Adaptive Auth
for Keycloak.
Humifortis is the identity risk control plane that sits on top of your existing IAM. It scores every login in real time, then lets Keycloak step-up MFA or block the moment risk crosses your threshold — without replacing your stack.
- Deploy on-premise or in the cloud
- Drop-in Keycloak connector — no code changes
- No user data leaves your network
{
"entity_id": "u-83bd9f",
"entity_type": "user",
"risk_score": 88,
"risk_level": "HIGH",
"decision": "step_up_mfa",
"confidence": 0.91,
"contributing_factors": [
"impossible_travel",
"new_device",
"failed_login_burst"
]
}On-premise is first-class — not an afterthought.
Run the entire risk engine inside your own network or air-gapped environment. No telemetry, no vendor dependency, full data sovereignty. Same product, same connector, your infrastructure.
Built for security teams who care about clarity
Every login scored, every decision explained, every signal surfaced.
Entity risk profile
See the live risk score per user, device or API key — with every contributing factor explained.
Risk timeline
A complete, timestamped audit of every signal that touched the score — transparent and exportable.
Rule telemetry
Monitor every detection rule in production — fire rates, impact weights and trend over time.
Signal coverage
Full map of active detection rules, threat categories and configurable thresholds — no black box.

Real-time risk score with contributing factors, confidence level and the Keycloak decision — allow, step-up MFA or block.
Risk-based decisions in three steps
Observe the signals you already produce. Score them in milliseconds. Enforce the right response at login.
Observe
Login attempts, device fingerprints, geo, velocity and behaviour flow in from Keycloak and your existing tools.
Score
An incremental, decaying risk score is maintained per user, device and API key — updated in under 10 ms, fully auditable.
Enforce
Keycloak steps up to MFA, allows, or blocks based on your policy. Fail-open by design — never locks out your users.
Everything you need for adaptive login
Built for security and identity teams who run Keycloak.
Drop-in Keycloak connector
Install the authenticator, point it at Humifortis, and every login is scored. No code changes to your apps.
Real-time step-up
Trigger MFA, deny, or allow within the login flow — decisions in milliseconds, not batch jobs.
Transparent scoring
Every decision shows its contributing factors. Configurable rules, no opaque black-box models.
Signals that matter
Impossible travel, new device, geo-velocity, failed-login bursts and behavioural anomalies — out of the box.
CAEP & webhooks
Push shared-signals events to downstream systems and revoke sessions the instant risk spikes.
Privacy by design
Minimal retention, no raw logs, no PII stored. On-premise keeps everything inside your perimeter.
Modern adaptive auth,
on the IAM you already run.
Keycloak is powerful but static: it doesn't know when a login feels wrong. Humifortis adds the missing risk layer — and gives your team a modern UI to see it happen.
- No rip-and-replace: keeps your realms, flows and users exactly as they are.
- Policy you control: set the thresholds for allow, step-up and block.
- Extensible: the same API protects APIs, gateways and custom apps beyond Keycloak.

Start free. Scale when you're ready.
Cloud plans below. Prefer on-premise? Available on Enterprise and Custom.
Free
For evaluation and small projects.
- 1 Keycloak realm
- Up to 5,000 risk evaluations / month
- Core signals & step-up MFA
- Community support
Enterprise
For teams running Keycloak in production.
- Unlimited realms & users
- High-volume risk evaluations
- CAEP, webhooks & session revocation
- On-premise deployment option
- SSO, priority support & SLA
Custom
For regulated & air-gapped environments.
- Everything in Enterprise
- Air-gapped / fully on-premise
- Custom signals & integrations
- Dedicated onboarding & support
Questions teams ask before adopting
What exactly does Humifortis do?
+It adds adaptive authentication to Keycloak. Humifortis maintains a real-time risk score for every user, device and API key, and lets Keycloak decide — in the login flow — whether to allow, require step-up MFA, or block. It's an identity risk control plane on top of your existing IAM, not a replacement.
How does it integrate with Keycloak?
+Through a drop-in Keycloak authenticator (connector). Add it to your authentication flow and point it at Humifortis. Every login is scored and the connector enforces your policy. No changes to your applications, realms or users are required.
Can I run it fully on-premise?
+Yes — on-premise is first-class. The entire risk engine runs inside your own network or an air-gapped environment. No telemetry or user data leaves your perimeter. Available on Enterprise and Custom plans.
Is the scoring a black box?
+No. Every decision exposes its contributing factors (impossible travel, new device, failed-login burst, and so on) and the score is computed with transparent, configurable rules and temporal decay. You set the thresholds; you can audit every outcome.
What happens if Humifortis is unavailable?
+The connector is fail-open by design. If the risk engine is unreachable, Keycloak falls back to your normal authentication flow — users are never locked out. Removing Humifortis is simply a matter of taking the authenticator out of the flow.
See adaptive authentication on your Keycloak.
Explore the live demo, or book a walkthrough with the team.
Talk to the team
Questions about deployment, pricing or a custom integration? We respond within one business day.