Keycloak
Keycloak is an open source identity and access management server and a CNCF incubating project, supporting OpenID Connect, OAuth 2.0, SAML 2.0, identity brokering and LDAP or Active Directory federation.
Free and open source under Apache 2.0; costs are infrastructure and staff time, with optional paid support available from third-party vendors.
Open source
Appears in 1 guide
Where it ranks
Guides that include Keycloak.
Security headers
What Keycloak's website sends to your browser.
Scanned 2026-08-25. Grade headers F, scoring 5 out of 100.
−
No Content-Security-Policy, so no defence in depth against cross-site scripting
−
No Strict-Transport-Security, so browsers may still attempt plain HTTP
−
No X-Content-Type-Options, so MIME sniffing is not disabled
−
No X-Frame-Options and no CSP frame-ancestors, so clickjacking is possible
−
No Referrer-Policy, so full URLs may leak to third parties
−
No Permissions-Policy, so powerful browser features are not restricted
−
No Cross-Origin-Opener-Policy
−
No Cross-Origin-Resource-Policy
+
No server-version or X-Powered-By disclosure
This is one narrow, automated check of the HTTP response headers on the vendor's own website. It says nothing about how the product itself is built, how it stores your data, or whether it has ever been audited. A good grade here is a small signal that somebody was paying attention.