To the second sentence: I don’t know what the benefit is either but in some environments you are not able to use any cloud provider or other external service to realize the auth layer so you are stuck with things like keycloak. Hope this thread discusses some other solutions which you can self host.
Setting up basic forward auth or OIDC was super easy though.
I mentioned Ory above but you get both options - either as a managed service or run on your own infra
I have clients that definitely prefer combination of open source + owner-controlled + lower costs ;)
Keycloak looks like a big complicated monster, so I would prefer to stay away except that it looks like I will be required to have all that complexity to support all the use-cases we are looking at.
https://zitadel.com/docs/apis/saml/endpoints
https://zitadel.com/docs/guides/integrate/identity-providers...
https://zitadel.com/docs/concepts/features/selfservice#mfa--...
https://zitadel.com/docs/guides/migrate/introduction#multi-t...
https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhos...