
Verified expert

Frédéric K.

View profile

IT Consultant, Architect, Full Stack, DevOps

Walpertskirchen
Frédéric K.

Last position:

Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA

  • Short description: Lead a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations control while preserving the autonomy of decentralized business units within regulatory boundaries.

  • Tasks and activities:

  • Overall responsibility for the design, setup, and implementation of an enterprise-wide cloud governance structure (Azure), incl. target picture, roadmap, and operating model.

  • Management of internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps) incl. decision-making and escalation management.

  • Planning and facilitation of workshops on cloud strategy, governance principles, and the design of areas such as Identity, Connectivity, and Platform Management.

  • Definition, implementation, and rollout of cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).

  • Building a cloud governance framework aligned with the Azure Cloud Adoption Framework (CAF), incl. landing zone and guardrail concepts.

  • Introduction of automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).

  • Implementation of cloud security and compliance monitoring mechanisms as well as continuous improvement processes.

  • Establishment and operationalization of FinOps in an enterprise environment (central and decentralized FinOps teams), incl. cost management strategies, reporting, and guardrails.

  • Integration of governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).

  • Implementation of access concepts incl. RBAC design and "break glass" mechanisms (emergency access) as well as certificate automation (ACME / step-ca).

  • Achievements:

  • Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud usage in a regulated environment.

  • Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risks.

  • Improved operational and decision-making capabilities across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).

  • Significantly increased workload compliance for lift-and-shift migrations.

  • Technologies used:

  • Microsoft Azure Policy, custom policies.

  • Terraform, OpenTofu, Terragrunt.

  • step-ca (ACME).

  • Entra ID.

  • Azure Firewall.

  • Azure networking, hub-and-spoke architecture.

  • Azure vWAN (evaluation).

  • Azure Front Door, Azure Application Gateway.

  • Azure ExpressRoute.

  • Azure Key Vault.

  • NetBox.

  • GitLab (on-premises).

  • Infrastructure, concepts used:

  • Cloud shared responsibility model.

  • Hub-and-spoke connectivity / central shared services (from a hub-spoke context).

  • Central governance with decentralized delivery (business unit autonomy with guardrails).

  • Methods used:

  • Scrum.

  • Stakeholder management (C-level to engineering).

  • Cloud governance, Azure Cloud Adoption Framework (CAF).

  • DevOps, CI/CD.

  • Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.

  • RBAC, "break glass" concepts.

  • ACME / certificate automation.

  • GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.

Verified expert

Sercan T.

View profile

Certified Professional for Software Architecture Foundation Level

Esslingen am Neckar
Sercan T.

Last position:

Co-Founder & Lead Software Architect at Pflege-Pfad

  • Focus: system architecture, cloud-native platforms, microservices, API design
  • Product: Pflege-Pfad is a digital matchmaking platform that connects relatives of people in need of care directly with verified care services and caregivers - without an agency and without ongoing fees.
  • Business analysis & process design:
  • Analysis of the German care market and identification of the key pain points of both target groups.
  • Modeling of the core business processes: registration, verification, care request, application, placement, and rating.
  • Definition of the business model as a freemium/premium model with optional contact unlocking.
  • Creation of user stories and requirements documentation for relatives, care services, and administrators.
  • Design of trust and quality assurance mechanisms with document upload, admin review process, and rating system.
  • Coordination with stakeholders and validation of product decisions with potential users.
  • Technical implementation:
  • Design and implementation of the entire platform architecture as a solo developer.
  • Design and implementation of a REST API with Spring Boot and Kotlin, including JWT-based authentication.
  • Development of the frontend as a single-page application with Angular 17.
  • Implementation of the AWS infrastructure with EC2, RDS PostgreSQL, S3, CloudFront, and IAM.
  • Document upload with AWS S3 via presigned URLs for verification of care services.
  • Email notifications via Resend API.
  • AI-supported care service search via OpenAI API.
  • Implementation of complete user flows such as registration, login, password reset, and placement process.
  • Building an admin panel for user and care service management as well as analytics.
  • CI/CD with GitHub Actions and containerized deployments with Docker.
  • End-to-end tests with Playwright.

Technologies: Kotlin, Spring Boot 3, Spring Security, JWT, JPA/Hibernate, PostgreSQL, Angular 17, TypeScript, RxJS, AWS (EC2, ECS, S3, CloudFront CDN, RDS PostgreSQL, IAM), nginx, GitHub Actions, Playwright, Maven, Git, OpenAI API, Resend API, Docker, Scrum, i18n (DE/EN/TR), Kiro, feature-flag architecture.

Verified expert

Julius H.

View profile

Freelancer

Berlin
Julius H.

Last position:

Freelancer at Freelancer — Pharma Industry

  • Led migration to GCP using Terraform, GKE, and GitOps, improving deployment consistency and scalability
  • Implemented Datadog observability stack via Terraform and datadog-operator
  • Established automated end-to-end tests and on-call processes, improving incident response and service reliability
  • Migrated from NGINX Ingress Controller to Kubernetes Gateway API (NGINX Gateway Fabric)
  • Migrated stateful services (PostgreSQL and Redis) to GCP, improving scalability and operational reliability
Verified expert

Salim C.

View profile

Cloud / Systems Architect

Stuttgart
Salim C.

Last position:

Cloud / Systems Architect

  • Development and introduction of operations processes
  • Preparation of complete documentation packages (including incident management and operations support) to meet compliance requirements
  • Introduction of a workshop on IaC (Infrastructure as Code)
  • Technical consulting for the project security concept (ISMS)
  • Installation and operation of Kubernetes clusters on AWS, on-prem, and Azure
  • Hybrid cloud architecture design (on-prem, Hetzner, AWS)
  • Analysis and troubleshooting of incidents and system outages
  • Network adjustments for firewall rules, gateways, OpenVPN settings, and IPsec tunnels (pfSense)
  • Technical consulting on Bitbucket, Jenkins, and GitLab CI/CD pipelines
  • Consulting on Ansible deployments and infrastructure automation
  • Consulting on building a scalable system in the cloud (AWS / Azure)
  • Technologies / Tools: Ansible, Terraform, AWS, Azure, VPN, pfSense, Jenkins, Bitbucket, Kubernetes, GitLab Runner, ISMS, Golang, Prometheus, Grafana, S3, Lambda, RDS, ECS, Cognito, OIDC, Harbor, MinIO, Postgres, Redis, Keycloak, Ceph, Proxmox, CloudFormation, PostgreSQL, Flux CD, Hetzner, IONOS, Sonatype Nexus Repository, Entra ID, Dex IdP, Pulumi
Verified expert

Tamás E.

View profile

Senior Software Developer / Tech Lead

Munich
Tamás E.

Last position:

Senior Software Developer / Tech Lead at NDA (defense / OSINT)

  • Designing the audit logging framework
  • Implementing APIs for developers to integrate in their codebase
  • Implementing ingestion pipeline, database query layer and UI for browsing the audit events
  • Improving stability and reliability of the backend system
Verified expert

Arkadius S.

View profile

Senior Java Backend Developer | API & Integration Development | Cloud-Native Microservices | Regulated & KRITIS-Related

Dortmund
Arkadius S.

Last position:

AWS Pricing Platform / API & Integration Architecture at Porsche Digital

Development and evolutionary further development of a highly available, cloud-native microservice and integration architecture for dealer and retail processes in the Porsche Car Configurator.

Responsibilities

  • Development of Java-/Kotlin-based backend, API, and integration components (Spring Boot)
  • Integration of internal and external systems via REST/OpenAPI, GraphQL, Apache Kafka, and AWS SQS (synchronous and asynchronous)
  • Implementation of stable, high-performance communication and data flows in a cloud-native platform architecture
  • Processing of structured data formats (JSON, Protobuf, GraphQL schemas) based on existing API patterns
  • Performance optimization of distributed microservices with reduced response times and higher operational stability
  • Technical tests (unit, integration, and API tests) as well as error analysis in production-like environments
  • AWS Infrastructure as Code with Terraform and AWS CDK
  • CI/CD automation (build, test, and deployment pipelines) with GitHub Actions
  • AI-supported feature implementation (GitHub Copilot Agent)

Label: Kotlin, Java 25, Spring Boot 4, Protobuf, TypeScript, AWS, Terraform, CDK, Apache Kafka, AWS SQS, REST/OpenAPI, GraphQL, JSON, PostgreSQL, Docker, GitHub Actions, Maven, Gradle, JUnit, Mockito, Testcontainers

Verified expert

Ramazan C.

View profile

Lead Software Engineer AI-Data Enthusiast

Mainz
Ramazan C.

Last position:

Fullstack-/DevOps Engineer at BKA (Federal Criminal Police Office)

Development and further development of an internal platform for managing and providing technical resources, virtual machines, and infrastructure services. The platform supports self-service processes and covers functions that are conceptually comparable to cloud management solutions like Azure or AWS.

  • Responsible involvement in the design, development, and implementation of new backend and frontend features
  • Hands-on development with Java, Spring Boot, Python, and Angular
  • Implementation of REST interfaces, business logic, validations, and integrations into existing system landscapes
  • Further development of modern web interfaces with Angular, including connection to backend services
  • Participation in architecture and design decisions within the team, especially with regard to scalability, maintainability, and clean interfaces
  • Containerization and deployment of applications with Docker, Kubernetes, and Helm
  • Support with CI/CD processes and deployment to Kubernetes-based environments
  • Work in the environment of vSphere, Broadcom, GitLab CI/CD, ArgoCD, Maven, npm, and NuGet
  • Close collaboration with developers, business teams, DevOps, and other technical stakeholders
  • Analysis of technical requirements, deriving suitable solutions, and independent implementation in an agile team
  • Use of GitHub Copilot to support code generation, refactoring, test case creation, and technical documentation

Methods/ tools/ technologies: Languages & frameworks: Java (21), Spring Boot (4.x), Python, Angular, Robot Framework, Kubernetes, Helm Persistence: PostgreSQL, MongoDB, Hibernate, Liquibase Architecture & communication: REST, gRPC, GraphQL, Apache Kafka, OpenAPI, Microservices, Event Driven, Domain Driven Design Cloud & infrastructure: Terraform, Docker, Rancher, Helm, Ansible Security: OAuth2, MS (Entra ID), web security, Keycloak (extensions for detailed group rights) DevOps: GitLab CI/CD, Ansible, Maven, Gradle, Grafana, Prometheus, Git, GitHub Copilot Testing & QM: JUnit, Robot Framework, automated component and integration tests, E2E tests with Playwright, Testcontainers, EasyMock Methodology & approach: Kanban, JIRA, Confluence, Clean Code

Verified expert

Stanley A.

View profile

Senior AI Engineer | LLMs, RAG & Agent Systems

Stanley A.

Last position:

Senior AI Engineer & Technical Lead at Independent / Freelance

  • TrendReel, production LLM agent and RAG system (Python, LangChain, OpenAI, Groq/Llama 3, Claude, FastAPI, Kubernetes, PostgreSQL).
  • Designed and built a production multi-step LLM agent system: a script generation agent with a per-platform psychology database, 7 viral narrative frameworks, and structured quality scoring, switching between Claude and Groq backends in real time based on output metrics.
  • Implemented multi-provider LLM routing (Claude primary, Groq/Llama 3 fallback) with priority-chain failover and quality-based provider switching, achieving 95% inference cost reduction while holding measurable quality thresholds.
  • Built an advanced RAG-style retrieval pipeline with per-platform knowledge bases, semantic content matching, and structured output evaluation across 7 decision frameworks, directly analogous to multi-tenant context-based reasoning for enterprise document workflows.
  • BrainyAI, adaptive AI learning platform (Python, LangChain, Groq Llama 3.3-70B, OpenAI, Next.js, Supabase, Redis).
  • Integrated Groq Llama 3.3-70B with education-level-aware prompting, dynamically adjusting vocabulary depth, citation complexity, and reasoning style across four student proficiency tiers.
  • Nexus Prime, multi-tenant SaaS platform for marketing and growth automation (25 modules, 99 backend routers, 153 frontend files).
  • Built a 25-module, 99-router multi-tenant SaaS platform covering ad remix, affiliates, WhatsApp inbox, email, and cart recovery, serving four subscription tiers from $199 to $1,999 per month with integrated Stripe, Paystack, and Flutterwave billing.
  • AI Video Surveillance Platform, multi-tenant edge and cloud computer vision system currently in active client pitch.
  • Designed a multi-tenant AI video surveillance platform combining edge YOLO26 inference on NVIDIA Jetson Orin NX boxes with a central GKE cloud layer (Postgres, Pub/Sub, ClickHouse, R2, Keycloak) for event storage, dashboards, alerting, and multi-tenancy.

Discover over 15,000 top freelancers

Statistics of experts using Keycloak

Aggregated from the professional profiles of matched freelancers.

Experience

18 years

Keycloak experts in Germany have 18 years of professional experience on average.

Position duration

1.7 years

Keycloak experts in Germany stay in a single position for 1.7 years on average.

Positions per freelancer

14

Keycloak experts in Germany have completed 14 positions on average over the course of their careers.

Top business areas

Information Technology, Product Development, Quality Assurance

Keycloak experts in Germany have gathered most of their hands-on project experience in Information Technology, Product Development, and Quality Assurance.

Top industries

Information Technology, Banking and Finance, Automotive

Keycloak experts in Germany are most in demand in Information Technology, Banking and Finance, and Automotive.

Certification focus areas

Information Technology, Product Development, Project Management

Keycloak experts in Germany earn their certifications most often in Information Technology, Product Development, and Project Management.

Bachelor's degree or higher

87%

87% of Keycloak experts in Germany hold at least a Bachelor's degree.

Master's degree or higher

54%

54% of Keycloak experts in Germany hold at least a Master's degree.

Doctorate

10%

10% of Keycloak experts in Germany have a doctorate (PhD).

Certifications per freelancer

2

Keycloak experts in Germany hold 2 professional certifications on average.

Most common languages

German, English, French

Keycloak experts in Germany most often speak German, English, and French.

Speak two or more languages

97%

97% of Keycloak experts in Germany speak two or more languages.

Based on our profile pool as of 19 Sep 2026.

Daily rate distribution

0 20 40 60 80
5 of the Keycloak experts in Germany charge less than €480 per day.
22 of the Keycloak experts in Germany charge between €480 and €640 per day.
56 of the Keycloak experts in Germany charge between €640 and €800 per day.
55 of the Keycloak experts in Germany charge between €800 and €960 per day.
19 of the Keycloak experts in Germany charge between €960 and €1120 per day.
5 of the Keycloak experts in Germany charge between €1120 and €1280 per day.
3 of the Keycloak experts in Germany charge €1280 or more per day.
<€480 €480-​640 €640-​800 €800-​960 €960-​1120 €1120-​1280 €1280+

The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Discover detailed Keycloak rate benchmarks:

Explore rate insights

Average rates of experts in Germany using Keycloak

Rates are based on recent contracts and do not include FRATCH margin.

800
600
400
200
Rate comparison chart
Daily rate avg. 771 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

800
600
400
200
Rate comparison chart
Median rate 768 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Keycloak experts industry focus

See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.

  • Information Technology (97%)
  • Banking and Finance (56%)
  • Automotive (43%)
  • Government and Administration (42%)
  • Retail (41%)
  • Insurance (37%)
  • Manufacturing (37%)
  • Telecommunication (34%)

Please note that freelancers can work across multiple industries, so percentages overlap.

About the technology

Identity and access

Keycloak is an open-source identity and access management system for applications, APIs and services. It provides single sign-on, user federation, social login, identity brokering and central policy controls without forcing each application to manage authentication alone. Teams can run it on their own infrastructure or use the Red Hat build of Keycloak where enterprise support is required.

Core capabilities

Keycloak supports OpenID Connect, OAuth 2.0 and SAML for modern and established application environments. Experts configure realms, clients, users, groups, roles, scopes and identity providers to match a company’s security model. They also handle token flows, session behavior, consent screens, password policies and multi-factor authentication.

Ecosystem and tooling

A reliable implementation connects Keycloak with the wider delivery stack rather than treating it as an isolated login screen.

  • Integrate Java, Spring Boot, Node.js and frontend applications
  • Protect REST APIs and services with signed tokens
  • Connect LDAP, Active Directory and external identity providers
  • Deploy with Docker, Kubernetes, Helm and infrastructure automation
  • Monitor events, logs, availability and security-relevant changes

Typical projects

Companies bring in Keycloak specialists for platform modernization, customer portals, internal workforce access and multi-tenant SaaS products. The technology is also used to unify authentication across microservices, partner applications and data-sensitive environments. In Germany, teams often need professionals who can collaborate remotely while documenting decisions clearly for distributed stakeholders and regulated industries.

When expertise matters

Freelance expertise is valuable when authentication spans several applications, directories or organizations. Typical signals include duplicated login logic, inconsistent access rules, a planned migration from a hosted identity service, or a need to replace custom security code.

  • Consolidate separate login systems
  • Migrate users and credentials safely
  • Establish realm and tenant boundaries
  • Review token, session and role design
  • Prepare production operations and recovery plans

Strong professionals

Strong Keycloak professionals understand identity standards as well as application architecture. They model authorization deliberately, distinguish authentication from access control, and test failure paths such as expired tokens, revoked sessions and unavailable identity providers. They also automate configuration, protect secrets, plan upgrades and explain trade-offs to security, product and infrastructure teams.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

Everything clients usually want to know about Keycloak, in one place.

Keycloak centralizes authentication and authorization for web applications, APIs, mobile clients and internal services. It provides single sign-on, user federation, identity brokering, multi-factor authentication and standards-based tokens through OpenID Connect, OAuth 2.0 and SAML.

Keycloak is self-hosted and highly configurable, while Auth0, Okta and Microsoft Entra ID are primarily managed identity services. The right choice depends on control, operating capacity, integration needs, compliance constraints and whether the organization wants to run its own identity layer.

A strong Keycloak specialist should understand OAuth 2.0, OpenID Connect, SAML, JWT validation and secure session handling. Experience with LDAP or Active Directory, Java or Spring Boot, REST APIs, Docker, Kubernetes, CI/CD and cloud networking is often useful.

The required depth depends on the scope. A simple application integration may need focused configuration skills, while a migration, multi-tenant setup or high-availability rollout calls for a Keycloak professional who has handled realm design, user migration, upgrades, monitoring and incident scenarios.

Keycloak projects can be delivered remotely when access, environments and security responsibilities are clearly organized. For teams in Germany, fluent English may be sufficient for technical work, while German language skills can help with workshops, internal documentation and coordination with business stakeholders.

Ask the Keycloak professional to explain the identity model, token lifecycle, authorization rules and recovery approach in plain language. Review automated configuration, audit events, secret handling, upgrade planning and tests for failed logins, expired tokens, provider outages and excessive permissions.

Keycloak can support multi-tenant designs through realms, groups, roles, clients and carefully separated configuration. The specialist must choose the boundary model deliberately, because tenant isolation, administration rights, branding, user federation and operational overhead differ between approaches.

A frequent Keycloak risk is treating authentication as the whole security design while leaving authorization vague. Other issues include unmanaged realm changes, weak secret protection, brittle custom themes, unsafe user migration, poorly validated tokens and upgrades that were never tested against connected applications.

The average hourly rate of freelancers in Germany who have used Keycloak in their recent projects is 96 €, which corresponds to a daily rate of about 771 € based on an 8-hour working day.

Of the freelancers in Germany who have used Keycloak in their recent projects, 87% hold at least a Bachelor's degree, 54% hold at least a Master's degree, and 10% hold a doctorate.

On average, freelancers in Germany who have used Keycloak in their recent projects have 18 years of professional experience, with a single engagement typically lasting around 1.7 years.

The most common languages among freelancers in Germany who have used Keycloak in their recent projects are German (99%), English (96%), and French (20%).

The most common industries among freelancers in Germany who have used Keycloak in their recent projects are Information Technology (97%), Banking and Finance (56%), and Automotive (43%).

The most common business areas among freelancers in Germany who have used Keycloak in their recent projects are Information Technology (100%), Product Development (91%), and Quality Assurance (60%).

Main locations of FRATCH Experts, who have recently used Keycloak

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH