CI jobs
Trade their platform's OIDC token for a short-lived Keycroft token, checked against trust rules with guards against forks and untrusted triggers.
A Sealcroft project
Secrets management for CI/CD pipelines, Kubernetes workloads, and developers — without a single hardcoded credential.
A central hub and connectors, written in Rust. Self-hosted, source-available.
Keycroft is a hub you run on your own servers, with PostgreSQL as its only dependency, and a connector in each Kubernetes cluster. Everything that asks for a secret proves who it is with an identity its platform already issued, so none of them stores a Keycroft credential.
Trade their platform's OIDC token for a short-lived Keycroft token, checked against trust rules with guards against forks and untrusted triggers.
Sign in with their ServiceAccount token. An injected agent keeps values in process memory or on a RAM-only volume, or a CSI provider mounts them.
keycroft login signs in through the browser; the session sits in the OS keychain, bound to the machine's hardware key. keycroft run starts a program with its secrets.
Act as their own principals, each with a sponsor and limits, and use secrets through Keycroft's MCP server and brokered HTTP calls.
A root key protected by any external KMS, a PKCS#11 HSM, Shamir key shares, or peer unseal — or Keycroft KMS, a self-hosted KMS built from the same server.
Databases, cloud keys, and some seventy apps' credentials, with dry runs, checks before every run, and a grace period before anything is revoked.
A tamper-evident chain with a Merkle tree beside it, signed checkpoints kept outside Keycroft, and evidence packs an auditor checks offline.
A tenant is a namespace and a project made from a template. New versions roll out in waves after a dry run; offboarding destroys the tenant's key.
Every 1Password and Proton Pass item type, one-time codes for people and machines, attachments, and one-time share links.
From password managers, Vault and OpenBao, other secrets managers, the major clouds, .env files, Kubernetes, and CI platforms — read where the export lies, never uploaded.
Notifications to email, chat, and PagerDuty; audit sinks; a Terraform and OpenTofu provider that keeps values out of state; Keycroft's own OIDC issuer.
The REST API the web UI itself uses, described by an OpenAPI document published and signed with every release.
These are commitments of the agreed design; each is built and tested by the plan that implements it, and the threat model (milestone M0.4) will say what they don't cover.
Eleven milestones lead to 1.0.0, each released and soaked on a test environment with simulated users and teams before the next; a twelfth comes after it. There are no dates: the pace depends on the time available.
| Milestone | What it builds | Release | State |
|---|---|---|---|
| M0 Foundations | Threat model, crypto core, storage schema, CI and supply chain | 0.0.1-alpha.1 | In progress |
| M1 Server core | API, sign-in with MFA and SSO, access rules, secrets, audit, notifications, operations | 0.1.0 | Planned |
| M2 Machine identity & CI | OIDC sign-in for every CI platform, SPIFFE, the Terraform provider | 0.2.0 | Planned |
| M3 Web UI | The screens for everything in M1 and M2 | 0.3.0 | Planned |
| M3b Items & imports | Items, vaults, one-time codes, and every importer | 0.4.0 | Planned |
| M4 Kubernetes | Connectors, the injector and agent, CSI, the full Helm chart | 0.5.0 | Planned |
| M4b Tenancy | Templates, rollouts in waves, onboarding and offboarding | 0.6.0 | Planned |
| M4c Keycroft KMS | The self-hosted KMS, its approvals, and NetHSM support | 0.7.0 | Planned |
| M5 Rotation | The rotation engine and the whole app catalog | 0.8.0 | Planned |
| M5b AI agents | Agents and assistants, the MCP server, approvals | 0.9.0 | Planned |
| M6 Hardening | Load tests, documentation, an external security audit | 1.0.0 | Planned |
| M7 Hosted KMS | A Sealcroft-hosted KMS, rehearsed first and offered when it's ready | after 1.0 | Planned |
Keycroft will be source-available, not open source. Organizations will be free to run it for themselves, in production too, to read every line of it, and to change it for their own use — but never to distribute it, or a copy they've changed. Giving your own customers accounts in your Keycroft will need a commercial licence.
If Keycroft ever stops being maintained, its last version becomes open source under MPL 2.0, so no one who trusts it with their secrets is stranded. The exact terms will be published with the source.
Free forever inside your organization. No capability of Keycroft will ever move behind a paywall for use inside your own organization, or for personal use at home.
Keycroft has a single maintainer and doesn't accept code contributions; issues and feedback on the design are welcome.