It works with Hasura out of the box, you just can't set the x-hasura-default-role jwt claim dynamically and thus it has to be hardcoded. I evaluated keycloak with Hasura for our company, but settled on writing my own SSO solution, since my experience wasn't as great as others are describing.