For your Keycloak
Keep your stack.
Add a boundary.
Add device approval to the sign-in flow you already run. Your applications keep using Keycloak.
- Native Keycloak integration
- Your existing applications
- No browser extension
A device check at sign-in
Know more than the password.
Your identity provider checks the person. TrustFlare adds a registered device and a fresh signature to the decision.
Compare
What 1Password XAM does — for your Keycloak
Western device-trust products are tied to a cloud and to Okta, Google, Entra. A company that chose Keycloak to keep control of identity cannot buy them at all.
| Capability | TrustFlare | Kolide / 1Password XAM | MDM + EDR | Client certificates |
|---|---|---|---|---|
| Core in the cloud; Ultimate — yours | Yes | No, their cloud only | Partial | Yes |
| Keycloak | Yes, native SPI step | No — Okta, Google, Entra only | Not about SSO | Yes, x509 flow |
| Personal devices and contractors | Yes, no admin rights | Yes | No — legal and operational | Needs PKI and manual issuance |
| Rollout | Straightforward | Straightforward | Needs MDM, heavy install | Hard — per-device setup |
| Time to production | A plugin in the Keycloak you have | Often unavailable | Months to years | Needs a CA/SCEP stack |
| Price per 1000 users / year | $24k — per user, every device included | ≈ $72–96k + XAM, billed per device | $36–100k for EDR alone | Cost of a PKI team |
Ultimate
Ultimate: the core is yours
Self-hosted core: on-prem or air-gapped, data does not leave the perimeter. That is a separate value for an enterprise customer, not the default path. On Free and Business the core runs in TrustFlare cloud.
Questions
What a Keycloak engineer asks
How does it fit into sign-in?
The Keycloak authenticator checks the core’s device decision. An approved, valid device can continue through the sign-in flow.
Do we need a certificate rollout?
TrustFlare uses signed device data and an approval registry without requiring a client-certificate rollout.
What reaches TrustFlare cloud?
Sign-in username, IP, user agent and device inventory. Passwords, sessions and Keycloak secrets stay with you. Trials run for 14 days; trial data are deleted after 30 days.
Can we host the core ourselves?
Customer-hosted delivery is available under Ultimate. Free and Business use TrustFlare cloud.
Pilot
Try it with your Keycloak.
Start with a few devices and review the results with your team.