> Markdown version of [/videos/1661-keymate-modern-authorization-for-developers](https://www.wearedevelopers.com/videos/1661-keymate-modern-authorization-for-developers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Keymate – Modern Authorization for Developers Stop tangling authorization inside your application code. Keymate entirely decouples access control at the infrastructure level. Enjoy modern, event-driven security with absolutely zero code rewrites. - **Speakers:** [Halil Özkan](https://www.wearedevelopers.com/@halil-ozkan) - **Event:** World Congress 2025 - **Published:** August 20, 2025 - **Duration:** 6:04 - **URL:** https://www.wearedevelopers.com/videos/1661-keymate-modern-authorization-for-developers ## Summary Authorization is traditionally a developer pain point, often starting with basic rules but quickly deteriorating into unmanageable 'role explosion' hidden deep within application code. This tight coupling makes versioning, debugging, and tracing incredibly difficult. The modern, pragmatic approach is to decouple authorization logic entirely from the codebase so developers can focus solely on core business workflows. Keymate, an event-driven solution built as an extension of Keycloak, tackles this by shifting access control to the infrastructure level. By integrating directly with service meshes and API gateways, it intercepts traffic to enforce permissions without requiring any code rewrites or complex migrations. While Keymate provides SDKs across multiple languages and prioritizes gRPC for speed when granular control is strictly needed, the platform's core value lies in its zero-rewrite philosophy. Engineering teams also gain essential observability into access events through native OpenTelemetry integrations. To ease transition from legacy frameworks, Keymate supports a 'parallel run' strategy, allowing organizations to seamlessly bridge existing identity providers with the new modern system over time rather than attempting a risky, immediate cutover. **Keywords:** authorization decoupling, role explosion management, keymate platform, keycloak extensions, zero rewrite authorization, service mesh routing, api gateway enforcement, event-driven architecture, opentelemetry observability, infrastructure access control, identity provider integration, grpc performance, parallel run migration, legacy continuous integration, decoupled access logic ## Chapters 1. **Identifying challenges of hardcoding authorization logic** (00:05) — Embedding authorization into codebases leads to scaling issues like role explosion and poor observability. 1. **Integrating Keymate for zero-rewrite authorization management** (02:12) — Keymate extends Keycloak to handle authorization seamlessly without application code rewrites or mandatory identity provider migrations. 1. **Offloading authorization routing to service meshes and gateways** (02:58) — Decoupling authorization logic from the application by offloading enforcement to service meshes and API gateways reduces developer overhead. 1. **Providing fine-grained access control using language SDKs** (04:13) — Applying fine-grained access control with language-specific SDKs and fast gRPC calls provides developers with manual override capabilities. 1. **Tracking telemetry events and orchestrating parallel migration runs** (05:09) — Utilizing OpenTelemetry for event tracing enables simultaneous execution of legacy and new systems to ensure frictionless migrations. ## Related Moments - [Exploring the Keycloak open-source identity and access system](https://www.wearedevelopers.com/videos/1599-keycloak-case-study-making-users-happy-with-service-level-indicators-and-observability) (from "Keycloak case study: Making users happy with service level indicators and observability") - [Reviewing identity endpoints alongside specific Keycloak preview features](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) (from "Delegating the chores of authenticating users to Keycloak") - [Key components and history of the Keycloak project](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) (from "Delegating the chores of authenticating users to Keycloak") - [Navigating the complexities of authorization maintenance in applications](https://www.wearedevelopers.com/videos/889-un-complicate-authorization-maintenance) (from "Un-complicate authorization maintenance") - [Audience questions on security, limitations, and Kubernetes crossover](https://www.wearedevelopers.com/videos/732-kubernetes-dev-is-fun-but-setup-and-ops-isn-t-see-a-fun-paas-alternative-to-push-any-code-ipynbs-or-even-just-data) (from "Kubernetes dev is fun, but setup and ops isn't! See a fun PaaS alternative to push any code, ipynbs or even just data!") - [Introduction to Kubernetes security challenges and opportunities](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) (from "Kubernetes Security - Challenge and Opportunity") ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Liuba Gonta and Yuliya Khadasevic - GitHub Copilot Beyond the Basics - 10 Ways to Elevate Your Coding](https://www.wearedevelopers.com/magazine/490-liuba-gonta-and-yuliya-khadasevic-github-copilot-beyond-the-basics-10-ways-to-elevate-your-coding) - [Never delegate the understanding](https://www.wearedevelopers.com/magazine/749-never-delegate-the-understanding) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) ## Related Jobs - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Senior Backend Developer — AI: MCP & Agent Engine](https://www.wearedevelopers.com/jobs/48297-senior-backend-developer-ai-mcp-agent-engine) at **basebox GmbH** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Founding Mobile Engineer (iOS)](https://www.wearedevelopers.com/jobs/ext/1648532-founding-mobile-engineer-ios) at **Almedia** - [Lead Cloud DevSecOps Engineer - Kubernetes](https://www.wearedevelopers.com/jobs/ext/1659167-lead-cloud-devsecops-engineer-kubernetes) at **BWI GmbH**