# Descope vs Keycloak

**Leader by Vioscale score:** Descope

| Attribute | Descope | Keycloak |
|---|---|---|
| **Vioscale score** | 90.5 (72% (medium)) | 71.8 (47% (low)) |
| activity.commits_last_30d | - | 100 |
| adoption.dependent_repos | - | 1,153 |
| adoption.github_stars | - | 36,428 |
| adoption.package_downloads_weekly | - | 1,713,825 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | Descope is an identity and access management platform that enables developers to build and customize authentication flows for customers, partners, AI agents, and MCP servers. It offers drag-and-drop workflows, passwordless authentication, MFA, SSO, and token management with features designed to reduce friction while preventing account takeover. | Centralized authentication and authorization platform that manages user identity and access control across applications, reducing the need for individual apps to build their own login systems. |
| features.capabilities | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"cloud","saml_sso":true,"hosted_ui":"both","open_source":false,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` | `{"mfa":true,"oidc":true,"rbac":true,"hosting":"both","saml_sso":true,"hosted_ui":"both","open_source":true,"passwordless":true,"social_login":true,"b2b_multi_tenant":true,"passkeys_webauthn":true,"scim_provisioning":true}` |
| integrations.count | 50 | 10 |
| integrations.list | `[{"name":"Vercel"},{"name":"OpenAI"},{"name":"Google Calendar"},{"name":"Facebook"},{"name":"MCP servers"},{"name":"Email/SMS platforms"},{"name":"CRM platforms"},{"name":"CDP platforms"},{"name":"Audit solutions"},{"name":"Fraud detection systems"}]` | `[{"name":"GitHub"},{"name":"Google"},{"name":"Facebook"},{"name":"Twitter"},{"name":"LDAP"},{"name":"Active Directory"},{"name":"Kerberos"},{"name":"Kubernetes"},{"name":"Apache APISIX"},{"name":"OpenTelemetry"}]` |
| language.primary | - | Java |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"ios":true,"web":true,"android":true}` | `{"cli":true,"web":true,"linux":true,"windows":true}` |
| pricing | `{"type":"hybrid","plans":[{"free":true,"name":"Free Forever","summary":"Free tier with M2M and agentic identity essentials","description":"Includes M2M and agentic identity essentials available to all developers","contactSales":false},{"free":false,"name":"Pro","contactSales":false}],"summary":"Usage-based pricing with Monthly Active Consents (MAC), Monthly Active Tokens (MATK), and M2M Exchanges. Free tier available.","currency":"USD","freeTier":true,"sourceUrl":"https://www.descope.com/blog/post/m2m-agentic-identity-pricing-update","retrievedAt":"2026-08-14T08:38:03.189Z","billingPeriods":["month"]}` | `{"type":"open_source","summary":"Free, open-source software","freeTier":true,"sourceUrl":"https://www.keycloak.org","retrievedAt":"2026-08-14T13:39:48.793Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | open_source |
| pricing.price_level | low | free |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 13 |
| release.history | - | `[{"url":"https://github.com/keycloak/keycloak/releases/tag/nightly","date":"2022-09-27T02:22:00Z","type":"prerelease","version":"nightly"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.7.2","date":"2026-08-19T05:26:20Z","type":"stable","version":"26.7.2"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.7.1","date":"2026-08-05T15:54:37Z","type":"stable","version":"26.7.1"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.7.0","date":"2026-07-09T06:58:13Z","type":"stable","version":"26.7.0"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.6.4","date":"2026-06-26T19:19:51Z","type":"stable","version":"26.6.4"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.6.3","date":"2026-06-04T17:00:13Z","type":"stable","version":"26.6.3"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.6.2","date":"2026-05-19T12:41:03Z","type":"stable","version":"26.6.2"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.6.1","date":"2026-04-15T13:58:02Z","type":"stable","version":"26.6.1"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.6.0","date":"2026-04-08T08:54:19Z","type":"stable","version":"26.6.0"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.7","date":"2026-04-02T14:47:13Z","type":"stable","version":"26.5.7"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.6","date":"2026-03-19T06:45:39Z","type":"stable","version":"26.5.6"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.5","date":"2026-03-05T15:40:30Z","type":"stable","version":"26.5.5"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.4","date":"2026-02-20T09:19:45Z","type":"stable","version":"26.5.4"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.3","date":"2026-02-10T07:30:08Z","type":"stable","version":"26.5.3"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.2","date":"2026-01-23T14:26:58Z","type":"stable","version":"26.5.2"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.1","date":"2026-01-14T18:09:13Z","type":"stable","version":"26.5.1"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.5.0","date":"2026-01-06T07:42:32Z","type":"stable","version":"26.5.0"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.4.7","date":"2025-12-01T08:14:11Z","type":"stable","version":"26.4.7"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.4.6","date":"2025-11-25T17:32:43Z","type":"stable","version":"26.4.6"},{"url":"https://github.com/keycloak/keycloak/releases/tag/26.4.5","date":"2025-11-12T15:24:23Z","type":"stable","version":"26.4.5"}]` |
| reliability.sla_pct | 99.99 | - |
| reliability.status_page | yes | - |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.gdpr | yes | - |
| security.hipaa | yes | - |
| security.iso27001 | yes | - |
| security.pci | yes | - |
| security.scorecard | - | 7.9 |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":58,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.keycloak%3Akeycloak-core&per_page=100","last_12m":0,"max_severity":"CRITICAL"}` |

## Capabilities (Auth & Identity Software)

| Capability | Descope | Keycloak |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Methods** |  |  |
| Social login | ✓ | ✓ |
| Passwordless | ✓ | ✓ |
| Passkeys / WebAuthn | ✓ | ✓ |
| Multi-factor auth | ✓ | ✓ |
| **Enterprise** |  |  |
| SAML SSO | ✓ | ✓ |
| SCIM provisioning | ✓ | ✓ |
| B2B / multi-tenancy | ✓ | ✓ |
| **Standards** |  |  |
| OpenID Connect provider | ✓ | ✓ |
| **Delivery** |  |  |
| Hosted UI | Both | Both |
| **Access** |  |  |
| RBAC | ✓ | ✓ |
| **Licensing** |  |  |
| Self-hostable OSS core | ✗ | ✓ |

*Source: Vioscale. Generated 2026-09-01T17:10:52.536Z. "-" = undocumented, not absent.*
