---
title: "Auth Templates: Deploy Keycloak, Vaultwarden, and More"
description: "Deploy authentication templates on Railway in one click. Run Keycloak, Vaultwarden, and other identity tools on always-on infrastructure."
url: https://railway.com/deploy/category/authentication
---

# Deploy authentication services in one click

Templates in this category deploy identity and security services in one click. Keycloak covers SSO, MFA, and OIDC. Vaultwarden runs a Bitwarden compatible password vault. Infisical manages secrets, and Cap adds a self-hosted CAPTCHA.

Each template creates the service with its database and variables preconfigured in your own project, running 24/7 with usage based pricing and a free trial.

## Common questions about Authentication templates

### How do I self-host Keycloak?

Deploy a Keycloak template and Railway creates the service with its configuration preconfigured. It runs on always-on servers, so sign-ins work around the clock.

### Can I run a self-hosted password manager?

Yes. Vaultwarden, a Bitwarden compatible server, deploys in one click and keeps its data inside your own project.

### Do authentication templates work with my existing app?

Yes. Services in the same project connect over private networking, and standard protocols like OIDC work the same as anywhere else.

### Is my authentication service always on?

Yes. Templates run on always-on servers with no cold starts, which matters for login flows. Nothing sleeps unless you turn on App Sleeping.

## Related

- Browse all templates: https://railway.com/deploy
- Railway docs: https://docs.railway.com

Open this page in a browser: https://railway.com/deploy/category/authentication
