The Identity Mutilator is
microscopic compared to Keycloak. It just does the two things it's supposed to do: let users log themselves in with 2FA, and then log them in to the applications they've been allowed to use.
My take is, if you were going to use Keycloak (or Shib or FreeIPA), you'd already be using Keycloak.