Keycloak Experts in Stuttgart
in minutes from over 15,000 CVs with the power of AI.Hire experts who can set up Keycloak realms, clients, roles, and identity brokering, and who can integrate SSO into web apps, APIs, and internal tools. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Stuttgart, who have recently used Keycloak
Sercan Tatar
Last position:
Co-Founder & Lead Software Architect at Pflege-Pfad
- Focus: system architecture, cloud-native platforms, microservices, API design
- Product: Pflege-Pfad is a digital matchmaking platform that connects relatives of people in need of care directly with verified care services and caregivers - without an agency and without ongoing fees.
- Business analysis & process design:
- Analysis of the German care market and identification of the key pain points of both target groups.
- Modeling of the core business processes: registration, verification, care request, application, placement, and rating.
- Definition of the business model as a freemium/premium model with optional contact unlocking.
- Creation of user stories and requirements documentation for relatives, care services, and administrators.
- Design of trust and quality assurance mechanisms with document upload, admin review process, and rating system.
- Coordination with stakeholders and validation of product decisions with potential users.
- Technical implementation:
- Design and implementation of the entire platform architecture as a solo developer.
- Design and implementation of a REST API with Spring Boot and Kotlin, including JWT-based authentication.
- Development of the frontend as a single-page application with Angular 17.
- Implementation of the AWS infrastructure with EC2, RDS PostgreSQL, S3, CloudFront, and IAM.
- Document upload with AWS S3 via presigned URLs for verification of care services.
- Email notifications via Resend API.
- AI-supported care service search via OpenAI API.
- Implementation of complete user flows such as registration, login, password reset, and placement process.
- Building an admin panel for user and care service management as well as analytics.
- CI/CD with GitHub Actions and containerized deployments with Docker.
- End-to-end tests with Playwright.
Technologies: Kotlin, Spring Boot 3, Spring Security, JWT, JPA/Hibernate, PostgreSQL, Angular 17, TypeScript, RxJS, AWS (EC2, ECS, S3, CloudFront CDN, RDS PostgreSQL, IAM), nginx, GitHub Actions, Playwright, Maven, Git, OpenAI API, Resend API, Docker, Scrum, i18n (DE/EN/TR), Kiro, feature-flag architecture.
Salim Chehab
Last position:
Cloud / Systems Architect
- Development and introduction of operational processes
- Preparation of complete documentation packages (including emergency management and operations) to meet compliance requirements
- Introduction of a workshop on IaC (Infrastructure as Code)
- Professional consulting for the project's security concept (ISMS)
- Installation and operation of Kubernetes clusters on AWS, on-prem, and Azure
- Design of hybrid cloud architecture (on-prem, Hetzner, AWS)
- Analysis and resolution of incidents and system outages
- Network changes to firewall rules, gateways, OpenVPN settings, and IPsec tunnel (pfSense)
- Professional consulting on BitBucket, Jenkins, and GitLab CI/CD pipelines
- Consulting on Ansible deployments and infrastructure automation
- Consulting on building a scalable system in the cloud (AWS / Azure)
- Technologies / Tools: Ansible, Terraform, AWS, Azure, VPN, pfSense, Jenkins, Bitbucket, Kubernetes, GitLab Runner, ISMS, Golang, Prometheus, Grafana, S3, Lambda, RDS, ECS, Cognito, OIDC, Harbor, MinIO, Postgres, Redis, Keycloak, Ceph, Proxmox, CloudFormation, PostgreSQL, Flux CD, Hetzner, IONOS, Sonatype Nexus Repository, Entra ID, Dex IdP, Pulumi
Will Orrantia
Last position:
Solution Architect at Stuttgart Police Authority
Designing the migration strategy for WLS applications to the BKA cloud and Stack IT
Creating a hybrid cloud for internal testing and development with Kubernetes
Transforming the IT landscape from a legacy monolithic architecture to a cloud-based architecture
Integrating new CI/CD processes using Azure Pipelines
Quadrupled the throughput of personnel security checks
Migrated personnel security clearance applications to Docker-based applications
Built CI/deploy pipelines with Azure DevOps
Environment: Java Spring Boot, Kubernetes, Oracle WebLogic, OpenID, Camunda, JUnit, TOGAF
Albert Frischmann
Last position:
Lead Product Owner at CMBlu Energy AG
- Lead Product Owner for 4 development teams
- Leading and coordinating a greenfield project with parallel implementation of core components by independent teams; managing dependencies and resources
- Establishing a data lakehouse approach, including analysis of data volumes and future requirements as part of a cloud migration (best-of-breed approach)
- Responsible for requirements analysis, selection, and piloting of a LIMS/ELN system, supported by advising decision-makers and managing external vendors
- Introducing and managing an OpenWeb UI and Azure OpenAI-based RAG system to support knowledge extraction and data-driven analyses
- Setting up, configuring, and managing Jira projects, as well as developing project-specific workflows and automations
- Implementing classic Scrum processes with all ceremonies and taking on the Scrum Master role for all involved teams
- Assisting in hiring through interviews and assessments from a product owner's perspective
- Making key architectural decisions, including selecting the platform for the data lakehouse (Databricks) and the strategic integration of LIMS and analytics platforms
Benjamin Schaich
Last position:
Design and implementation of a new cloud service at Porsche AG
- Design of a new cloud service
- Requirements Engineering
- API Design (REST API, Kafka)
- Consulting on architecture, feasibility and effort estimation
- Implementation of a microservice architecture
- Implementation of a Spring Boot web service
- Development of REST APIs including business and persistence logic
- Kafka consumers and producers
- Various Excel upload/download scenarios
- Change Data Capture
- Cloud provisioning with IaC/Terraform
- Go-live with 30,000 users
- Operation, support and bug fixing for other services
Environment/tools: GitLab, JIRA, Confluence, IntelliJ, Spring Boot, Java, Docker, Terraform, AWS ECS, Postgres, Apache Kafka, SAP Datasphere, JUnit, Debezium, Apache POI, Hibernate, JPA, Testcontainers
Marcel Schmidt
Last position:
Technical Lead / Lead Developer at REWE digital
- Due to an organizational restructuring towards product-based teams, the implementation of a Data Mesh in the area of Digital Supplier Management (DSM) was decided.
- A highly available real-time Data Mesh for providing large volumes of data via Kafka and REST to other products.
- New development of a core supplier management software in a (micro-)service-based architecture with a modern tech stack.
- Technologies/Tools:
- Java 21
- Spring Boot
- Angular
- TypeScript
- Go
- MapR
- Kafka
- Docker
- Google Cloud Platform (GCP)
- Kubernetes
- Helm
- GitLab CI
- Maven
- JUnit
- Mockito
- WireMock
- Cypress
- Keycloak
- OAuth 2.0 & OpenID Connect
- Humio
- Nexus
- Artifactory
- SonarQube
- Renovate
- Git
- Postman
- IntelliJ
Ahmed Fikri
Last position:
Senior Lead Engineer (Freelance) at Atruvia AG
- Development of a wealth management application for investing in foreign currencies
- Full-stack development with Angular, Spring Boot, OpenShift, Oracle DB, Kafka
- Design and implementation of a microservice architecture
- Integration into Atruvia's BWS system and connection of multiple interfaces between Atruvia and DZ Privatbank
- Greenfield development of the application from the ground up
- Technical responsibility for architecture and interface design
- Close collaboration with business units and external stakeholders
Felix Junghans
Last position:
Senior Software Engineer at PCA GmbH
- Developed three applications with Flutter (Dart), Swift (iOS), and Kotlin (Android)
- Responsible for the apps' UI/UX design
- Developed a fingerprint plugin for HidGlobal in Swift and Kotlin
- Used Riverpod and Flutter Bloc for efficient state management
- Used Hive and Isar for local data management
- Used Firebase for backend services (Firebase Cloud Messaging, Analytics, and Firestore)
- Managed code with GitLab, developed using Visual Studio Code and Xcode
Discover over 15,000 top freelancers
Statistics of experts using Keycloak
Aggregated from the professional profiles of matched freelancers.
Experience
16 years (Germany: 18 years)
Position duration
1.9 years (Germany: 1.7 years)
Positions per freelancer
13
Top business areas
Information Technology, Product Development, Operations
Top industries
Automotive, Information Technology, Banking and Finance
Certification focus areas
Information Technology, Operations, Product Development
Bachelor's degree or higher
100% (Germany: 87%)
Master's degree or higher
33% (Germany: 53%)
Certifications per freelancer
2
Most common languages
German, English, Spanish
Speak two or more languages
100% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Stuttgart are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Stuttgart using Keycloak
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Identity control
Keycloak is an open-source identity and access management system. Companies use it to centralize login, single sign-on, role control, and user federation across internal tools, customer portals, and APIs. It helps reduce custom auth code and keeps access rules in one place.
Core setup
A strong Keycloak specialist works with realms, clients, users, groups, roles, and identity providers. Typical tasks include SSO setup, OpenID Connect and SAML integration, token settings, and password flows.
- Realm and client configuration
- Identity brokering and user federation
- Role and group design
- Token, session, and consent settings
Common use cases
Keycloak often sits in front of business apps, partner portals, and service APIs. It is also used for social login, external identity provider connections, and secure access for hybrid systems. In Stuttgart, it is a practical fit for industrial, software, and enterprise environments that need controlled access across many systems.
What good professionals do
Strong Keycloak experts think in security boundaries, not just setup screens. They check redirect handling, token lifetimes, client scopes, logout behavior, and how identities move between systems. They also document changes so teams can maintain the configuration after delivery.
Ecosystem and tooling
Keycloak work often touches OAuth 2.0, OpenID Connect, SAML, LDAP, reverse proxies, Java-based services, and container platforms. Good specialists know how to trace authentication issues across app, IdP, and network layers.
- OpenID Connect and SAML flows
- LDAP or directory integration
- Proxy and gateway compatibility
- Container and cloud deployment
When to bring in help
Companies usually bring in freelance Keycloak professionals when login is blocking a rollout, when an older auth setup needs replacement, or when multiple apps need one identity layer. It also helps when internal teams need a clean review before release, especially if onsite work in Stuttgart is useful for workshops and remote follow-up for the implementation.
Frequently asked questions
Questions about Keycloak? Start with the answers below.
Keycloak is used to manage login, single sign-on, roles, and identity federation in one place. It is common when several apps, APIs, or partner portals need the same access rules and a shared user experience. Teams also use it to reduce custom authentication code in their own systems.
Keycloak is self-hosted and highly configurable, so it suits teams that want control over their identity stack. Auth0 and Okta are managed services, which can be faster to start with but less flexible in how you run and tune the system. The right choice depends on whether control, hosting, and integration depth matter most.
A strong Keycloak specialist usually knows OpenID Connect, OAuth 2.0, and often SAML as well. LDAP, reverse proxies, Java apps, and container setups are also common adjacent skills. The best people can move between identity design, integration work, and troubleshooting.
For simple realm or client setup, a focused Keycloak expert may be enough. For enterprise SSO, federation, or migrations from older systems, companies usually need someone who has handled edge cases like logout, token mapping, and mixed identity sources. The more systems involved, the more important proven delivery becomes.
Yes. Keycloak is often used for both employee access and external user login, as long as the realm and client design matches the security model. Freelancers should be able to separate internal roles from customer roles and keep flows clear for each audience.
Most Keycloak tasks can be done remotely because they involve configuration, integration, and testing. On-site time in Stuttgart can help for workshops, access reviews, or early architecture decisions with local teams. Many projects work best with a mix of both.
Look for clear thinking about realms, clients, roles, token handling, and user flows, not just a working demo. A good Keycloak freelancer explains trade-offs, documents settings, and can show how the solution behaves during login, refresh, and logout. Security awareness and calm troubleshooting matter as much as setup speed.
Common issues in Keycloak projects include confusing client scope design, weak role mapping, bad redirect settings, and logout problems across several apps. Migrations also fail when teams do not plan user federation or token behavior early enough. Good specialists spot these risks before they break delivery.
The average hourly rate of freelancers in Stuttgart, Germany who have used Keycloak in their recent projects is 99 €, which corresponds to a daily rate of about 795 € based on an 8-hour working day.
Of the freelancers in Stuttgart, Germany who have used Keycloak in their recent projects, 100% hold at least a Bachelor's degree and 33% hold at least a Master's degree.
On average, freelancers in Stuttgart, Germany who have used Keycloak in their recent projects have 16 years of professional experience, with a single engagement typically lasting around 1.9 years.
The most common languages among freelancers in Stuttgart, Germany who have used Keycloak in their recent projects are German (100%), English (100%), and Spanish (38%).
The most common industries among freelancers in Stuttgart, Germany who have used Keycloak in their recent projects are Automotive (88%), Information Technology (88%), and Banking and Finance (63%).
The most common business areas among freelancers in Stuttgart, Germany who have used Keycloak in their recent projects are Information Technology (100%), Product Development (100%), and Operations (63%).
Main locations of FRATCH Experts, who have recently used Keycloak
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Frankfurt
Dusseldorf