For your Keycloak

Keep your stack.
Add a boundary.

Add device approval to the sign-in flow you already run. Your applications keep using Keycloak.

  • Native Keycloak integration
  • Your existing applications
  • No browser extension

A device check at sign-in

Know more than the password.

Your identity provider checks the person. TrustFlare adds a registered device and a fresh signature to the decision.

KeycloakA native authenticator in your sign-in flow
DevicesA registry of computers approved by your organization
PolicyYour rules for enrollment and approval

Compare

What 1Password XAM does — for your Keycloak

Western device-trust products are tied to a cloud and to Okta, Google, Entra. A company that chose Keycloak to keep control of identity cannot buy them at all.

CapabilityTrustFlareKolide / 1Password XAMMDM + EDRClient certificates
Core in the cloud; Ultimate — yoursYesNo, their cloud onlyPartialYes
KeycloakYes, native SPI stepNo — Okta, Google, Entra onlyNot about SSOYes, x509 flow
Personal devices and contractorsYes, no admin rightsYesNo — legal and operationalNeeds PKI and manual issuance
RolloutStraightforwardStraightforwardNeeds MDM, heavy installHard — per-device setup
Time to productionA plugin in the Keycloak you haveOften unavailableMonths to yearsNeeds a CA/SCEP stack
Price per 1000 users / year$24k — per user, every device included≈ $72–96k + XAM, billed per device$36–100k for EDR aloneCost of a PKI team

Ultimate

Ultimate: the core is yours

Self-hosted core: on-prem or air-gapped, data does not leave the perimeter. That is a separate value for an enterprise customer, not the default path. On Free and Business the core runs in TrustFlare cloud.

Ultimate column on the price page →

Questions

What a Keycloak engineer asks

How does it fit into sign-in?

The Keycloak authenticator checks the core’s device decision. An approved, valid device can continue through the sign-in flow.

Do we need a certificate rollout?

TrustFlare uses signed device data and an approval registry without requiring a client-certificate rollout.

What reaches TrustFlare cloud?

Sign-in username, IP, user agent and device inventory. Passwords, sessions and Keycloak secrets stay with you. Trials run for 14 days; trial data are deleted after 30 days.

Can we host the core ourselves?

Customer-hosted delivery is available under Ultimate. Free and Business use TrustFlare cloud.

Pilot

Try it with your Keycloak.

Start with a few devices and review the results with your team.

How should we reach you *