Managed Keycloak providers vs. self-hosting: an honest comparison

Last reviewed: 2026-08-26. Vendors change — if anything here is out of date, email hello@keelinfra.io and we'll correct it within one business day.

When managed Keycloak is the right answer

Honestly: often. If you have no ops team, no data-residency constraint, and you want the 2am pager to be someone else's problem, both vendors below do that genuinely well — Phase Two has SOC 2 and ISO 27001, enterprise customers, and a real published SLA; Skycloak has flat infrastructure pricing, a strong security page, and first login in minutes. If that's you, use them.

This page exists for the buyer they both structurally cannot serve: the team whose identity data cannot live on someone else's cloud — regulated industries, data residency, air-gapped networks, formal change control. Skycloak's own blog puts it plainly: if identity data can't leave your infrastructure, "a SaaS identity provider is off the table by definition."

The table

keelinfraPhase TwoSkycloakDIY
Where identity data livesYour machines, alwaysTheir cloud; on-prem via consulting + containerTheir cloud (4 regions)Your machines
License of the ops layerApache-2.0, all of itExtensions are Elastic License v2 (relicensed from AGPL in 2023; not OSI open source; restricts on-prem redistribution)Proprietary SaaSn/a — you write it
Air-gapped / offlineDesigned for it — offline bundle ships with the subscriptionNot offered; container phones home by defaultNot offered — SaaS by definitionPossible, all on you
HA / backup / upgrade docs public?Yes — docs, and CI-provenNo — docs cover app integration; ops is sold as supportn/a — they operate it for youUpstream docs only
Upgrade testing you can inspectNightly public CI matrix + published probe logsNone published; upgrades are a service engagementNone published; no version pinning, sequential upgrades onlyYours to build
SLA / uptime — verifiable?No SLA — measurements and drills insteadPublished SLA doc with credit formula"99.99%" on the homepage; SLA page says best-effort below Enterprise; no public status pagen/a
Exit pathNothing to export — it's already your databaseYour data in their container/cloud, ELv2 terms on extensionsDB export: Launch tier and up, credentials excluded by default, files expire in 24hn/a
Custom extensions / SPIsUnrestricted — it's your KeycloakTheir ecosystem, ELv2 termsCustom JARs are Enterprise-only; curated marketplace below thatUnrestricted
Who carries the 2am pagerYou — with drills, runbooks, and a $200/hr emergency lineThem (managed); you + retainer (self-hosted)ThemYou, alone
Time to first login~10 minutes — but you bring 1–3 VMsMinutes, free trialMinutes, free trialDays to weeks
Compliance paperworkNone from us — your data never reaches us; auditable source insteadSOC 2 Type II, ISO 27001SOC 2, ISO 27001, HIPAA claimed; documented pentests & subprocessorsYours
Pricing model$0 OSS · $1,500/node/yr sub · fixed-scope services$149–2,999/mo by MAU; support $3.5K–7.5K/mo$29–599/mo by infrastructure + EnterpriseYour engineers' time

How to read it

If you can use a managed cloud, the pager row and the compliance row may be all that matters — and both vendors win them. Per-MAU cost is the thing to model carefully: Skycloak's infrastructure-based pricing is genuinely different from Phase Two's MAU tiers.

If your data can't leave, the structural facts are these. Phase Two's self-hosted offering is a container image plus a support retainer ($42K–90K/yr at their published rates) — the HA, backup, and upgrade knowledge stays behind the retainer. Skycloak has no self-hostable product at all. In both cases the ops knowledge is the paywall.

keelinfra's bet is the opposite: the ops knowledge is the product, and it's Apache-2.0 — the installer, the docs, the drills, the upgrade runbooks, and the nightly CI that re-proves them. You pay for people and guarantees, not for access to how it works.

What we concede

Also in this series: Phase Two alternatives · Skycloak alternatives