Skip to content
Keenpix vs imgproxy

Keenpix vs imgproxy: managed delivery or a self-hosted engine

imgproxy is a fast, mature image-processing server you operate. Keenpix combines an open-source path with a managed image CDN, a dashboard, usage analytics, and one delivered-GB cloud meter. The real choice is ownership, not a fake feature-score winner.

Bottom line

The honest verdict

Choose imgproxy when your team wants direct control of the transform service, already operates containers and a CDN, values its Apache-2.0 core license, or needs an imgproxy-specific processing feature. Choose Keenpix managed cloud when you want a vendor to operate transformation, delivery, caches, usage metering, analytics, abuse controls, and updates behind one service. imgproxy open source has no license fee, but that is not a zero-cost delivery system: compute, egress, CDN, storage, observability, on-call work, upgrades, and capacity remain yours. imgproxy Pro starts at $49/month or $499/year for up to 16 workers and adds advanced features and support; infrastructure remains separate. Keenpix starts at $9/month for 100 GB of managed delivery with published overage. Keenpix is a younger, solo-founder product and imgproxy has a mature standalone engine with a broad processing surface, so teams that already own the platform work may rationally prefer imgproxy.

Disclosure and source policy

Keenpix publishes this comparison and benefits if you choose Keenpix. Vendor facts were checked against the primary sources listed here in August 2026. Pricing scenarios are estimates using the displayed assumptions, not quotes; contracts, taxes, regions, cache behavior, and legacy plans can change a real bill.

Facts verified ; next scheduled review . Reviewed by Raed Bahri, Keenpix founder and maintainer.

Full methodology and corrections policy

Primary source list

Decision worksheet

How to compare imgproxy and Keenpix with your own workload

A headline plan price is not a total-cost comparison. Use one representative month, preserve every excluded meter, and test the product boundary before deciding. The five checks below are the same ones Keenpix uses for its source-dated calculator and comparison reviews. Save the inputs, official source URLs, response headers, and test date with the decision so a later pricing or cache-policy change can be audited instead of remembered.

1. Capture the workload before choosing units

Record delivered image GB after optimization, request count, source storage, unique generated variants, projects or sites, custom domains, delivery regions, source-change frequency, and cache hit behavior. Use a normal month and a peak month. Do not start by translating one vendor unit into another: a credit, transformation, cache read, worker, stored image, and delivered GB describe different work. If a required input is unavailable, label the resulting estimate partial instead of replacing it with zero.

2. Normalize the product boundary, not only the invoice

List what imgproxy includes that Keenpix does not and what your team would need to replace. That may include source storage, DAM workflows, video, a hosting platform, a bundled CDN, AI operations, upload widgets, support, or a self-hosted engine. Then list what sits outside each public price: transfer, requests, infrastructure, observability, additional domains, plan minimums, and operator time. A lower partial subtotal is not automatically a lower complete bill, and a broader platform can be worth paying for when you use its breadth.

3. Test cache and failure behavior

Run a representative URL set through both options. Measure a cold transform, a warm generated-variant hit, an edge hit, an expired source, an invalid signature, an unavailable origin, and a request above the usage allowance. Confirm which layer records billable usage and whether browser or customer-owned CDN hits reach it. Document cache keys, invalidation, stale behavior, retry limits, and the response users receive at a limit. Provider documentation is necessary, but a canary with your headers, URLs, and origins is the stronger acceptance test.

4. Price ownership and security work

Identify who owns origin allowlists, SSRF protection, signing keys, abuse controls, TLS, DNS, capacity, updates, vulnerability response, dashboards, logs, alerts, backups, incident response, and cost anomalies. A managed service moves some of those responsibilities to a vendor; a self-hosted or platform-native option may keep them with your existing team. Compare the architecture you will actually operate, including on-call and recovery expectations, rather than valuing engineering time at zero or assuming a managed boundary eliminates every integration task.

5. Define migration and rollback before the winner

Inventory production transformation options and save visual fixtures before translating URLs. Decide whether originals move, whether both services can read the same origin, how signatures and custom domains change, and how long old URLs must remain valid. Canary a measurable traffic slice and set acceptance thresholds for output dimensions, visual crops, content type, cache behavior, latency, errors, and projected cost. Keep the old path available until a complete traffic cycle passes. The right choice is the one that meets those thresholds and has a credible rollback, not the one with the longest feature column.

Model this workload in the cost calculator
Costs

Pricing compared

Pricing as of August 2026. Numbers come from vendor pricing pages, which may change.

Pricing comparison between imgproxy and Keenpix
ScenarioimgproxyKeenpix
Open-source licenseApache-2.0 core with no imgproxy license feeAGPL-3.0 self-host release with no Keenpix license fee
Managed entry pointNo managed CDN plan; you assemble and operate the delivery stack$9/month for 100 GB managed delivery
Commercial feature tierPro starts at $49/month or $499/year for up to 16 workersManaged plans are $9/$29/$69 monthly; no separate transform-worker license
Compute and scalingYour servers, autoscaling, queues, concurrency, and capacity marginIncluded in managed cloud; your workload is billed by delivered GB
CDN delivery and egressSeparate provider bill and configurationIncluded in the managed-delivery meter; customer-owned CDN hits do not reach Keenpix
A 400 GB managed workloadCannot be derived from license price alone; model infrastructure, CDN, egress, and labor$29/month Pro before any overage
Capabilities

Feature by feature

Feature comparison between imgproxy and Keenpix
FeatureimgproxyKeenpix
Product boundaryStandalone image-processing serverManaged image transformation and delivery service plus a self-host release
Open-source licenseApache-2.0 coreAGPL-3.0 published release
DeploymentDocker is recommended; an official Helm chart is availableManaged cloud or documented Docker/Coolify self-host deployment
URL protectionHMAC URL signatures with key and salt; recommended for productionOrigin allowlists and optional HMAC signed URLs
Modern formatsAVIF, WebP, JPEG XL, and other libvips-supported formatsAutomatic AVIF/WebP negotiation plus explicit format controls
Processing depthBroad standalone processing surface; several advanced features are Pro-onlyFocused resize, crop, quality, DPR, blur, format, and responsive delivery surface
Processed-image cacheYou provide the cache/CDN architecture; imgproxy Pro includes an internal cacheManaged memory, disk, object-storage, and delivery caching
Dashboard and projectsNo managed multi-project SaaS dashboard in the open-source serverProjects, origin settings, API keys, domains, team access, and billing UI
Usage analyticsPrometheus/OpenTelemetry building blocks; you store and visualize telemetryBandwidth, cache, format, latency, top-image analytics, and request logs
OperationsYou own upgrades, scaling, security patches, alerts, backups, and incidentsKeenpix owns the managed service; self-host users retain those responsibilities
SupportCommunity for OSS; priority creator support is a Pro benefitManaged product support by email and WhatsApp; open-source issue tracker for public code
Video previews and ML featuresAvailable among imgproxy Pro capabilitiesNo video product; AI extensions are not claimed as generally available
Fit and trade-offs

Why teams switch

Replace a stack diagram with one managed boundary

A production imgproxy deployment normally sits beside compute orchestration, a delivery CDN, DNS/TLS, metrics, logs, alerting, secrets, rate controls, and an upgrade process. Keenpix managed cloud contracts those responsibilities into a service and exposes project settings and usage in one dashboard.

Forecast a delivery bill from delivered GB

imgproxy’s zero-dollar open-source license and worker-priced Pro license do not include infrastructure or delivery. Keenpix managed plans publish included delivered GB and linear overage, so the calculator can estimate a managed bill without pretending engineering time is free.

Give product teams self-service visibility

Keenpix includes project analytics, request logs, cache behavior, format mix, bandwidth savings, domains, and usage projections. An imgproxy team can build an excellent observability stack, but it must choose, connect, secure, retain, and operate those components.

Keep an escape hatch without operating it today

Keenpix publishes a self-host path for teams that later need control, while the managed cloud removes the immediate operational load. The licenses differ: evaluate AGPL-3.0 obligations for Keenpix and Apache-2.0 for imgproxy with your own counsel.

Separate origin trust by project

Managed Keenpix projects use explicit origin allowlists, optional signatures, quotas, and isolated settings. imgproxy has strong source restrictions and signed URLs, but multi-tenant project governance remains part of the platform you design around the server.

When imgproxy is the better choice

An honest comparison lists both columns. Stay with imgproxy if any of these describe you:

  • Your platform team already operates Kubernetes or container services, a CDN, metrics, logs, alerts, and incident response, so another managed control plane adds little value.
  • Apache-2.0 compatibility is a hard requirement and AGPL-3.0 is not acceptable for your self-hosted distribution model.
  • You need a specific imgproxy processing option, codec, video-preview feature, or Pro ML capability that Keenpix does not provide.
  • You want to tune worker concurrency, CPU and memory allocation, networking, cache topology, and release timing directly.
  • Your traffic is large and predictable enough that owned infrastructure plus engineering time is demonstrably cheaper in your environment.
  • You prefer imgproxy’s mature standalone engine and release history over adopting a younger managed product from a solo founder.
Practical path

How to migrate from imgproxy

  1. 1

    Inventory every imgproxy URL option, preset, source scheme, signature rule, output format, and Pro-only feature in production. Mark any capability that has no Keenpix equivalent before changing traffic.

  2. 2

    Export a representative URL corpus and expected dimensions, content types, cache headers, visual crops, and failure responses. Use it as a regression set rather than relying on a few hand-picked images.

  3. 3

    Create one Keenpix project per trust and ownership boundary, then allowlist only the source hosts each project needs. Do not carry a permissive source policy into the managed configuration.

  4. 4

    Translate supported resize, crop, quality, DPR, blur, and format operations into Keenpix query parameters. Automatic AVIF/WebP negotiation can replace explicit format selection where that matches your cache strategy.

  5. 5

    Replace imgproxy path signatures with the Keenpix project URL shape and optional HMAC signature. Rotate keys and keep the old path available during the overlap instead of attempting a flag-day migration.

  6. 6

    Canary a small, measurable traffic slice. Compare visual output, origin fetches, cache hit rate, latency, error classes, and projected delivery cost under real traffic and multiple device widths.

  7. 7

    Move the remaining traffic only after the regression corpus and canary meet your thresholds. Keep a rollback route until cache behavior and billing projections remain stable through a complete traffic cycle.

Questions answered

Frequently asked questions

Open a question to review the answer without losing your place in the comparison.