Table of Contents

Increasing security - introduction of Keycloak

Julia Walther Updated by Julia Walther

From Session Management to Keycloak: Increased security and extension possibilities

To make Sweap even more secure in the future and to have the possibility to introduce more security features, we decided to migrate from a session management to a modern Identity and Access Management (IAM) based on Keycloak.

Keycloak is an open source identity and access management solution that simplifies user authentication and access rights management. This gives us the ability to provide new functionality. It is scalable, extensible and offers a range of features that are critical for both security and usability.

Enhanced security

Keycloak offers a variety of security features that go far beyond simple password verification. As a framework, it supports Single Sign-On (SSO) with OpenID Connect (OIDC), OAuth 2.0 and SAML 2.0, minimizing the risk of password theft.

With the ability to support multi-factor authentication (MFA), Keycloak significantly increases the security of user accounts. Users can use different methods for MFA, such as SMS, email, or hardware-based tokens.

Keycloak also provides protection against brute force attacks by monitoring a user's login attempts and temporarily locking accounts if too many failed login attempts are detected.

Introducing Keycloak from a user perspective

What does the introduction of Keycloak mean for you as a user? At first glance, you will not notice any visual change. In some cases, it may be necessary to update your password or e-mail address.

In the unlikely event that you are unable to log in, please contact our support.

Conclusion

The migration to Keycloak gives us the opportunity to introduce new features like session limitation, multi-factor authentication and the like step by step in the next weeks and months. As in the past, we will make sure that the introduction of new possibilities and product features goes hand-in-hand with the usual usability.

If you have any questions about security at Sweap, feel free to take a look at our articles:

Questions about security & data protection

Privacy policy and GDPR

Data tracking with Sweap

How did we do?

Sweap AI - Questions about security & data protection

Session limits - session limitation

Contact