For B2B SaaS

Enterprise SSO your customers will ask for

When a large customer's security review arrives, you already have the answers: sign-in through their identity provider, a tenant of their own, audit logs and a SOC 2 report.

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

What enterprise buyers put in the security questionnaire

The items on that list are predictable, and each one is either a configuration step on Skycloak or a document you can already send.

SSO with their identity provider

Each customer signs in through Entra ID, Okta, Google Workspace or any SAML or OIDC provider, set up per customer as an identity provider.

A tenant of their own

Keycloak 26 Organizations group each customer's users, domains and identity provider inside one realm. Teams that want harder separation give each customer a realm of their own.

User provisioning

SCIM is available through the SCIM 2.0 extension in the Skycloak extension marketplace. It is not built into Keycloak itself, where native SCIM is still experimental.

MFA and session control

TOTP, WebAuthn and passkeys, plus session listing and revocation, on every plan.

Audit logs

Authentication events on Launch and above, with SIEM export as an add-on (included on Enterprise).

Compliance evidence

Our SOC 2 Type II report and ISO 27001 certificate, shared under NDA, plus a public SLA. See the procurement checklist.

Have it ready before the contract

Building enterprise SSO while a contract waits is the expensive way to get it. On Skycloak, adding a customer's identity provider is configuration rather than a development project, and the security pack is a set of documents rather than a project.

Because there are no per-user or per-MAU fees, a new customer with thousands of employees does not change your identity bill. Cost grows when you add clusters, for example a second region for a customer who needs to be hosted in Europe or Canada.

What you stop staffing

Skycloak runs
  • Keycloak upgrades and security patches
  • Infrastructure and monitoring
  • Certificates and custom domains
  • The infrastructure in your chosen region
Your team keeps
  • Which customers get which identity provider
  • Roles and permissions in your product
  • Full Keycloak admin access when you want it

What it costs

You pay for the infrastructure your identity runs on. Users are unlimited on every plan, so growth in sign-ups does not change the invoice.

PlanPriceClusters included
Developer$29 per month1
Launch$149 per month1
Business$599 per month2
EnterpriseCustom3 or more

Additional clusters cost more, so the bill grows with the number of environments and regions you run, not with the number of people who sign in. Annual billing takes 20% off. Full detail on pricing.

A realm per customer, in production

We explored other vendors, however most were geared towards low realms, high user counts. Our model, as a smaller software vendor, is a relatively high realm count, allowing our customers to control their own login flows and provide their own identity servers. The user counts are relatively low on the realms. There were no other good fits for what we were trying to accomplish.
Jamie Dougal VP of Engineering, Candata Global
Read the case study
SOC 2 Type II
Independently audited. Report shared under NDA.
ISO 27001
Certified information security management system.
4 regions
US East (Ohio), EU Central (Germany), Asia Pacific (Sydney), Canada (Central).
Unlimited
Users on every plan. No per-user or per-MAU fees.

Enterprise SSO your customers will ask for

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

Book a 15-minute call
© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman