compare
Keycloak vs Rauthy
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | Keycloak | Rauthy |
|---|---|---|
| Language | Java | Rust |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 37k | 1.4k |
| Latest | 26.8.0 | v0.37.0 |
| Last push | 2026-10-06 | 2026-10-06 |
| Release cadence | about 14 days between releases | about 33 days between releases |
| Active contributors | 97+ commit authors on the default branch in the last 90 days | 18 commit authors on the default branch in the last 90 days |
| Flags | none | none |
How they relate
Both replace Okta. Alternatives to Okta →
Full replacementKeycloakSSO over OpenID Connect and SAML, user federation with LDAP and Active Directory, and MFA.
PartialRauthyLightweight OpenID Connect provider with passkeys and MFA, without SAML.
Keycloak
Rauthy
- v0.37.02026-10-03IF YOU DO NOT FOLLOW THE STEPS BELOW, YOU MIGHT END UP WITH INCONSISTENT DATA!
- v0.36.22026-08-08There were 2 reachable panics in certain situations. Especially in one case it was easy to abuse it for an unauthentica…
- v0.36.12026-07-24There was a security issue with Moderate severity during token refresh under some circumstances that allows cross-clien…
- v0.36.02026-07-06Technically, this is not a breaking change, but it might be for you. The config parser now has an additional validation…
- v0.35.22026-05-19This version bumps several 3rd party dependencies to fix CVEs in them. A timely update is advised.
Keycloak
unsigned The latest release, 26.8.0, carries no signature GitHub could verify.
Loading the security report
Rauthy
✓ signed The latest release, v0.37.0, carries a signature GitHub verified.
Loading the security report