// Engineering Log
Accounts and SSO: Part 2 — FusionAuth
Published on 2026-09-22
// Fast route
This article belongs to the topic Python and automation.
FusionAuth — an authentication and user management server that developers built around an API: anything you can do in the admin panel can be done via REST API. You can host it on your own servers for free or use the cloud version from the vendor.
Licensing model
The main thing to know before choosing: FusionAuth is not an open source project. The Community edition is free and can be installed on your own servers, but the code is closed. This distinguishes it from Keycloak, where all code is open under the Apache 2.0 license.
Pricing as of September 2026 (according to the FusionAuth website):
| Plan | Price | Notes |
|---|---|---|
| Community | free | unlimited users, self-hosting, support — forum |
| Starter | from $162/month | paid features, support |
| Essentials | from $2,970/month | advanced security features and support |
| Enterprise | from $2,970/month and up | custom terms |
Running FusionAuth on your own servers is allowed on all plans. The SAML v2 protocol is included in all plans, including the free one — the previous claim that SAML is only available for a fee is incorrect.
Features
- OAuth 2.0, OpenID Connect and SAML v2 — sign-in for web and mobile apps and enterprise systems.
- User registration and profiles, application-level groups and roles.
- Multi-factor authentication and login via external providers.
- An API for every action and client libraries for popular languages — useful when accounts are created from code, for example during registration in your product.
- Webhooks for events: registration, login, user changes.
How to run
The official way to try it is Docker Compose from the fusionauth-containers repository:
curl -o docker-compose.yml https://raw.githubusercontent.com/FusionAuth/fusionauth-containers/main/docker/fusionauth/docker-compose.yml
curl -o .env https://raw.githubusercontent.com/FusionAuth/fusionauth-containers/main/docker/fusionauth/.env
# in .env replace the database passwords
docker compose up -dThe installation consists of FusionAuth itself, a database (PostgreSQL by default or MySQL) and a search service OpenSearch or Elasticsearch. According to the documentation search is formally optional, but it is present in the standard build. The admin panel is exposed on port 9011; on first login a setup wizard runs.
For production you need the same precautions as for any authentication server: HTTPS on a reverse proxy, a database with backups, restricted access to the admin panel and regular updates.
Comparison with Keycloak
| FusionAuth Community | Keycloak | |
|---|---|---|
| Source code | closed | open, Apache 2.0 |
| Cost of self-hosting | free | free |
| Protocols | OAuth 2.0, OIDC, SAML v2 | OAuth 2.0, OIDC, SAML 2.0 |
| Approach | API and developer-oriented | admin panel and configuration |
| Community | smaller | large, CNCF project |
Limitations
- Closed source. You cannot audit or fix the code yourself, and the terms of the free edition are determined by the vendor.
- Price of paid plans. The gap between Starter and Essentials is large; for a small company paid features may be unaffordable.
- Russia. The cloud version and paid plans are paid with a foreign card; Visa and Mastercard issued in Russia do not work abroad. The free edition on your own server in Russia does not depend on payment, and user data stays with you, which complies with the requirement to store citizens’ personal data in databases located within the country.
Common mistakes
- Assuming FusionAuth is an open source project and planning for a code audit or fork.
- Leaving the database passwords from the example
.env. - Exposing port 9011 with the admin panel to the internet without a reverse proxy and access restrictions.
- Not making database backups: all users and settings are stored there.
When to choose
FusionAuth is convenient if you are building a product and want to manage users from code via a clean API, and open source is not a requirement. If openness, a large community and integration with corporate directories are important, Keycloak is a more logical choice.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Python and automation
Bots, integrations, internal services, process automation, and workflows.
Typical tasks behind this topic
- Build a bot, integration, or internal tool
- Remove manual routine with Python and APIs
- Connect services and automate the full workflow
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related