Casdoor vs. Keycloak
Keycloak and Casdoor are both open-source, self-hosted identity providers under the Apache-2.0 license. Both speak OAuth 2.0, OpenID Connect, and SAML, and both can sit in front of LDAP or Active Directory. They differ mostly in how they are built and how you operate and customize them.
Summary
| Casdoor | Keycloak | |
|---|---|---|
| Backend | Go, single binary | Java on Quarkus |
| Admin and login UI | React, configured in the web console | Admin console plus FreeMarker or React-based themes packaged as files |
| Tenancy | Organizations, with applications shared or scoped per organization | Realms, plus Organizations inside a realm |
| Protocols served | OAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS, SCIM, WebAuthn, Kerberos | OAuth 2.0, OIDC, SAML, WebAuthn, Kerberos; LDAP and AD as user federation |
| Social and enterprise sign-in | More than 70 built-in providers, including WeChat, DingTalk, Lark, Alipay | A smaller built-in set; others through generic OIDC/SAML or community extensions |
| Extending | REST API, webhooks, SDKs in 10+ languages | Java Service Provider Interfaces (SPIs) deployed into the server |
| Authorization | Casbin models (ACL, RBAC, ABAC) | Authorization Services (UMA 2.0, policies) |
| AI agents and MCP | Built-in MCP server; OAuth 2.1 authorization server for MCP | Standard OAuth; no built-in MCP server |
| Governance | Casdoor community, commercial support from Casbin | CNCF project, commercial support from Red Hat |
Architecture and operations
Keycloak is a Java application built on Quarkus. It is mature and scales well, and it expects JVM tuning, a build step when you change providers or features, and Infinispan caches when you run a cluster.
Casdoor is a Go backend that serves a React frontend. It starts as one process, keeps its state in a SQL database, and supports MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, TiDB, and CockroachDB. For a trial you can run the whole thing with one command:
docker run -p 8000:8000 casbin/casdoor-all-in-one
See Server installation and Kubernetes deployment for production setups.
Customizing the login experience
In Keycloak, changing the look of the login pages means writing a theme (FreeMarker templates or a React-based theme), packaging it, and deploying it to the server.
In Casdoor, each application has its own sign-in and sign-up pages that you edit in the admin console: which fields appear, which providers are offered, the layout, background, and custom CSS or HTML. See UI customization and Sign-up items. Nothing is redeployed.
If you need behavior the server does not offer, Keycloak's answer is a Java SPI running inside the server. Casdoor's answer is to call its REST API or react to webhooks from your own service, in any language.