Best VPS for Keycloak in 2026
Updated Oct 2026 · 8 plans compared
Keycloak is the enterprise-standard identity server — Java and Quarkus under the hood, with the deepest SAML and LDAP federation of any open-source IdP, backed by over a decade of production use at banks and large organizations. That maturity comes with real weight: a JVM process, an admin console, and (once you leave dev mode) an external Postgres database all need to run reliably, because an IdP going down locks you out of everything behind it. If Keycloak's enterprise depth feels like more than you need, the authentik-vs-Keycloak and Keycloak-vs-Zitadel comparisons cover the lighter alternatives; the picks below assume you've decided Keycloak is the right tool and just need a box that runs it well.
- Keycloak's start-dev quickstart uses an embedded H2 database — fine for a five-minute trial, wrong for anything real. Production Keycloak needs an external Postgres instance, so size and budget for both the JVM process and a database, not just the container.
- The JVM has its own memory behavior: a cold start and realm import both spike RAM well above Keycloak's steady-state footprint. Don't size to the idle number — give it headroom for startup and for the admin console under load.
- Every OIDC/SAML client Keycloak serves depends on it being reachable — that's the trade of running your own IdP instead of authentik or Zitadel. Put TLS in front of it from day one (redirect URIs have to be https) and take backups of the database seriously; losing the realm config locks every downstream app out at once.
- If Keycloak's Java footprint and admin-console depth are more than your use case needs, it's worth reading how it stacks up against authentik's flow-based builder or Zitadel's Go-based, multi-tenant design before committing a VPS to it.
The picks
The $6/mo 2 GB plan (1 vCPU / 2 GB / 30 GB NVMe) is custom-sized instead of over-provisioned, and the 30-day free trial is a reasonable way to test an OIDC or SAML realm migration before paying for it.
CPX12 (1 vCPU / 2 GB / 40 GB NVMe, $14.09/mo) is the Hetzner box you can order today — the $7.09 CX23 has been out of stock since 2026-09 — and it costs more than the others here, but it's the natural pick if you're already running other self-hosted apps on Hetzner and want Keycloak on the same account rather than splitting providers.
VPS-1 (2 vCPU / 4 GB / 40 GB NVMe, $4.54/mo) is the cheapest plan here that clears Keycloak's real footprint with room to spare for a companion Postgres instance, and unlimited traffic is one less thing to budget for once federated logins are flowing through it.
Cloud VPS 4 (4 vCPU / 8 GB / 100 GB NVMe, $4.95/mo) is a rounding error more than OVHcloud but doubles the RAM and cores — useful headroom for the JVM's startup memory spike and for running Postgres on the same box instead of a second server.
The picks, side by side
Prices verified Oct 2026 · How we benchmark →
Common questions
How much RAM does Keycloak need?
Keycloak's own minimum is 1 GB, but that's the JVM process alone. Once you add an external Postgres database (required in production — the embedded H2 database is dev-only) and headroom for the JVM's startup memory spike, a 2 GB VPS is the realistic floor.
Can I run Keycloak's embedded database in production?
No. The start-dev quickstart uses an embedded H2 database, which the Keycloak project explicitly scopes to evaluation and local development. A production deployment needs an external Postgres (or another supported database) that you back up independently of the app server.
Is Keycloak overkill for a small self-hosted setup?
Often, yes. Keycloak's depth is enterprise SAML and LDAP federation — if you just need OIDC login across a handful of self-hosted apps, authentik's flow-based builder or Zitadel's lighter Go-based design (see the authentik-vs-Keycloak and Keycloak-vs-Zitadel comparisons) get you there with less to run and less to lock yourself out of.