Digital identities are essential for digital sovereignty, as they allow access to applications and data. Whoever manages these identities controls application access and data flow. A self-managed identity access management (IAM) tool like Keycloak provides full control over employee and customer digital identities. It can be integrated with your applications using OpenID Connect and SAML, and authenticate your users securely with second factors or passkeys. Keycloak can be hosted on premise or in the cloud—and move as your business needs change. Choose the features you want, customize them where needed, build on existing infrastructures like Lightweight Directory Access Protocol (LDAP) and Kerberos, and integrate it with other identity providers via federation across organizations. I’ll show how to implement and self-host digital identities, with case studies for e-government, banking, and startups. We’ll also review the latest features and roadmap of the project.