Mastodon

Single Sign On (SSO)

Information on our SSO system.

General documentation on our SSO system

Single Sign-On (SSO) is a technology that allows users to log in once and access multiple applications without the need to log in again. Keycloak is the SSO system offered by our company that provides managed hosting services. It simplifies the authentication process and enhances the user experience.

SSO with Keycloak - features

At Cloud68.co we use Keycloak, an well established open source platform, for user authentication. This is very helpful when you have more than one instance with us. Below are the main features of our SSO solution with Keycloak:

Benefits of using Keycloak for your SSO needs

Getting SSO for your infrastructure

Our SSO solution is available free of charge for all users that have at least three (3) managed hosting software (instances) on an active billing cycle.If you need less than three instances, the cost for the Managed Hosting Keycloak instance is 9Eur/month.

Keep in mind that not all platforms available on our website from this page support Keycloak and/or SSO for authentication.

How to configure Passkeys

Below is a step-by-step guide how to configure passkeys as an authentication method for Keycloak. 

First step is to go to your Keycloak URL instance and login using your SSO credentials. 

Upon login, you will land on the Keycloak Console

Screenshot From 2026-01-26 11-59-50.png

Once there you need to go to Account Security and click Signing in which will open the authentication options. 

image.png

Click on Set up Passkey, and it will take you to a window to register the passkey as seen below. 

Screenshot From 2026-01-26 12-02-42.png

Follow the steps and configure your passkey, and you will be able to log in using your Titan keys. 

There is also a way for users to enforce this way of authenticating and when the user logs in, it is required to set it up following the steps above, but this is only if all Keycloak users will use this method of authentication. 






How to terminate all sessions for a user on Keycloak

  1. Login to Keycloak and go to Users on the left panel.
  2. Locate the user and click on the name to open their options. 
  3. Go to Sessions, last button on the panel and Logout all sessions.

    image.png


 

 

Adding your logo and other visual elements (branding)

Unfortunately, you cannot make branding or visual customisations to your Keycloak instance directly. Changes such as uploading a logo, adjusting colours, or modifying other visual elements require modifications at the theme level, which fall outside the scope of what is accessible under our current Keycloak Managed Hosting setup and workflows.

To have these changes applied, you will need to open a support ticket as described in our Tech Support (FAQs) documentation.

This service is provided free of charge for all subscribers who are receiving our Add-On services.

How to change your password on Keycloak

Go to your Keycloak Console and Log in with your credentials.

Once logged in, go under Account Security → Signing in. 

Under Basic authentication you will see and Update button next to My Password. 

image.png

In case you do not know your Keycloak Login URL, please reach out to our Support Team.

 

How to setup 2FA on Keycloak

Go to your Keycloak Console and Log in with your credentials.

Once logged in, go under Account Security → Signing in. 

Under Two-Factor authentication click on Set up Authenticator application and follow the steps.

image.png

In case you do not know your Keycloak Login URL, please reach out to our Support Team.

How to create a user on Keycloak

In order to create a new user on Keycloak follow the steps below.

1. Visit Admin Dashboard:

  - Go to:  Your Keycloak URL
  - Log in using the admin account.

2. Create a New User:

  - Navigate to Users on the left side of the dashboard.

image.png

  - Click on Add User.

image.png

  - Under Required user actions, select Update Profile.

In case user impersonation is required leave this empty.

image.png

  - Set Email Verified to ON.

image.png

  - Fill in the Username, Email, First Name

image.png


  - Click Join Groups and add the user to the group it belongs.

image.png

  - Click Create

image.png



3. Send Password Reset Request:

  - Go to Users.

image.png

  - Click on the newly created user.

image.png

  - Navigate to Credentials and click Set a Password.

image.png

In case user impersonation is required toggle "Temporary" to Off so it does not require setting up a password when impersonating.

image.png

- Click Credentials Reset.

image.png

In case you followed the user impersonation steps, on this step choose Update password and Update Profile

image.png

- Choose an expiration time for the reset request and click Send. 

image.png



  - Notify the user that they now have an account and will receive an email to reset their password and update their profile.

In case you do not know your Keycloak URL reach out to our support team