IAM / CIAM Consultant

Identity and access management on Keycloak, OpenID Connect, OAuth 2.0, SAML and OpenFGA. Where Keycloak’s configuration stops, I write the Java extension that goes the rest of the way. I also work on Okta and Auth0.

What I do

  • Identity security review

    Your OAuth 2.0 and OpenID Connect setup, reviewed against the OAuth 2.0 Security Best Current Practice (RFC 9700): flows, PKCE, redirect URIs, token lifetimes and storage, client authentication, MFA. Findings ranked by risk, each with a fix.

    Fixed scope. The usual place to start.

  • CIAM platform

    Design and build a customer identity platform on Keycloak: realm and client model, OIDC, OAuth 2.0 and SAML federation, MFA and passwordless, integration with CRM, billing and existing SSO. Includes the operational side: upgrades, monitoring and incident response.

    Fits when you are launching a customer-facing product, or the identity layer was bolted on and is now the bottleneck.

  • Keycloak migration, upgrades and extensions

    Move a legacy identity provider, home-grown authentication, or Okta or Auth0 to Keycloak without locking users out. Take an existing Keycloak estate through major version upgrades. Write custom Java extensions (authenticators, user federation, token mappers, event listeners, themes) where the product stops short.

    Fits when you are running an unsupported version, have hit a limit you cannot configure around, or your Okta or Auth0 costs have outgrown the product.

  • Authorization design

    Replace role checks scattered across services with one central, relationship-based model on OpenFGA, designed against your real access rules, not a textbook example.

    Fits when “who can do what” is answered differently in every service.

What it produced

Clients are anonymised. Two of the engagements in full.

Under 5 minutes
of user-facing downtime on each of three major Keycloak upgrades.Web platform operator, several hundred sites
10,000+ users
moved from in-house authentication to Keycloak with no planned downtime.SaaS company
1 model
on OpenFGA for per-organisation access, in place of scattered role checks.SaaS company

Stack

Keycloak (including custom SPIs), Okta, Auth0, OIDC, OAuth 2.0, SAML 2.0, SCIM, FIDO2 / WebAuthn, token exchange, OpenFGA, Java, Spring Boot. ISC2 Certified in Cybersecurity.

Public code: keycloak-otp, email and SMS one-time-password authenticators for Keycloak 26.

Send your identity stack, the problem, and the timeline.

ante.rados@delmisoft.hr