compare
Authelia vs Keycloak
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | Authelia | Keycloak |
|---|---|---|
| Language | Go | Java |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 29k | 37k |
| Latest | v4.39.28 | 26.8.0 |
| Last push | 2026-10-06 | 2026-10-06 |
| Release cadence | about 2 days between releases | about 14 days between releases |
| Active contributors | 13+ commit authors on the default branch in the last 90 days | 97+ commit authors on the default branch in the last 90 days |
| Flags | none | none |
How they relate
Both replace Okta. Alternatives to Okta →
PartialAutheliaSSO and MFA in front of a reverse proxy, plus an OpenID Connect provider, without user management UI.
Full replacementKeycloakSSO over OpenID Connect and SAML, user federation with LDAP and Active Directory, and MFA.
Authelia
- v4.39.282026-09-17docker pull authelia/authelia:4.39.28
- v4.39.272026-09-15handlers: use correct status code for consent redirects (#13155) (b1d294e) by @james-d-elliott
- v4.39.262026-09-12oidc: allow conformant alg none jarm (#13110) (2ce5b5b) by @james-d-elliott
- v4.39.252026-09-10notification: smtp ipv6 literal addresses (#13051) (ffa6a89), closes #13041 by @james-d-elliott
- v4.39.242026-09-09suites: preserve log colours under go test -json (#13048) (c004538) by @nightah
Authelia
✓ signed The latest release, v4.39.28, carries a signature GitHub verified.
Loading the security report
Keycloak
unsigned The latest release, 26.8.0, carries no signature GitHub could verify.
Loading the security report