Platform · Analytics & Insights
See how your identity platform is really performing
We turn Keycloak's metrics and events into dashboards, alerts and reports — so your team spots login failures and capacity pressure early, and stakeholders get answers without anyone querying the database.
- Prometheus metrics & Grafana dashboards
- User event metrics by realm and client
- Alerting wired to your on-call
Standards & integrations
- Prometheus
- OpenMetrics
- Grafana
- Alertmanager
- OpenTelemetry
- PagerDuty / Opsgenie
Overview
From raw metrics to decisions
Keycloak already exposes a lot: HTTP, JVM, database pool and cache metrics on its management interface, plus counters for user events such as logins, failures and registrations. Out of the box, though, that data usually goes unused. We wire it into Prometheus and Grafana, decide which signals deserve an alert, and shape the rest into reports that answer the questions your security, product and platform teams actually ask.
What we deliver
- Metrics and user event metrics configuration for Keycloak
- Prometheus scrape configuration and recording rules
- Grafana dashboards for operations, security and product
- Alert rules with runbook links, routed to your on-call tool
- Capacity baseline for your Keycloak cluster
- Recurring stakeholder report template
Capabilities
What Analytics & Insights covers
Configured, tested and documented on upstream Keycloak — then handed over or operated by us.
Metrics enabled properly
Keycloak's metrics endpoint enabled and scraped from the management interface, kept off the public hostname, with HTTP histograms turned on where you need latency detail.
User event metrics
Login, logout, registration and error counters broken down by realm, client and identity provider, so a failing app or IdP stands out immediately.
Grafana dashboards
Dashboards for sign-in trends, error causes, active sessions, latency and cluster health, starting from Keycloak's published dashboards and extended for your realms.
MFA and passkey insight
Enrolment and usage trends for OTP, WebAuthn and passkeys, derived from credential and login events, so you can follow an MFA or passwordless rollout.
Alerting that means something
Alertmanager rules for failed-login spikes, error rates, latency and node health, routed to PagerDuty, Opsgenie or Slack with a runbook link on every alert.
Capacity insights
CPU, memory, database connection pool and cache metrics across your HA cluster, compared against Keycloak's sizing guidance so you scale ahead of peak traffic, not during it.
How it works
From first call to production
Decide what you need to know
We agree the questions each audience cares about — on-call engineers, security, product, leadership — and map them to metrics, events and thresholds.
Instrument and visualize
Metrics and user event metrics are enabled, scraped and retained, and dashboards and recording rules are delivered as code alongside your infrastructure.
Alert, report and tune
Alerts go live with runbooks, a recurring report goes to stakeholders, and thresholds are tuned against real traffic so on-call isn't flooded with noise.
Use cases
Where teams put it to work
Spotting attacks and outages early
A spike in failed logins for one client, or errors from one identity provider, shows up on a dashboard and in an alert before users start filing tickets.
Tracking an MFA or passkey rollout
Product and security teams follow enrolment and sign-in method trends week by week, without asking an engineer to pull numbers by hand.
Planning capacity for growth
Platform teams use real load and latency data to size the cluster ahead of launches, seasonal peaks or a migration wave.
FAQ
Analytics & Insights questions, answered
Does Keycloak expose Prometheus metrics natively?
Yes. With metrics enabled, Keycloak serves them in Prometheus / OpenMetrics format on its management interface, separate from the public HTTP port. We enable the right options and keep that endpoint off the internet.
Can we see logins per application?
Yes. Keycloak's user event metrics can be tagged by realm, client and identity provider, which gives per-application login and error trends without exporting raw events.
Where do deeper reports come from?
For questions metrics can't answer — such as which users have registered a passkey — we draw on Keycloak's stored events and Admin REST API, or stream events to your data platform through an event listener.
Do you replace our existing monitoring stack?
No. We plug into what you already run — Prometheus, Grafana, Datadog or a managed equivalent — and add the Keycloak-specific dashboards and alerts on top.
Ready to roll out Analytics & Insights?
Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.