Inteca » Case studies » Keycloak SSO & Identity Federation for 330,000 Users | Case Study

sso · identity federation · financial sector

Keycloak SSO and Identity Federation for 330 000 users

Inteca implemented a Keycloak-based SSO and identity federation solution connecting an online banking platform with leasing applications. The federated architecture allows customers to move seamlessly between the two environments without having to sign in again.

  • Fully clustered, highly available Keycloak deployment
  • Migration of user data from existing CIAM systems
  • Federated SSO between banking and leasing applications

330 000
end users
6
month implementation
4
person project team
User logging into mobile banking app showing secure Keycloak SSO experience

Technologies and solution areas

Keycloak

Keycloak SSO

Identity federation

Federated SSO

OpenShift

OAuth 2.0

OpenID Connect

Customer Identity and Access Management (CIAM)

Identity Lifecycle Management

Customer self-service portal

Client

A financial institution operating in the leasing sector

The client is a financial institution operating in the leasing sector. Together with its banking partner, it was developing a shared digital journey for corporate customers. The goal was to make leasing services available directly through the online banking platform, creating a seamless experience in which customers would not feel they were moving between two separate systems and two separate accounts.

The business objective was to use the bank’s existing customer base as a new distribution channel for leasing products.

Client profile

Case study anonymized at the client’s request

Industry
Financial services
Segment
Leasing
Market
Poland
Scale
300,000+ users

This case study has been anonymized at the client's request. The company and its banking partner are therefore not disclosed, while the project scope, technologies and results are presented in full.


Challenge: Separate User Identities and Two Login Processes

Two platforms, two logins, one customer

The same corporate customer existed separately in the bank’s systems and in the leasing company’s systems - with separate accounts, registration processes, and customer records. Every transition between the two environments required the user to authenticate again. Onboarding for a leasing product also had to start from scratch, even though the bank already held the necessary company data and documentation.

Making leasing products available to bank customers — including information about their existing leases and potential new leasing opportunities.

Enabling a seamless transition between banking and leasing applications within a single authentication flow.

Streamlining corporate customer onboarding by reusing data already held by the bank instead of collecting the same documents again.

Migrating user data from existing Customer Identity and Access Management (CIAM) databases and implementing a new authorization server supporting OAuth 2.0 and OpenID Connect.


Solution: Keycloak SSO and Identity Federation

Keycloak as the central authentication and federation layer

Inteca designed and implemented a Keycloak-based identity federation architecture connecting the bank and the leasing company. Both organizations remained separate environments, but Keycloak provided the authentication and federation layer required to create a consistent user journey across their applications.

For the end user, this resulted in a unified experience: a customer authenticated in the banking environment could move into the leasing applications without going through another independent login process. The Keycloak environment was deployed on OpenShift as a fully clustered, highly available solution designed to support a growing customer base.

Federated SSO with Keycloak

The solution enabled Keycloak SSO across banking and leasing applications, allowing users to authenticate once and move seamlessly between systems.

Customer Account Lifecycle

The platform supported the customer account lifecycle from onboarding and permission changes through to account deactivation.

Customer Self-Service Portal

Customers could independently update information such as their password or email address without contacting a call center or submitting a support request.

Migration from Existing CIAM Systems

User data was migrated from the existing CIAM databases to the new Keycloak-based authentication and authorization environment.

High-Availability Keycloak on OpenShift

Keycloak was deployed as a scalable, fully clustered solution on OpenShift, providing high availability and the capacity required to support continued growth in the number of users.


Implementation

Six months from architecture design to production

The project was delivered by a four-person Inteca team working directly with both the bank and the leasing company. This setup made it possible to coordinate architectural and integration decisions across both organizations without additional intermediaries.

01

Designing the Identity Federation Architecture

Inteca designed the federation model and the authentication and authorization processes required to connect the two organizations and their application environments.

02

Deploying Keycloak

The team deployed and configured Keycloak with OAuth 2.0 and OpenID Connect support on a clustered OpenShift platform.

03

User Migration and System Integration

User data was migrated from existing CIAM systems, and Keycloak was integrated with the leasing company's existing application and communication channels.

04

Production Launch and Scaling

The solution was launched in production, customer self-service capabilities were made available, and the environment was prepared to support continued growth in the user base.


Results

A new sales channel and lower customer service costs

The implementation enabled the leasing company to meet its business objectives around sales growth and customer acquisition while providing users with a significantly more seamless digital experience.

Sales growth — the leasing company gained a new sales channel based on the bank's existing customer base.

Expanded customer base — the new federated customer journey supported seamless onboarding and access for approximately 330,000 end users.

Improved customer experience — federated SSO removed unnecessary authentication steps, while self-service functionality reduced the need to contact customer support.

Lower operating costs — customer self-service reduced the operational effort required to manage common account-related requests.

Built for future growth — the scalable, clustered Keycloak deployment on OpenShift was designed to accommodate additional users and future requirements.

Planning a Keycloak SSO or identity federation project?

Inteca designs and implements enterprise Keycloak SSO and identity federation solutions, including integration with existing enterprise applications, migration from legacy CIAM environments, OAuth 2.0 and OpenID Connect integration, and deployment on customer-controlled infrastructure.