Keycloak Identity & SSO Setup
Budget: $1,500 – $3,000 USD
I need a reliable Keycloak specialist to establish a solid identity-management foundation for our web applications. The primary objective is to centralise user identities and deliver smooth single sign-on.
Scope of work
• Install and configure the latest stable Keycloak on our preferred infrastructure (Docker or bare-metal Linux—advise on best fit).
• Create a production-ready realm, roles, groups and client definitions focused on web-app access only (no mobile clients required).
• Integrate the following identity providers:
– Google using OAuth2 / OpenID Connect
– Microsoft Azure AD / Entra ID via SAML or OpenID Connect (whichever you recommend for long-term maintainability).
• Enable cross-provider SSO so users can move between our internal apps without re-authenticating.
• Configure essential security settings: TLS, password policies, session time-outs, brute-force protection, token lifetimes and refresh behaviour.
• Provide concise documentation (step-by-step run-book + architecture diagram) so our in-house team can maintain and extend the setup.
Acceptance criteria
• Successful login/logout flows confirmed for both Google and Azure AD/Entra ID accounts.
• A sample web client demonstrates SSO across at least two test applications.
• All configuration exported to version-controlled JSON for repeatable deployments.
• Clear hand-over call or video walkthrough explaining realm structure, identity-provider mappings and backup strategy.
If you have proven experience with Keycloak plus OAuth2, OpenID Connect, and SAML, I’d like to get this rolling right away.
Scope of work
• Install and configure the latest stable Keycloak on our preferred infrastructure (Docker or bare-metal Linux—advise on best fit).
• Create a production-ready realm, roles, groups and client definitions focused on web-app access only (no mobile clients required).
• Integrate the following identity providers:
– Google using OAuth2 / OpenID Connect
– Microsoft Azure AD / Entra ID via SAML or OpenID Connect (whichever you recommend for long-term maintainability).
• Enable cross-provider SSO so users can move between our internal apps without re-authenticating.
• Configure essential security settings: TLS, password policies, session time-outs, brute-force protection, token lifetimes and refresh behaviour.
• Provide concise documentation (step-by-step run-book + architecture diagram) so our in-house team can maintain and extend the setup.
Acceptance criteria
• Successful login/logout flows confirmed for both Google and Azure AD/Entra ID accounts.
• A sample web client demonstrates SSO across at least two test applications.
• All configuration exported to version-controlled JSON for repeatable deployments.
• Clear hand-over call or video walkthrough explaining realm structure, identity-provider mappings and backup strategy.
If you have proven experience with Keycloak plus OAuth2, OpenID Connect, and SAML, I’d like to get this rolling right away.