IAM / CIAM Consultant
Identity and access management on Keycloak, OpenID Connect, OAuth 2.0, SAML and OpenFGA. Where Keycloak’s configuration stops, I write the Java extension that goes the rest of the way. I also work on Okta and Auth0.
What I do
-
Identity security review
Your OAuth 2.0 and OpenID Connect setup, reviewed against the OAuth 2.0 Security Best Current Practice (RFC 9700): flows, PKCE, redirect URIs, token lifetimes and storage, client authentication, MFA. Findings ranked by risk, each with a fix.
Fixed scope. The usual place to start.
-
CIAM platform
Design and build a customer identity platform on Keycloak: realm and client model, OIDC, OAuth 2.0 and SAML federation, MFA and passwordless, integration with CRM, billing and existing SSO. Includes the operational side: upgrades, monitoring and incident response.
Fits when you are launching a customer-facing product, or the identity layer was bolted on and is now the bottleneck.
-
Keycloak migration, upgrades and extensions
Move a legacy identity provider, home-grown authentication, or Okta or Auth0 to Keycloak without locking users out. Take an existing Keycloak estate through major version upgrades. Write custom Java extensions (authenticators, user federation, token mappers, event listeners, themes) where the product stops short.
Fits when you are running an unsupported version, have hit a limit you cannot configure around, or your Okta or Auth0 costs have outgrown the product.
-
Authorization design
Replace role checks scattered across services with one central, relationship-based model on OpenFGA, designed against your real access rules, not a textbook example.
Fits when “who can do what” is answered differently in every service.
What it produced
Clients are anonymised. Two of the engagements in full.
- Under 5 minutes
- of user-facing downtime on each of three major Keycloak upgrades.Web platform operator, several hundred sites
- 10,000+ users
- moved from in-house authentication to Keycloak with no planned downtime.SaaS company
- 1 model
- on OpenFGA for per-organisation access, in place of scattered role checks.SaaS company
Stack
Keycloak (including custom SPIs), Okta, Auth0, OIDC, OAuth 2.0, SAML 2.0, SCIM, FIDO2 / WebAuthn, token exchange, OpenFGA, Java, Spring Boot. ISC2 Certified in Cybersecurity.
Public code: keycloak-otp, email and SMS one-time-password authenticators for Keycloak 26.