Okta migration

Move off per-user pricing and keep your integrations

Okta integrations are OIDC and SAML underneath, so your applications move to managed Keycloak with new endpoints, and you stop paying more for every person you add.

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

Why teams leave Okta

Per-user pricing

The cost of identity rises with every employee, customer or partner you add, while most infrastructure costs are expected to fall per unit as you grow.

A closed platform

Your configuration lives in a proprietary system. Leaving means rebuilding it, which makes the renewal hard to walk away from.

Add-ons for the basics

Capabilities your security team considers standard are often sold as separate products.

What carries over

The protocols are the same on both sides. The proprietary parts are what need rebuilding.

Carries over
  • OIDC and SAML applications: new issuer or metadata URL, new client credentials
  • Groups, exported through the Okta API and recreated in Keycloak
  • Federation with your customers' or partners' identity providers
  • User profiles and attributes
Gets rebuilt
  • Sign-on policies, which become Keycloak authentication flows
  • Okta Workflows and inline hooks, which become flows, mappers or extensions
  • MFA enrollments, since Okta does not export MFA devices

How the migration runs

Today this is a guided migration: our engineers plan it with your team and support each stage of the move. It is staged rather than a single big-bang cutover.

1

Map what you have

Applications, connections, rules and custom logic, user counts, and which users sign in with a password versus Google, Microsoft or a company identity provider.

2

Stand up the new realm next to the old one

A Skycloak cluster configured to mirror your current setup, so you can test every flow before any real user touches it.

3

Move users and passwords

Okta does not export password hashes. The usual answer is a just-in-time migration: Okta is connected to Keycloak as a temporary identity provider, and each user moves across the first time they sign in, without doing anything differently. Users who never come back get a password reset email when you switch Okta off. A forced reset for everyone is the simpler fallback if your user base can tolerate it. Users who sign in through a social or company identity provider need no password step at all.

4

Move applications in waves

Each application is repointed to its new OIDC or SAML endpoint one wave at a time, with a rollback for every wave. MFA devices cannot be exported from Okta, so users enroll again on their first sign-in to Keycloak. We plan when that prompt appears so it does not land on everyone the same morning.

What it costs

You pay for the infrastructure your identity runs on. Users are unlimited on every plan, so growth in sign-ups does not change the invoice.

PlanPriceClusters included
Developer$29 per month1
Launch$149 per month1
Business$599 per month2
EnterpriseCustom3 or more

Additional clusters cost more, so the bill grows with the number of environments and regions you run, not with the number of people who sign in. Annual billing takes 20% off. Full detail on pricing.

No lock-in on the way out either

Keycloak is open source under Apache 2.0, and Skycloak runs it without a fork. On Launch, Business and Enterprise you can export a realm, including users and their password hashes, as an encrypted standard Keycloak file that imports into any Keycloak server, including one you run yourself.

What integration looks like

Once we got running with Skycloak and everything was basically set up, we just had to change a couple of URLs and it was pretty easy to integrate.
Dustin Principal Web Developer, Beaulieu Canada
Read the case study

Common questions

Can we keep Okta for employees and move customers first?
Yes. Keycloak can federate with Okta as an identity provider, so you can move one population or one application at a time and keep Okta running for the rest.
Do users have to reset their passwords?
With a just-in-time migration, most users move on their next sign-in without a reset. Users who do not return during the migration window get a reset email, and users on social or company sign-in need no password step.

Move off per-user pricing and keep your integrations

The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.

Book a 15-minute call
© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman