跳到主内容

Casdoor vs. Keycloak

Keycloak and Casdoor are both open-source, self-hosted identity providers under the Apache-2.0 license. Both speak OAuth 2.0, OpenID Connect, and SAML, and both can sit in front of LDAP or Active Directory. They differ mostly in how they are built and how you operate and customize them.

Summary​

CasdoorKeycloak
BackendGo, single binaryJava on Quarkus
Admin and login UIReact, configured in the web consoleAdmin console plus FreeMarker or React-based themes packaged as files
TenancyOrganizations, with applications shared or scoped per organizationRealms, plus Organizations inside a realm
Protocols servedOAuth 2.0, OIDC, SAML, CAS, LDAP, RADIUS, SCIM, WebAuthn, KerberosOAuth 2.0, OIDC, SAML, WebAuthn, Kerberos; LDAP and AD as user federation
Social and enterprise sign-inMore than 70 built-in providers, including WeChat, DingTalk, Lark, AlipayA smaller built-in set; others through generic OIDC/SAML or community extensions
ExtendingREST API, webhooks, SDKs in 10+ languagesJava Service Provider Interfaces (SPIs) deployed into the server
AuthorizationCasbin models (ACL, RBAC, ABAC)Authorization Services (UMA 2.0, policies)
AI agents and MCPBuilt-in MCP server; OAuth 2.1 authorization server for MCPStandard OAuth; no built-in MCP server
GovernanceCasdoor community, commercial support from CasbinCNCF project, commercial support from Red Hat

Architecture and operations​

Keycloak is a Java application built on Quarkus. It is mature and scales well, and it expects JVM tuning, a build step when you change providers or features, and Infinispan caches when you run a cluster.

Casdoor is a Go backend that serves a React frontend. It starts as one process, keeps its state in a SQL database, and supports MySQL, MariaDB, PostgreSQL, SQL Server, Oracle, SQLite, TiDB, and CockroachDB. For a trial you can run the whole thing with one command:

docker run -p 8000:8000 casbin/casdoor-all-in-one

See Server installation and Kubernetes deployment for production setups.

Customizing the login experience​

In Keycloak, changing the look of the login pages means writing a theme (FreeMarker templates or a React-based theme), packaging it, and deploying it to the server.

In Casdoor, each application has its own sign-in and sign-up pages that you edit in the admin console: which fields appear, which providers are offered, the layout, background, and custom CSS or HTML. See UI customization and Sign-up items. Nothing is redeployed.

If you need behavior the server does not offer, Keycloak's answer is a Java SPI running inside the server. Casdoor's answer is to call its REST API or react to webhooks from your own service, in any language.

Protocols​

Both products cover OAuth 2.0, OIDC, and SAML as an identity provider and as a service provider. The differences are at the edges:

  • CAS: Casdoor is a CAS server out of the box. Keycloak needs a community extension.
  • LDAP and RADIUS: Casdoor can act as an LDAP server and a RADIUS server, so legacy applications, VPNs, and network devices can authenticate against it. Keycloak consumes LDAP directories but does not serve LDAP or RADIUS.
  • Fine-grained standards: Keycloak has broader coverage of advanced OAuth profiles such as UMA 2.0, token exchange, and FAPI. If you depend on those, check Casdoor's current support before switching.

AI agents and MCP​

Casdoor treats agents as first-class clients:

Keycloak can issue tokens for MCP clients through standard OAuth, and it supports Dynamic Client Registration, but MCP-specific pieces are left to you to assemble.

Authorization​

Keycloak's Authorization Services model resources, scopes, policies, and permissions inside the server and follow UMA 2.0.

Casdoor uses Casbin. You choose or write a model (ACL, RBAC, RBAC with domains, ABAC), manage policies in the UI, and can call the same enforcement API from your services. If your applications already use Casbin, policies and identity live in one place.

Migrating from Keycloak​

You do not have to switch in one step.

  1. Import users. The Keycloak syncer reads Keycloak's database tables and maps users, credentials, and groups into Casdoor.
  2. Run side by side. Add Keycloak to Casdoor as a SAML provider or a custom OIDC provider so existing Keycloak sessions keep working while applications move over.
  3. Move applications one at a time. Each application only needs a new issuer URL, client ID, and client secret, because both servers speak standard OIDC and SAML.

When to choose which​

Choose Keycloak if you need its advanced OAuth profiles, already maintain Java SPIs, or want Red Hat's supported distribution.

Choose Casdoor if you want a smaller service to operate, login pages your team can change without a deployment, built-in CAS, LDAP, and RADIUS servers, sign-in providers for the Chinese market, or first-class support for AI agents and MCP.

See also the comparison overview.