Sovereign alternative to Okta, Auth0, Entra ID
FerrisKey IAM managed, hosted in Europe
The open-source IAM written in Rust, OIDC-compatible with Keycloak, operated for you in Europe. One single sign-on for every service, multi-organization realms, and identities you can bring back in-house whenever you decide.
What the managed service covers
FerrisKey is an open-source identity and access management (IAM) server, written in Rust and released under the Apache-2.0 licence. It exposes the same OpenID Connect URLs as Keycloak, so your applications connect to it without a rewrite. Bunker hosts and operates it in Europe.
Deployment and updates
We install, configure and keep the latest stable version up to date. You have no server to administer.
Encrypted backups
Daily encrypted backups, kept in Europe. A restore is one ticket away.
Monitoring and security
Monitoring, security patches and firewall handled continuously by our team.
Human support
A team that answers on software it operates itself.
- OIDC single sign-on for every service
- Multi-organization realms
- Identity brokering (hub-and-spoke federation)
- Self-service admin UI
Hosted in Europe, outside US jurisdiction
Okta, Auth0 and Entra ID centralize your whole organization's authentication on infrastructure subject to US law: every login, every identity, every group transits there. FerrisKey hosted in Europe keeps that identity directory on the continent, under EU law, and stays re-internalizable: both the software and the data can move back onto your own infrastructure.
- Servers physically in Europe, operated by a European company.
- A European company, outside the scope of the US CLOUD Act and FISA.
- No subcontracting to a US hyperscaler.
- Re-internalizable: you can bring the service back onto your own servers.
Frequently asked questions
Is FerrisKey compatible with my Keycloak applications?
Yes. FerrisKey exposes the same OpenID Connect endpoints as Keycloak (/.well-known/openid-configuration, /realms/<realm>/...). An application configured for Keycloak connects to it by simply changing the issuer URL.
How does multi-organization federation work?
Bunker operates a central FerrisKey that brokers authentication to a FerrisKey dedicated to your organization. Each organization keeps its own realm, users and rules, and can export everything to re-internalize it.
Can I get my identities back if I leave?
Yes, at any time. FerrisKey is open source (Apache-2.0): you export your realm configuration and your users, and you can bring the service back onto your own infrastructure. No proprietary format, no lock-in.
Deploy FerrisKey in Europe
We handle hosting, updates and backups. You keep control of your data, and the ability to bring everything back in-house whenever you decide.