Keycloak Experts in Munich
in minutes from over 15,000 CVs with the power of AI.Hire experts who design Keycloak realms, SSO flows, and identity federation for modern applications. They handle OpenID Connect, SAML, role mapping, and secure login journeys with fast, precise matching to vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used Keycloak
Karen Manukyan
Last position:
Personal AI Engineering Project — Croky AI at Crocky AI
Product:
- Built a production-ready AI platform for generating brand-aware marketing images and videos from product data, user requirements, and uploaded media.
- Own the platform architecture, technical roadmap, API design, security, deployment workflow, operational reliability, and model-provider strategy.
- Developed the core platform in .NET and built supporting AI and workflow prototypes in Python, applying language-independent API contracts and structured interfaces between services and model providers.
- Implemented reliable background processing with RabbitMQ, persisted workflow state, idempotent handling, retries, failure recovery, logging, secure storage, authorization, and credit accounting.
- Made pragmatic build-versus-buy and model-routing decisions based on reliability, latency, cost, and maintainability rather than novelty.
Agent Orchestration & RAG Systems
- Built and compared agent workflows using Microsoft Agent Framework, LangGraph, and LangChain, including tool use, conditional routing, clarification steps, state management, and hand-offs between agents.
- Implemented reusable .NET components for agents, prompts, tools, model providers, structured responses, and retrieval with pyvector, making it easier to change AI providers without rewriting the core workflow.
Tamás Eppel
Last position:
Senior Software Developer / Tech Lead at NDA (defense / OSINT)
- Designing the audit logging framework
- Implementing APIs for developers to integrate in their codebase
- Implementing ingestion pipeline, database query layer and UI for browsing the audit events
- Improving stability and reliability of the backend system
Thomas Hoefkens
Last position:
Senior MLOps, DevOps Engineer at Trianel Energy
- Build and operate an end-to-end MLOps platform on Azure ML and Kubernetes (Kubeflow) for the automated deployment, monitoring, and scaling of forecasting models (including Temporal Fusion Transformer, Informer, Autoformer).
- Implement CI/CD pipelines in Azure DevOps for the full ML lifecycle – from resource provisioning (Terraform), data transformation (Hugging Face Datasets, Pandas, PyTorch, CUDA cluster) through training and evaluation to model registry and endpoint deployment.
- Integrate MLflow for experiment tracking, model versioning, performance monitoring, and automated registration in the Azure Model Registry.
- Develop and containerize PyTorch training jobs (Azure Notebook, Jupyter Notebooks) for price and time series forecasting (PFC models) with automatic rollout via Azure ML Endpoints and REST/gRPC interfaces, Docker containerization, secured with OAuth 2.0.
- Set up monitoring and alerting mechanisms (Prometheus, MLflow Metrics), log centralization, and cost monitoring.
- Automate infrastructure provisioning and model deployment using Terraform, Helm, and Azure CLI; connect to existing market data systems and event pipelines.
- Migrate existing workloads and databases (IONOS → Azure, MongoDB) with integration into central MLOps workflows and internal networks.
- Extend the platform with LLM-based tools (LangChain, LangServe) to integrate GPT-based analysis modules into existing Spring Boot services for market anomaly detection and automated reports.
- Analyze and architect a software solution to process large volumes of data efficiently (>3000 messages/sec.) (market data store).
- Spring Boot / Java 21 container development with RabbitMQ for distributing stock market data via MongoDB (Kubernetes) with fast storage of data in Redis RMaps, deduplication, forwarding messages to Read Model queues, and building Read Models for UI display in MongoDB.
- Integration of RESTHeart to create a REST API for MongoDB.
- Build an Angular frontend to simplify data queries and master data maintenance.
- Agentic coding with remote and local LLMs (Claude Sonnet, Ollama Qwen) and MCP servers.
- Develop Python scripts for transforming and cleaning incoming stock market data (Pandas, scikit-learn).
Srinivasu Kakaraparti
Last position:
Atruvia
Project: Tax Exemption Order Application
The client has an existing application for creating and maintaining tax exemption orders for end customers; design and implementation of a comparable application for internal employees.
- Design and implementation of microservices and the UI for the business area "tax exemption orders" using Domain Driven Design as well as Spring Boot and Angular.
- Implementation of reactive, non-reactive, and asynchronous APIs (Spring REST, WebFlux, GraphQL).
- Development of the Angular application, including state management using Signals, RxJS Observables, and subscriptions.
- Securing the API and the application using OAuth2, JWT, and OpenID Connect.
- Configuration and setup of CI/CD pipelines with Jenkins.
- Collaboration with cross-functional teams and conducting code reviews.
Environment: Java, Spring Boot, Angular 18 & 19 (standalone, signals), RxJs, Bootstrap CSS, Vitesting, OpenShift, Istio, microservices, Kafka, Dynatrace, Jenkins, GitLab, Graylog, Sonar, Oauth2, OracleDB
Birgit Stünkel
Last position:
Business Analysis, Requirements Engineer at BMW
Refinement of epics and user stories to achieve a higher degree of automation in CRM usage. Testing of new Discountsystem
Ronald Mazelisz
Last position:
DevOps Consultant at M.it services & systems GmbH
- Adjusting, optimizing, configuring, and administering a multi-stage GitLab instance with over 250 users
- Building, adjusting, expanding, and optimizing infrastructure, configuration, and monitoring
- Providing services and handing them over to production
- System environment: DependencyTrack, GitLab, Grafana, Hedgedoc, Kubernetes, OAuth2 Proxy, Openstack, Prometheus, Syseleven
Sebastian Kanzow
Last position:
Senior Lead Developer, System Architecture at AVL DITEST
- Redesign of a legacy Windows app for vehicle diagnostics as an AWS cloud application
- Creating build pipelines and conducting code reviews using Kotlin, Spring Boot, Micronaut, Jenkins, and GitHub
Alexander Schwartz
Last position:
Founder and Full-Stack Developer at TrumpPostAlert.com
- Feasibility study for quick implementation of requirements with AI-based development (vibe coding)
- Development of a single-page web app in Angular 20
- Development of a backend server application in Kotlin
- Integration with Google Cloud Platform (Firebase): authentication, Firestore NoSQL database, storage, Cloud Functions, hosting and Cloud Run
- Integration with a NEON PostgreSQL database
- Automated AI-based analysis of Donald Trump's posts on Truth Social and analysis of relevance for stock markets and geopolitical topics
- CI/CD via GitHub Actions using Docker and Google Cloud Run
- Technical environment: Angular 20 (Angular Material, RxJS), Kotlin 2.2.20, TypeScript 5.9.3, Spring Boot 3.5.6, Google Cloud Platform (Firebase, Cloud Run, Gemini, Vertex AI), ChatGPT Codex, Git, GitHub, SourceTree, IntelliJ WebStorm, IntelliJ IDEA
Harald Laschitz
Last position:
Project Management at Loocid LLC
- Conducted a comprehensive due diligence review for a potential acquisition of a Swiss manufacturing company as part of a pre-merger analysis
- Assessed production capacities and technical infrastructure
- Evaluated integration possibilities into existing business processes
- Performed risk assessment and developed recommendations for action
- Documented the findings and presented them to management
Enis Spahi
Last position:
Software Developer at 50Hertz Transmission GmbH
- Participated in the gradual modernization of components into cloud-native 12-factor applications.
- Worked closely with the business operations team to eliminate manual processes and resolve several performance bottlenecks.
- Designed and implemented a CI/CD pipeline to increase developer productivity, enforce quality and security checks, and automate product delivery.
- Migrated several components into the OpenShift Kubernetes cluster.
- Built a monitoring stack from scratch with Prometheus and Grafana to monitor services running in OpenShift.
- Developed dashboards in both Grafana and Splunk for operational transparency.
- Implemented an OIDC/OAuth2-based single sign-on (SSO) solution with Keycloak to secure multiple applications.
- Technologies: Java, Spring, Quarkus, Kafka, MySQL, Cassandra, Redis, Spring Data, Hibernate, Docker, Kubernetes, OpenShift, Keycloak, OIDC, OAuth2, Helm, Prometheus, Grafana, Splunk, Spark.
Matthias Lang
Last position:
Typescript Fullstack Engineer at Card Complete / Bank Austria
- Designed and developed the "Credit Risk Engine" using Camunda, Node.js and Typescript
- Greenfield project for credit card credit assessment for existing and new customers, including EBA KPIs, SCHUFA and CRIF scorings
- Built and modeled workflows (BPMN) and decision logic (DMN) with Camunda Modeler in close collaboration with stakeholders
- Implemented service tasks, user tasks and jobs with Nest.js, Node.js and Typescript, including exception handling
- Backend-for-Frontend (BFF), frontend with React, Tailwind and Ant Design UI library
- CI/CD with GitLab, Kubernetes/Rancher
Patrick Upmann
Last position:
Interim Management | Consulting & Implementation | Data Deletion in SAP at BSR (Berliner Stadtreinigung)
- Topics: Business Analysis, Data Privacy, Data Management, Stakeholder Management, Conceptualization
- This project focuses on developing and implementing a strategic approach for data deletion in SAP systems. The goal is to identify the relevant data and structures during system migration to ensure both data privacy and IT system efficiency. At the same time, downtime should be minimized and regulatory requirements met.
- Development of a comprehensive approach for data deletion in SAP systems, considering data privacy and business requirements.
- Ensuring efficient and structured data transfer to the new system.
- Optimizing system efficiency and reducing downtimes during migration.
- Creating functional and technical concepts to ensure compliant and sustainable data management.
- Topic preparation: Detailed study of the "data deletion" area to lay the foundation for a structured data migration.
- Definition of project structure: Setting roles, interfaces and the project's organizational structure.
- Regulatory requirements: Analysis of data privacy regulations and business requirements to define deletion criteria.
- Approach: Developing possible scenarios and methods for data cleansing and deletion.
- Deletion concepts: Creating functional and technical deletion concepts that structure the implementation and provide clear guidelines.
- Setting deletion criteria: Defining which data and structures to delete or transfer.
- Responsibilities: Clarifying responsibilities within the project team and among stakeholders.
- Analysis of ongoing activities: Identifying and collecting existing activities in the "data deletion" area.
- Effort, cost and timeline planning: Creating estimates for resources, effort and budget.
- Implementation initiatives: Developing and executing concrete measures to apply the defined deletion strategies.
- IT system efficiency: Analyzing the existing IT infrastructure to identify optimization potential for data deletion and transfer.
- Technology trends: Evaluating new technologies and tools that can support the data cleansing process.
- Cost-benefit analysis: Assessing the financial impact of data cleansing and the introduction of new solution approaches.
- Risk management: Identifying potential risks during implementation and developing appropriate mitigation measures.
- This project lays the foundation for a sustainable and compliant data transfer to a new SAP system. With a clear approach to data deletion, it meets data privacy requirements, reduces downtimes and increases the efficiency of the new system. The results and recommendations will help companies develop a future-proof data strategy that meets legal and business needs.
Keith Howe
Last position:
Senior Technical Business Analyst / Requirements Engineer / Product Owner at Deutsche Post E-Post Solutions
- SBAM (Sendungsbasiert Auftragsmanagement System) is the core component responsible for splitting customer deliveries into individual letters based on contractual agreements (OLA/SLA).
- Transformation from proprietary host-based AS/400 applications to a modern stack using Java, PostgreSQL, Apache Kafka, MinIO S3, Red Hat OpenShift, Keycloak SSO, Salesforce and Angular Material GUI.
- Application design, solution architecture, use case specification and OLA/SLA concept for end customers.
- Conduct solution architecture/design and requirements engineering (elicitation, documentation, validation, negotiation and ongoing management) in Confluence, including UML/BPMN process models.
- Development and analysis according to Scrum using Jira and Confluence.
- Design user journeys and UI experience; wireframing with Balsamiq and Figma.
- Document requirements as user stories and epics in Jira; create stakeholder and technical design documents.
- Participate in end-to-end solution design, architecture and event-driven messaging design.
- Perform process modelling (UML/BPMN with Draw.io), application internal architecture design and ERM/SERM data modelling.
- Lead sprint planning, story refinement, estimation, retrospective and review meetings; deliver C-level management presentations on OLA/SLA and order management.
Dmitry Varlamov
Last position:
Fullstack Software Developer at Mercedes-Benz Tech Innovation
- Backend development of the cloud-based microservice
- Frontend development of the microfrontend
- Migration of the cloud backend environment
- Rollout of the distributed high-availability Privacy Data Service
- Technologies: Java, Kotlin, Spring Boot, REST Services, Kubernetes, Microsoft Azure, Cloud Security, OpenAPI, Postman, JavaScript, Vue.js, AngularJS, TypeScript, Micro Frontend, Redis, Kibana, Grafana, CI/CD, GitHub Actions, Jenkins, Helm Charts, Sec-Hub, Black Duck, Docker, Maven, Git, Scrum
Maryam Nemati
Last position:
Senior FullStack Developer at Camunda
- Role: Senior FullStack Developer
- Technologies: Google Cloud, Azure, Microsoft Entra, Keycloak, Spring Boot, Java
- Active in production
Discover over 15,000 top freelancers
Statistics of experts using Keycloak
Aggregated from the professional profiles of matched freelancers.
Experience
22 years (Germany: 18 years)
Position duration
1.8 years (Germany: 1.7 years)
Positions per freelancer
14 (Germany: 13)
Top business areas
Information Technology, Product Development, Project Management
Top industries
Information Technology, Banking and Finance, Insurance
Certification focus areas
Information Technology, Product Development, Project Management
Bachelor's degree or higher
82% (Germany: 87%)
Master's degree or higher
71% (Germany: 53%)
Doctorate
24% (Germany: 10%)
Certifications per freelancer
2
Most common languages
German, English, Spanish
Speak two or more languages
95% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using Keycloak
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Identity control
Keycloak is an open source identity and access management tool for login, single sign-on, and user federation. It helps companies centralize authentication across web apps, APIs, and internal tools. Strong specialists know how to fit it into existing security and application landscapes.
Common use cases
- Single sign-on for customer and employee portals
- Central login for APIs and microservices
- Social or enterprise identity federation
- Multi-factor authentication and access policies
- Secure logout and session handling
Core skills
A good Keycloak professional works with realms, clients, identity providers, roles, groups, and protocol mappers. They understand OpenID Connect and SAML, plus how tokens, sessions, and claims move through an application. Many also work with LDAP, Active Directory, and Kubernetes-based deployments.
Ecosystem
Keycloak sits in the middle of a broader security stack. Work often includes reverse proxies, API gateways, Java services, Spring Boot applications, and cloud infrastructure. Knowledge of Red Hat SSO matters too, because many teams still use that name when they mean Keycloak.
When companies need help
Companies usually bring in freelance expertise when identity flows become hard to maintain or risky to change. That can be during a migration from a legacy login system, a new SSO rollout, or a redesign of permissions and user onboarding. In Munich, this often comes up in regulated sectors, enterprise software, and larger platform teams that need clean integration work.
What strong specialists deliver
Strong professionals do more than configure a login screen. They document flows, test token behavior, secure client settings, and keep the setup understandable for developers and operations teams. They also think about backups, upgrades, and how changes will affect users and connected systems.
Frequently asked questions
Not sure where to start with Keycloak? These answers cover the essentials.
Keycloak is used to centralize identity and access control across applications. Companies use it for single sign-on, user federation, social login, and secure token-based access to web apps and APIs. It is a fit when many systems need the same login and policy layer.
Keycloak is self-managed and open source, so teams keep more control over configuration, hosting, and data. Auth0 and Azure AD B2C are managed services, which can reduce operations work but also reduce flexibility. The right choice depends on governance, hosting needs, and how much identity logic you want to own.
A strong Keycloak specialist usually knows OpenID Connect, SAML, and token-based security. Useful adjacent skills include Java, Spring Boot, LDAP, Active Directory, Kubernetes, and reverse proxy setup. If your project touches APIs or microservices, API gateway knowledge also helps.
A good Keycloak engagement starts with clear information about your applications, user groups, and current login flow. The specialist should also see your identity sources, permission model, and any existing SSO or federation setup. With that context, they can design a clean rollout instead of patching issues later.
Most Keycloak work can be done remotely because the key tasks are configuration, integration, and testing. On-site time in Munich can still help when identity touches many internal teams or when workshops are needed for security and application owners. Many companies use a hybrid setup for the rollout phase.
You likely need Keycloak help when login flows are breaking, client settings are unclear, or role mapping has become messy. Another sign is when teams are afraid to change identity settings because no one fully owns them. A freelancer can stabilize the setup and reduce that risk.
A strong Keycloak specialist explains trade-offs clearly and can describe why a realm, client, or mapper is set up a certain way. They should be able to trace a login flow from browser to token to backend access check. Good signs are clean documentation, careful testing, and secure defaults.
Keycloak is the product most teams mean when they mention Red Hat SSO in older projects. Red Hat SSO was the commercial branding around Keycloak in many environments, so searchers often use both names. A good freelancer should understand that history and know how older setups map to current Keycloak versions.
The average hourly rate of freelancers in Munich, Germany who have used Keycloak in their recent projects is 96 €, which corresponds to a daily rate of about 764 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used Keycloak in their recent projects, 82% hold at least a Bachelor's degree, 71% hold at least a Master's degree, and 24% hold a doctorate.
On average, freelancers in Munich, Germany who have used Keycloak in their recent projects have 22 years of professional experience, with a single engagement typically lasting around 1.8 years.
The most common languages among freelancers in Munich, Germany who have used Keycloak in their recent projects are German (100%), English (86%), and Spanish (18%).
The most common industries among freelancers in Munich, Germany who have used Keycloak in their recent projects are Information Technology (95%), Banking and Finance (73%), and Insurance (59%).
The most common business areas among freelancers in Munich, Germany who have used Keycloak in their recent projects are Information Technology (100%), Product Development (91%), and Project Management (73%).
Main locations of FRATCH Experts, who have recently used Keycloak
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Cologne
Frankfurt
Stuttgart
Dusseldorf