One sign-on for several hundred websites
Web platform operator · Keycloak · remote, part-time
The problem
The operator ran several hundred web properties and needed single sign-on across all of them. There was no shared identity layer to extend. It had to be built from scratch, as one platform for the whole estate.
Constraints
- One engineer. I was the only identity engineer on the account: architecture, build and incident response.
- Part-time. The work fitted a fixed weekly budget, alongside a full-time job.
- Keycloak out of the box was not enough. The standard configuration did not cover everything the platform needed.
What I built
A Keycloak SSO platform serving the whole estate, up to 10,000 end users.
Three custom extensions, written in Java, where configuration stopped:
- A registration flow, for direct sign-up and for social login, that validates names and generates a unique username for each new account.
- Themes for the login pages and the emails, responsive and with dark mode.
- An event listener that mirrors new and verified users into the operator’s membership system, so both systems agree on who exists.
Then the upkeep. I took the platform through three major Keycloak version upgrades. Each ran blue/green: a parallel cluster on the new version, then a switch of traffic, so the running platform was never upgraded in place.
I still maintain the platform part-time. Recent changes, such as the email verification flow, are made with Claude Code.
Result
- Users sign in once and are signed in across several hundred properties.
- Three major upgrades, each with under 5 minutes of user-facing downtime.
- One person ran all of it, part-time.