Okta integrations are OIDC and SAML underneath, so your applications move to managed Keycloak with new endpoints, and you stop paying more for every person you add.
The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.
The cost of identity rises with every employee, customer or partner you add, while most infrastructure costs are expected to fall per unit as you grow.
Your configuration lives in a proprietary system. Leaving means rebuilding it, which makes the renewal hard to walk away from.
Capabilities your security team considers standard are often sold as separate products.
The protocols are the same on both sides. The proprietary parts are what need rebuilding.
Today this is a guided migration: our engineers plan it with your team and support each stage of the move. It is staged rather than a single big-bang cutover.
Applications, connections, rules and custom logic, user counts, and which users sign in with a password versus Google, Microsoft or a company identity provider.
A Skycloak cluster configured to mirror your current setup, so you can test every flow before any real user touches it.
Okta does not export password hashes. The usual answer is a just-in-time migration: Okta is connected to Keycloak as a temporary identity provider, and each user moves across the first time they sign in, without doing anything differently. Users who never come back get a password reset email when you switch Okta off. A forced reset for everyone is the simpler fallback if your user base can tolerate it. Users who sign in through a social or company identity provider need no password step at all.
Each application is repointed to its new OIDC or SAML endpoint one wave at a time, with a rollback for every wave. MFA devices cannot be exported from Okta, so users enroll again on their first sign-in to Keycloak. We plan when that prompt appears so it does not land on everyone the same morning.
You pay for the infrastructure your identity runs on. Users are unlimited on every plan, so growth in sign-ups does not change the invoice.
| Plan | Price | Clusters included |
|---|---|---|
| Developer | $29 per month | 1 |
| Launch | $149 per month | 1 |
| Business | $599 per month | 2 |
| Enterprise | Custom | 3 or more |
Additional clusters cost more, so the bill grows with the number of environments and regions you run, not with the number of people who sign in. Annual billing takes 20% off. Full detail on pricing.
Keycloak is open source under Apache 2.0, and Skycloak runs it without a fork. On Launch, Business and Enterprise you can export a realm, including users and their password hashes, as an encrypted standard Keycloak file that imports into any Keycloak server, including one you run yourself.
Once we got running with Skycloak and everything was basically set up, we just had to change a couple of URLs and it was pretty easy to integrate.
The call is with an engineer rather than a salesperson. Bring your current setup and we will tell you what moving would involve.