[
  {
    "type": "vendor",
    "slug": "akamai-identity-cloud",
    "name": "Akamai Identity Cloud",
    "legal_name": "Akamai Identity Cloud (Akamai Technologies, Inc., formerly Janrain)",
    "parent_company": "Akamai Technologies, Inc.",
    "acquired_by": "Akamai (Janrain acquisition closed January 2019)",
    "website": "https://www.akamai.com/products/identity-cloud",
    "docs_url": "https://identitydocs.akamai.com",
    "pricing_url": null,
    "github_url": null,
    "hq": "Cambridge, Massachusetts, USA",
    "founded": 2002,
    "status": "deprecated",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": {
        "stage": "acquired",
        "amount_usd": null,
        "year": 2019,
        "lead": "Akamai"
      },
      "investors": [],
      "profitable": null,
      "notes": "Built on Janrain, acquired by Akamai (NASDAQ: AKAM) in 2019; the CIAM line has since been wound down.",
      "source": "https://www.prnewswire.com/news-releases/akamai-completes-acquisition-of-customer-identity-access-management-company-janrain-inc-300783209.html"
    },
    "categories": [
      "enterprise-ciam",
      "b2c-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": false,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "java",
          "dotnet"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Hosted Login customization + custom rules"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based via Akamai sales",
      "notable_costs": [
        "Akamai enterprise sales engagement; quote-based pricing",
        "Strong fit when paired with Akamai's broader edge / WAF / bot defense portfolio",
        "Pricing typically positioned at the higher end of the index"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 8000,
      "tco_at_500k_mau_estimate_usd_per_month": 24000,
      "tco_at_1m_mau_estimate_usd_per_month": 40000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Strong B2C heritage from Janrain (founded 2002), twenty years of consumer registration, social login, and consent expertise.",
      "Tight integration with Akamai's broader edge platform, WAF, Bot Manager, and DDoS protection at the same vendor.",
      "Mature consent management and preference center capabilities for B2C regulated industries.",
      "Comprehensive compliance footprint covering SOC 2, ISO, HIPAA, PCI Level 1."
    ],
    "limitations": [
      "Enterprise-only commercial structure with high entry pricing.",
      "DX trails developer-first tier; admin tooling reflects classic enterprise design.",
      "Outside Akamai ecosystem, the integration story is less compelling.",
      "No FedRAMP authorization."
    ],
    "best_for": [
      "Existing Akamai customers consolidating CIAM with edge / WAF / bot defense",
      "Large B2C enterprise deployments with serious consent management requirements",
      "Media, retail, and consumer brands at high MAU"
    ],
    "not_for": [
      "Mid-market or startup deployments",
      "Workloads requiring FedRAMP authorization",
      "Greenfield projects without Akamai ecosystem context"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 5
    },
    "last_verified": "2026-05-08",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Akamai Identity Cloud End-of-Life announcement (October 31, 2024)",
        "url": "https://techdocs.akamai.com",
        "accessed": "2026-05-08"
      },
      {
        "title": "Akamai Identity Cloud product page",
        "url": "https://www.akamai.com/products/identity-cloud",
        "accessed": "2026-05-08"
      }
    ],
    "editorial_verdict": "Akamai Identity Cloud (formerly Janrain) has reached end-of-life. Akamai transitioned the product to End-of-Sale on March 7, 2024 and announced End-of-Life plans on October 31, 2024; feature freeze took effect at the end of 2024 and the complete shutdown is set for December 31, 2027. Existing customers should be planning migration now, most organizations need 12-18 months from decision to completed cutover. Do not select for new deployments; it is included here only so existing buyers can find the migration context.",
    "faqs": [
      {
        "q": "Is Akamai Identity Cloud being shut down?",
        "a": "Yes. Akamai announced End-of-Life on October 31, 2024 with a complete shutdown date of December 31, 2027. Feature freeze is already in effect (end of 2024). The product entered End-of-Sale on March 7, 2024, no new customer onboardings are accepted. Existing customers should be in active migration planning."
      },
      {
        "q": "Where should existing Akamai Identity Cloud customers migrate?",
        "a": "The typical destinations in 2026 depend on segment: B2C enterprise (media, retail, consumer brands) often evaluate Auth0, SAP Customer Data Cloud, or Microsoft Entra External ID; cost-sensitive moves often target MojoAuth, Stytch (now Twilio), or self-hosted Keycloak / Ory. Several CIAM vendors offer Akamai-specific migration consultation."
      },
      {
        "q": "What was Janrain?",
        "a": "Janrain was a B2C CIAM founded in 2002, with strong heritage in social login and consumer registration. Akamai acquired Janrain in 2019 and rebranded the product as Akamai Identity Cloud. The Janrain DNA, social registration, consent management, customer profile orchestration, was the core of the product."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-08",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      },
      {
        "date": "2026-05-08",
        "summary": "Status changed to 'deprecated'. Verdict rewritten with full End-of-Life timeline (EoS March 2024, EoL announced October 31 2024, feature freeze end of 2024, complete shutdown December 31 2027). FAQ updated with migration guidance for existing customers."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:i}=arguments[0];function _createMdxContent(n){const t={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return i(e,{children:[a(t.h2,{id:\"what-akamai-identity-cloud-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-akamai-identity-cloud-is\",children:\"What Akamai Identity Cloud is\"})}),\"\\n\",i(t.p,{children:[\"Akamai Identity Cloud is Akamai's CIAM platform, originating as Janrain (founded 2002 in Portland, OR) and acquired by Akamai in January 2019. The product preserved Janrain's B2C heritage, strong consumer registration, social login depth, consent management, and \",a(t.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"progressive profiling\"}),\", and integrated it with Akamai's broader edge security portfolio (WAF, Bot Manager, DDoS protection). The buyer is typically an existing Akamai customer or a large B2C enterprise consolidating identity with edge security.\"]}),\"\\n\",a(t.h2,{id:\"where-akamai-identity-cloud-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-akamai-identity-cloud-wins\",children:\"Where Akamai Identity Cloud wins\"})}),\"\\n\",i(t.p,{children:[\"Twenty years of B2C heritage from the Janrain era, uncommon depth on consumer registration flows, social login coverage, \",a(t.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", and preference center capabilities. Tight integration with Akamai's edge security stack is a meaningful consolidation play for existing Akamai customers. Comprehensive compliance footprint (SOC 2, ISO 27001, HIPAA, PCI Level 1).\"]}),\"\\n\",a(t.h2,{id:\"where-akamai-identity-cloud-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-akamai-identity-cloud-hurts\",children:\"Where Akamai Identity Cloud hurts\"})}),\"\\n\",i(t.p,{children:[\"Enterprise-only commercial structure with high entry pricing typically positions \",a(t.a,{href:\"/ciam-compass/vendors/akamai-identity-cloud/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Akamai Identity Cloud\"}),\" at six-figure annual minimums, which excludes mid-market evaluation entirely. DX trails the developer-first tier substantially, admin tooling and APIs reflect classic enterprise design, with longer onboarding and less self-service than Auth0 or Stytch. Outside the Akamai customer base the integration story is less compelling, since the WAF / Bot Manager / DDoS bundle is the primary value driver. No FedRAMP authorization, which excludes federal workloads.\"]}),\"\\n\",a(t.h2,{id:\"how-akamai-identity-cloud-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-akamai-identity-cloud-compares\",children:\"How Akamai Identity Cloud compares\"})}),\"\\n\",i(t.p,{children:[\"The closest comparisons are \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-akamai-identity-cloud/\",children:\"Auth0 vs Akamai Identity Cloud\"}),\" for the modern-vs-legacy-B2C-enterprise call. For other legacy enterprise CIAM with B2C heritage, \",a(t.a,{href:\"/ciam-compass/vendors/sap-customer-data-cloud/\",children:\"SAP Customer Data Cloud\"}),\" is the peer. For modern B2C with \",a(t.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\" orchestration depth, \",a(t.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" and \",a(t.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"}),\" are alternatives at lower cost.\"]})]})}return{default:function(e={}){const{wrapper:i}=e.components||{};return i?a(i,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/akamai-identity-cloud/",
    "edit_path": "content/vendors/akamai-identity-cloud.mdx"
  },
  {
    "type": "vendor",
    "slug": "auth0",
    "name": "Auth0",
    "legal_name": "Auth0 (an Okta company)",
    "parent_company": "Okta, Inc.",
    "acquired_by": "Okta (acquisition closed May 2021, $6.5B)",
    "website": "https://auth0.com",
    "docs_url": "https://auth0.com/docs",
    "pricing_url": "https://auth0.com/pricing",
    "github_url": null,
    "hq": "Bellevue, Washington, USA",
    "founded": 2013,
    "status": "active",
    "funding": {
      "model": "public",
      "total_raised_usd": 330000000,
      "last_round": {
        "stage": "acquired",
        "amount_usd": 6500000000,
        "year": 2021,
        "lead": "Okta"
      },
      "investors": [
        "Bessemer Venture Partners",
        "Meritech Capital",
        "Sapphire Ventures",
        "Salesforce Ventures"
      ],
      "profitable": null,
      "notes": "Raised ~$330M of VC before Okta acquired it for $6.5B in 2021; now Okta Customer Identity Cloud (NASDAQ: OKTA).",
      "source": "https://www.okta.com/press-room/press-releases/okta-completes-acquisition-of-auth0/"
    },
    "categories": [
      "developer-first-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "angular",
          "ios",
          "swift",
          "android",
          "kotlin",
          "java",
          "python",
          "go",
          "ruby",
          "php",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Actions (Node.js serverless)"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": true,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": true,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1 (with config)",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High (via Okta)",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": [
          "OneTrust",
          "Cookiebot"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 25000
      },
      "paid_starts_at_usd": 35,
      "enterprise_quote_required_above": "100k MAU or Enterprise SSO",
      "notable_costs": [
        "MAU overages compound quickly above 50k",
        "Enterprise connection fee for SAML",
        "Adaptive MFA gated to higher tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 240,
      "tco_at_100k_mau_estimate_usd_per_month": 1200,
      "tco_at_500k_mau_estimate_usd_per_month": 4500,
      "tco_at_1m_mau_estimate_usd_per_month": 9500,
      "pricing_transparency_score": 3
    },
    "dx_score": 5,
    "docs_quality": 5,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Largest developer ecosystem in CIAM, npm install rates, sample apps, and community size are the category benchmark.",
      "Most extensive social and enterprise federation library out of the box.",
      "Mature B2B Organizations model for SaaS tenant separation.",
      "Auth0 FGA brings Zanzibar-style fine-grained authorization without a separate vendor."
    ],
    "limitations": [
      "MAU pricing scales steeply, cost per MAU often exceeds $0.05–$0.10 above 100k.",
      "Actions-based extensibility creates lock-in; portable to neither Okta Workflows nor a self-hosted runner.",
      "Passkey UI is generic, no device-aware prompting; expect 5–10% adoption without orchestration.",
      "Auth0 for AI Agents and Auth for MCP are GA, but billed as add-on identity volume on top of already-steep MAU pricing."
    ],
    "best_for": [
      "Mid-market SaaS with mixed B2C and B2B Enterprise SSO needs",
      "Teams that prioritize developer ecosystem and React/Next.js DX"
    ],
    "not_for": [
      "Cost-sensitive consumer apps above 500k MAU",
      "Teams that need a cheap path above 500k MAU",
      "Self-hosted / data-sovereignty-mandatory deployments"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 4
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Auth0 Pricing Page",
        "url": "https://auth0.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Auth0 Documentation",
        "url": "https://auth0.com/docs",
        "accessed": "2026-08-19"
      },
      {
        "title": "Okta Q1 FY26 Earnings",
        "url": "https://investor.okta.com/",
        "accessed": "2026-08-19"
      },
      {
        "title": "Auth0 for AI Agents is Now Generally Available",
        "url": "https://auth0.com/blog/auth0-for-ai-agents-generally-available/",
        "accessed": "2026-08-19"
      },
      {
        "title": "Auth0 for AI Agents product",
        "url": "https://auth0.com/ai",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Auth0 remains the safest mid-market default for B2C plus B2B Enterprise SSO when developer velocity matters more than long-run TCO. Auth0 for AI Agents (GA November 2025) and Auth for MCP (GA May 2026) make it the first major CIAM with a packaged agent-identity surface. Below 50k MAU it is still hard to beat. Above 500k MAU, cost and Actions-driven lock-in make FusionAuth, Cognito, or Stytch (Twilio) plus a passkey orchestrator the more honest shortlist.",
    "faqs": [
      {
        "q": "Is Auth0 the same as Okta?",
        "a": "Auth0 is a product line owned by Okta since 2021. It runs as Okta Customer Identity Cloud while Okta Workforce Identity Cloud handles employee access."
      },
      {
        "q": "Does Auth0 support passkeys?",
        "a": "Yes. Auth0 supports WebAuthn passkeys natively across web and mobile SDKs, but the default UI does not perform device-aware prompting, which keeps adoption rates around 5–10% without orchestration."
      },
      {
        "q": "What does Auth0 cost at 100k MAU?",
        "a": "On Compass TCO assumptions (60% activity, one MFA factor, two SSO connections, standard support), about $1,200 per month at 100k MAU. Confirm against the live pricing page; Enterprise SSO connection fees move this number."
      },
      {
        "q": "What does Auth0 cost at 500k MAU?",
        "a": "At 500k MAU, expect $4,000–$5,000 per month on the Essentials/Professional tier, rising to $10k or more once Enterprise SSO connections, MFA add-ons, and FGA usage are layered in. Always request a custom quote at this scale. Jump to the pricing table on this page."
      },
      {
        "q": "Can I self-host Auth0?",
        "a": "No. Auth0 is cloud-only SaaS. For self-hosting, look at Keycloak, Ory, FusionAuth, or Zitadel."
      },
      {
        "q": "Does Auth0 support MCP and AI agent identity?",
        "a": "Yes. Auth0 for AI Agents went GA in November 2025 with agent-vs-human token separation and Dynamic Client Registration. Auth for MCP exited early access and went GA on 6 May 2026. Both are add-on surfaces on top of the core CIAM tenant; confirm agent-identity pricing separately from MAU."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-03-23",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(t){const s={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return n(e,{children:[a(s.h2,{id:\"what-auth0-actually-is\",children:a(s.a,{className:\"heading-anchor\",href:\"#what-auth0-actually-is\",children:\"What Auth0 actually is\"})}),\"\\n\",n(s.p,{children:[a(s.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" is Okta's developer-focused CIAM product line, sold as Okta Customer Identity Cloud. It runs as a multi-tenant SaaS in AWS regions across the US, EU, AU, and JP, with optional Private Cloud deployments for regulated customers. The buyer is typically an engineering team standing up auth for a SaaS product who needs B2C onboarding plus B2B Enterprise SSO without building either from scratch.\"]}),\"\\n\",n(s.p,{children:[\"The product surface is wide: hosted login pages, a \",a(s.a,{href:\"/ciam-compass/glossary/universal-login/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Universal Login\"}),\" customizer, a Rules-then-Actions extensibility model (Actions is the current path; Rules and Hooks are deprecated), and a fine-grained authorization product (Auth0 FGA) modeled on Google's Zanzibar paper. Organizations is the B2B model, tenants-within-a-tenant, and remains one of the more mature implementations in the market.\"]}),\"\\n\",a(s.h2,{id:\"where-auth0-wins\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-auth0-wins\",children:\"Where Auth0 wins\"})}),\"\\n\",n(s.p,{children:['The default play is \"don\\'t think about auth for the first 18 months.\" Below 50k ',a(s.a,{href:\"/ciam-compass/glossary/mau/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MAU\"}),\" the free tier covers most B2C apps, and the paid tier's per-MAU cost is competitive. The SDK coverage is the broadest in the category, the docs are well-maintained, and the community is large enough that nearly every integration question has been answered somewhere.\"]}),\"\\n\",n(s.p,{children:[\"For B2B SaaS, Organizations plus Enterprise SSO connections cover the SAML / OIDC matrix that buyers ask for in security questionnaires. Auth0 FGA, while still under-used, gives teams a \",a(s.a,{href:\"/ciam-compass/glossary/zanzibar/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Zanzibar\"}),\"-style permission engine they would otherwise have to buy from Authzed or build on OpenFGA themselves.\"]}),\"\\n\",a(s.h2,{id:\"where-auth0-hurts\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-auth0-hurts\",children:\"Where Auth0 hurts\"})}),\"\\n\",n(s.p,{children:[\"Pricing is the lasting friction. Above 100k MAU the per-user math compounds, Enterprise SSO connections are billed per-connection, Adaptive \",a(s.a,{href:\"/ciam-compass/glossary/mfa/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MFA\"}),\" is gated to higher tiers, and MAU overages can double a quarterly bill before procurement notices. At 500k MAU expect $4–5k per month on standard tiers, climbing to $10k+ as add-ons accumulate.\"]}),\"\\n\",n(s.p,{children:[\"The Actions extensibility model is convenient but proprietary. Code written for Actions does not run on Okta Workflows, on a self-hosted \",a(s.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\", or anywhere else, outbound migration involves rewriting every Action against the new vendor's hooks model. Combined with Auth0's database connection format, this is the lock-in vector that makes outbound migrations a 60–90 day exercise.\"]}),\"\\n\",n(s.p,{children:[\"Passkey support is technically present but UX-naïve. Without device-aware prompting (the prompt should know whether the user has a synced passkey on this device), adoption stalls at 5–10%. Teams pursuing serious passwordless rollouts increasingly pair Auth0 with an orchestrator like \",a(s.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\" or Corbado, or migrate to a passkey-native vendor.\"]}),\"\\n\",a(s.p,{children:\"Agent identity is no longer a gap. Auth0 for AI Agents went GA in November 2025, and Auth for MCP followed on 6 May 2026. The remaining question is price: agent identities bill on top of MAU, and a busy agent fleet can look like a second user population.\"}),\"\\n\",a(s.h2,{id:\"how-auth0-compares\",children:a(s.a,{className:\"heading-anchor\",href:\"#how-auth0-compares\",children:\"How Auth0 compares\"})}),\"\\n\",n(s.p,{children:[\"For B2B SaaS under 100k MAU, \",a(s.a,{href:\"/ciam-compass/compare/auth0-vs-clerk/\",children:\"Clerk\"}),\" is the most credible direct alternative on developer experience and time-to-first-login. For pure B2B with deep Enterprise \",a(s.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" needs, \",a(s.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" and \",a(s.a,{href:\"/ciam-compass/vendors/frontegg/\",children:\"Frontegg\"}),\" win on the SSO-first feature set. For self-hosted, \",a(s.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",a(s.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\" are the standard alternatives. For \",a(s.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-first consumer apps, \",a(s.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" and \",a(s.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" deserve serious evaluation.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/auth0/",
    "edit_path": "content/vendors/auth0.mdx"
  },
  {
    "type": "vendor",
    "slug": "authelia",
    "name": "Authelia",
    "legal_name": "Authelia (open-source project)",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.authelia.com",
    "docs_url": "https://www.authelia.com/overview/",
    "pricing_url": null,
    "github_url": "https://github.com/authelia/authelia",
    "hq": null,
    "founded": 2017,
    "status": "open-source",
    "funding": {
      "model": "foundation-oss",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Volunteer-driven open-source authentication portal; no commercial entity or institutional funding.",
      "source": "https://www.authelia.com/"
    },
    "categories": [
      "open-source-ciam"
    ],
    "deployment": [
      "self-hosted"
    ],
    "target_segments": [
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": false,
        "magic_links": false,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": false,
        "adaptive_mfa": false,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": false,
        "progressive_profiling": false,
        "self_service_account": "partial",
        "bulk_user_import": true,
        "user_search_admin": "partial",
        "custom_user_metadata": "partial",
        "organizations": false,
        "multi_tenancy": false,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "YAML configuration + access control rules"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": "partial",
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": false,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": false,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "No commercial offering, community-driven OSS only",
      "notable_costs": [
        "Apache 2.0 licensed; free at any scale",
        "Single Go binary; minimal infrastructure footprint",
        "Designed primarily as web SSO portal, not full CIAM"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 50,
      "tco_at_100k_mau_estimate_usd_per_month": 100,
      "tco_at_500k_mau_estimate_usd_per_month": 300,
      "tco_at_1m_mau_estimate_usd_per_month": 600,
      "pricing_transparency_score": 5
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Single Go binary with minimal operational footprint, among the lightest in the OSS index.",
      "Apache 2.0 licensed, fully community-driven, no commercial layer.",
      "Excellent fit for self-hosted infrastructure (homelab, internal SaaS, reverse-proxy-based access control).",
      "First-class integration with reverse proxies (Traefik, NGINX, HAProxy, Caddy) for forward-auth patterns."
    ],
    "limitations": [
      "Not a full CIAM, designed for web SSO portal scenarios, not customer identity at scale.",
      "No B2B Organizations, no multi-tenancy, no self-service registration as a default flow.",
      "User store is file-based or LDAP-backed, not designed for high-volume consumer apps.",
      "Compliance attestations are operator-earned; no SDK ecosystem; minimal API surface for app integration."
    ],
    "best_for": [
      "Self-hosted infrastructure (homelab, internal SaaS) where Authelia gates access to backend services",
      "Reverse-proxy-based forward-auth deployments",
      "Developer-tools and small-scale internal platforms"
    ],
    "not_for": [
      "B2C consumer apps with self-service registration",
      "B2B SaaS needing Organizations or multi-tenancy",
      "Workloads requiring vendor-attested compliance"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-04-29",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Authelia Documentation",
        "url": "https://www.authelia.com/overview/",
        "accessed": "2026-04-22"
      },
      {
        "title": "Authelia GitHub",
        "url": "https://github.com/authelia/authelia",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Authelia is the lightweight self-hosted SSO portal for infrastructure access in 2026, single Go binary, Apache 2.0, designed for reverse-proxy forward-auth patterns rather than consumer-scale CIAM. It is intentionally narrow: no Organizations, no self-service registration, no SDK ecosystem. For homelab and self-hosted-infrastructure access control, Authelia is one of the cleanest choices; for customer identity, look at full-platform CIAM instead.",
    "faqs": [
      {
        "q": "Is Authelia a CIAM platform?",
        "a": "Not really, in the sense the rest of this index uses the term. Authelia is designed as an SSO portal that gates access to backend services via reverse-proxy forward-auth, Traefik, NGINX, HAProxy, Caddy. It supports OIDC and SAML for downstream apps, but the focus is workforce / infrastructure access rather than consumer or B2B SaaS identity."
      },
      {
        "q": "What is forward-auth?",
        "a": "A reverse-proxy pattern where the proxy queries an external auth service (Authelia) to authorize each request before forwarding it to the backend. Common in homelab and self-hosted contexts; Authelia is one of the most popular implementations."
      },
      {
        "q": "Should I use Authelia for my SaaS app?",
        "a": "Probably not, Authelia is not designed for self-service consumer flows or multi-tenant B2B SaaS. For SaaS, look at Keycloak, FusionAuth, Zitadel, Logto, or one of the SaaS CIAM products."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-29",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(t){const n={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return r(e,{children:[a(n.h2,{id:\"what-authelia-is\",children:a(n.a,{className:\"heading-anchor\",href:\"#what-authelia-is\",children:\"What Authelia is\"})}),\"\\n\",r(n.p,{children:[a(n.a,{href:\"/ciam-compass/vendors/authelia/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authelia\"}),\" launched in 2017 as a self-hosted SSO portal for infrastructure access, designed primarily for reverse-proxy forward-auth patterns where Authelia gates access to backend services (Grafana, internal dashboards, code-server, file shares, etc.) routed through Traefik, NGINX, HAProxy, or Caddy. It is a single Go binary with a small operational footprint, popular in homelab and self-hosted-infrastructure contexts.\"]}),\"\\n\",a(n.h2,{id:\"where-authelia-wins\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-authelia-wins\",children:\"Where Authelia wins\"})}),\"\\n\",a(n.p,{children:\"Lightest operational profile in the index, single Go binary plus optional database. Apache 2.0 licensed and fully community-driven. First-class reverse-proxy integration that no other CIAM in this index matches as cleanly. Excellent for the use case it targets.\"}),\"\\n\",a(n.h2,{id:\"where-authelia-hurts\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-authelia-hurts\",children:\"Where Authelia hurts\"})}),\"\\n\",a(n.p,{children:\"It is intentionally narrow, not a full CIAM. No B2B Organizations, no multi-tenancy, no self-service registration as a default. User store is file-based or LDAP-backed. No SDK ecosystem. Compliance attestations are operator-earned. For consumer apps or B2B SaaS, look elsewhere.\"}),\"\\n\",a(n.h2,{id:\"how-authelia-compares\",children:a(n.a,{className:\"heading-anchor\",href:\"#how-authelia-compares\",children:\"How Authelia compares\"})}),\"\\n\",r(n.p,{children:[\"The closest comparisons are \",a(n.a,{href:\"/ciam-compass/compare/keycloak-vs-authelia/\",children:\"Keycloak vs Authelia\"}),\" for the self-hosted workforce-access call. For full-platform CIAM that handles customer identity at scale, \",a(n.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\", \",a(n.a,{href:\"/ciam-compass/vendors/authentik/\",children:\"Authentik\"}),\", \",a(n.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\", and \",a(n.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" are the alternatives. For workforce-IAM specifically (Authelia's adjacent space), Pomerium and Teleport are outside this CIAM-focused index.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/authelia/",
    "edit_path": "content/vendors/authelia.mdx"
  },
  {
    "type": "vendor",
    "slug": "authentik",
    "name": "Authentik",
    "legal_name": "Authentik Security, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://goauthentik.io",
    "docs_url": "https://docs.goauthentik.io",
    "pricing_url": "https://goauthentik.io/pricing",
    "github_url": "https://github.com/goauthentik/authentik",
    "hq": "New York, New York, USA",
    "founded": 2018,
    "status": "open-source",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 2000000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 2000000,
        "year": 2022,
        "lead": "Open Core Ventures"
      },
      "investors": [
        "Open Core Ventures",
        "Aviso Ventures"
      ],
      "profitable": null,
      "notes": "Commercial entity (Authentik Security) launched by Open Core Ventures as its first public-benefit company; project relicensed to MIT.",
      "source": "https://goauthentik.io/blog/2022-11-02-the-next-step-for-authentik/"
    },
    "categories": [
      "open-source-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "self-hosted",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "b2b-saas",
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "python",
          "go",
          "js",
          "node"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Flow stages (configurable) + Python policy expressions"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": false,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Authentik Enterprise (paid edition with support and additional features)",
      "notable_costs": [
        "Self-hosted Community is MIT-licensed, free at any scale",
        "Authentik Enterprise (paid) adds priority support, RAC (Remote Access Connector), and enterprise features",
        "Operational cost: Python service plus PostgreSQL plus Redis"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 200,
      "tco_at_100k_mau_estimate_usd_per_month": 600,
      "tco_at_500k_mau_estimate_usd_per_month": 1800,
      "tco_at_1m_mau_estimate_usd_per_month": 3500,
      "pricing_transparency_score": 5
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Modern Python-based OSS CIAM with a polished admin UI, closer to a SaaS console experience than Keycloak's admin tooling.",
      "Configurable Flow Stages, auth flows compose from declarative stages, similar to Authentication Trees but configured rather than scripted.",
      "Strict MIT licensing on the Community edition; no commercial-use clauses.",
      "Active community and rapid release cadence; popular in homelab and self-hosted enterprise contexts."
    ],
    "limitations": [
      "Operational profile, Python service plus PostgreSQL plus Redis, is mid-weight; lighter than Keycloak, heavier than FusionAuth or Zitadel.",
      "No managed cloud offering as of 2026; teams must operate it themselves.",
      "Compliance attestations are operator-earned; the project itself does not ship SOC 2 / ISO 27001 / HIPAA.",
      "No native FGA; no MCP support; SDK breadth is narrower than incumbents."
    ],
    "best_for": [
      "Self-hosted enterprise and homelab deployments wanting a modern, polished admin UX",
      "Teams with Python operational competence wanting MIT-licensed OSS",
      "Mid-market apps where data sovereignty matters more than managed-cloud convenience"
    ],
    "not_for": [
      "Teams without operational capacity for stateful Python services",
      "Workloads requiring vendor-attested SOC 2 / HIPAA / FedRAMP / PCI DSS",
      "Apps prioritizing managed-cloud convenience over self-host control"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-03-13",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Authentik Documentation",
        "url": "https://docs.goauthentik.io",
        "accessed": "2026-04-22"
      },
      {
        "title": "Authentik GitHub",
        "url": "https://github.com/goauthentik/authentik",
        "accessed": "2026-04-22"
      },
      {
        "title": "Authentik Pricing",
        "url": "https://goauthentik.io/pricing",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Authentik is the modern alternative to Keycloak for self-hosted enterprise CIAM in 2026, Python-based, MIT-licensed, with a materially nicer admin UI than Keycloak's dated console. The trade-off is mid-weight operational profile and no managed cloud offering. For teams with Python operational competence and a strict-OSS mandate, Authentik is the lower-friction alternative to Keycloak.",
    "faqs": [
      {
        "q": "How does Authentik differ from Keycloak?",
        "a": "Both are self-hosted OSS CIAM. Keycloak is Java/JBoss-based with the largest ecosystem; Authentik is Python-based with a more modern admin UI and MIT licensing. Operational profile is similar, both are stateful services with database dependencies. For homelab and modern self-host enterprise, Authentik often wins on UX; for largest community, Keycloak wins."
      },
      {
        "q": "Is there a managed Authentik cloud?",
        "a": "No managed cloud as of 2026. Authentik Enterprise (paid edition) adds priority support and enterprise features but you still run the service yourself. Teams that want managed should look at Zitadel Cloud, Auth0, or Ory Network."
      },
      {
        "q": "What is RAC (Remote Access Connector)?",
        "a": "An Authentik Enterprise feature for proxying remote access (RDP, SSH, VNC) through Authentik for centralized auth and audit. Useful for enterprise IT teams managing remote access without separate VPN/PAM tools, but not a CIAM-core feature for most B2C / B2B SaaS."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-13",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:t}=arguments[0];function _createMdxContent(n){const i={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return t(e,{children:[a(i.h2,{id:\"what-authentik-is\",children:a(i.a,{className:\"heading-anchor\",href:\"#what-authentik-is\",children:\"What Authentik is\"})}),\"\\n\",t(i.p,{children:[a(i.a,{href:\"/ciam-compass/vendors/authentik/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authentik\"}),\" launched in 2018 as a modern alternative to Keycloak, Python-based instead of Java, with a polished admin UI and MIT licensing. The product is a self-hosted CIAM that runs as a Python service backed by PostgreSQL and Redis, with configurable Flow Stages composing the auth journey declaratively. Authentik Enterprise is the paid edition with support and additional features (notably the Remote Access Connector for enterprise remote access).\"]}),\"\\n\",a(i.h2,{id:\"where-authentik-wins\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-authentik-wins\",children:\"Where Authentik wins\"})}),\"\\n\",t(i.p,{children:[\"A genuinely modern admin UX in the OSS CIAM tier. Strict MIT licensing without commercial-use clauses. Configurable Flow Stages that compose auth journeys without writing Java like \",a(i.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\"'s SPI requires. Active community, rapid releases, popular in homelab and modern self-hosted enterprise contexts.\"]}),\"\\n\",a(i.h2,{id:\"where-authentik-hurts\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-authentik-hurts\",children:\"Where Authentik hurts\"})}),\"\\n\",t(i.p,{children:[\"No managed cloud, the team operates it themselves. Compliance attestations are operator-earned, not platform-provided. Operational profile is mid-weight. No native \",a(i.a,{href:\"/ciam-compass/glossary/fga/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"FGA\"}),\", no MCP, narrower SDK breadth than incumbents.\"]}),\"\\n\",a(i.h2,{id:\"how-authentik-compares\",children:a(i.a,{className:\"heading-anchor\",href:\"#how-authentik-compares\",children:\"How Authentik compares\"})}),\"\\n\",t(i.p,{children:[\"The closest comparisons are \",a(i.a,{href:\"/ciam-compass/compare/keycloak-vs-authentik/\",children:\"Keycloak vs Authentik\"}),\", \",a(i.a,{href:\"/ciam-compass/compare/fusionauth-vs-authentik/\",children:\"FusionAuth vs Authentik\"}),\", and \",a(i.a,{href:\"/ciam-compass/compare/authentik-vs-zitadel/\",children:\"Authentik vs Zitadel\"}),\". For managed OSS, \",a(i.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory Network\"}),\" and \",a(i.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel Cloud\"}),\" are the alternatives.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?a(t,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/authentik/",
    "edit_path": "content/vendors/authentik.mdx"
  },
  {
    "type": "vendor",
    "slug": "authress",
    "name": "Authress",
    "legal_name": "Authress Limited",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://authress.io",
    "docs_url": "https://authress.io/knowledge-base",
    "pricing_url": "https://authress.io/pricing",
    "github_url": "https://github.com/Authress",
    "hq": "Auckland, New Zealand",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "bootstrapped",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Privately held by Rhosys AG (Switzerland); no disclosed institutional funding.",
      "source": "https://authress.io"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": false,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": true,
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "python",
          "go",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks + custom rules"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 1000
      },
      "paid_starts_at_usd": 25,
      "enterprise_quote_required_above": "Volume + dedicated tenancy",
      "notable_costs": [
        "Authorization-first product, pay primarily for permission evaluations",
        "Auth (login flows) is the simpler product surface; authz is the depth",
        "B2B Organizations and per-resource permissions included at standard tier"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 25,
      "tco_at_100k_mau_estimate_usd_per_month": 350,
      "tco_at_500k_mau_estimate_usd_per_month": 1500,
      "tco_at_1m_mau_estimate_usd_per_month": 2900,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Authorization-first design, native ReBAC and Zanzibar-style FGA at a price point below Auth0 FGA or WorkOS FGA.",
      "Strong B2B multi-tenant model with per-resource permission evaluation.",
      "Includes authentication and authorization in one product without forcing a two-vendor split.",
      "Modern API design with typed SDKs across major languages."
    ],
    "limitations": [
      "Smaller community than Auth0 / Clerk; fewer integrations and partner connectors.",
      "Authentication features are competitive but not the differentiator; teams picking on auth alone usually go elsewhere.",
      "Compliance footprint is solid for B2B (SOC 2, ISO 27001) but lacks HIPAA, FedRAMP, PCI DSS.",
      "No managed bot defense or advanced fraud signals."
    ],
    "best_for": [
      "B2B SaaS that needs serious authorization (FGA / ReBAC) without buying a separate authz vendor",
      "Apps with complex per-resource permission models",
      "Teams that prefer a single vendor for authn + authz"
    ],
    "not_for": [
      "Apps prioritizing best-in-class authentication features over authorization",
      "B2C consumer apps with serious progressive profiling and fraud needs",
      "Workloads requiring HIPAA, FedRAMP, or PCI DSS"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-04-30",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Authress Pricing",
        "url": "https://authress.io/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Authress Documentation",
        "url": "https://authress.io/knowledge-base",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Authress is the authorization-first developer CIAM in 2026, native ReBAC and Zanzibar-style FGA at a price point materially below Auth0 FGA or WorkOS FGA. For B2B SaaS designing fine-grained per-resource permissions where authorization is the binding constraint rather than authentication, Authress removes the two-vendor split (full CIAM plus separate authz service) most teams end up running. For teams whose binding constraint is auth methods or B2C scale, look elsewhere.",
    "faqs": [
      {
        "q": "What is ReBAC?",
        "a": "Relationship-Based Access Control, a permission model derived from Google's Zanzibar paper where access decisions evaluate relationships between subjects and resources (e.g., \"Alice is a member of Acme Corp's engineering team, which has read access to repo X\"). ReBAC is more expressive than RBAC for SaaS multi-tenant scenarios; Authress, OpenFGA, Authzed, and Permify are the major implementations."
      },
      {
        "q": "How does Authress compare to WorkOS FGA or Auth0 FGA?",
        "a": "All three ship Zanzibar-style FGA. WorkOS FGA and Auth0 FGA bundle FGA inside their broader CIAM product; Authress builds the entire CIAM around authz as the core, which makes the model more idiomatic for serious authorization scenarios. Authress is also materially cheaper at the FGA-evaluation tier."
      },
      {
        "q": "Should I use Authress for authn or authz?",
        "a": "Both, but the authz product is the differentiator. If authentication is the binding constraint, look at Auth0, Clerk, or Stytch. If authorization is the binding constraint and you want one vendor for both, Authress."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-30",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(t){const r={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return s(e,{children:[a(r.h2,{id:\"what-authress-is\",children:a(r.a,{className:\"heading-anchor\",href:\"#what-authress-is\",children:\"What Authress is\"})}),\"\\n\",s(r.p,{children:[\"Authress launched in 2020 in Auckland with an authorization-first thesis: most CIAM vendors treat authn as the headline product and authz as an afterthought, which leaves teams with serious permission requirements either running a second vendor (OpenFGA, Authzed, Permify) or building authz on top of CIAM RBAC primitives that don't scale. Authress builds the CIAM around Zanzibar-style ReBAC as the core, with \",a(r.a,{href:\"/ciam-compass/glossary/authentication/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authentication\"}),\" as the supporting layer.\"]}),\"\\n\",a(r.h2,{id:\"where-authress-wins\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-authress-wins\",children:\"Where Authress wins\"})}),\"\\n\",s(r.p,{children:[\"Native ReBAC and FGA at a price point below Auth0 FGA or \",a(r.a,{href:\"/ciam-compass/vendors/workos/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"WorkOS\"}),\" FGA. B2B multi-tenant model with per-resource permission evaluation as the design center. Single vendor covers both authn and authz, which simplifies the architecture for teams that would otherwise run two services.\"]}),\"\\n\",a(r.h2,{id:\"where-authress-hurts\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-authress-hurts\",children:\"Where Authress hurts\"})}),\"\\n\",a(r.p,{children:\"Smaller community than incumbents; partner ecosystem is younger. Authentication features are competitive but not the differentiator. Compliance footprint is good for B2B (SOC 2, ISO 27001) but lacks HIPAA, FedRAMP, PCI DSS. For B2C consumer apps or for teams whose binding constraint is auth, look elsewhere.\"}),\"\\n\",a(r.h2,{id:\"how-authress-compares\",children:a(r.a,{className:\"heading-anchor\",href:\"#how-authress-compares\",children:\"How Authress compares\"})}),\"\\n\",s(r.p,{children:[\"The closest comparisons are \",a(r.a,{href:\"/ciam-compass/compare/auth0-vs-authress/\",children:\"Auth0 vs Authress\"}),\" for the \",a(r.a,{href:\"/ciam-compass/glossary/fga/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"FGA\"}),\"-included CIAM choice and \",a(r.a,{href:\"/ciam-compass/compare/authress-vs-workos/\",children:\"Authress vs WorkOS\"}),\" for the B2B-with-authz call. For pure authz services that pair with any CIAM, OpenFGA, Authzed, and Permify are the alternatives outside this index. For B2C focus, \",a(r.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" and \",a(r.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" are the standard picks.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/authress/",
    "edit_path": "content/vendors/authress.mdx"
  },
  {
    "type": "vendor",
    "slug": "authsignal",
    "name": "Authsignal",
    "legal_name": "Authsignal Limited",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.authsignal.com",
    "docs_url": "https://docs.authsignal.com",
    "pricing_url": "https://www.authsignal.com/pricing",
    "github_url": "https://github.com/authsignal",
    "hq": "Auckland, New Zealand",
    "founded": 2021,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 905000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 905000,
        "year": 2022,
        "lead": "Blackbird Ventures"
      },
      "investors": [
        "Blackbird Ventures",
        "Dovetail Capital",
        "Aspire NZ Seed Fund"
      ],
      "profitable": null,
      "notes": "New Zealand drop-in MFA / step-up auth; $905K seed (2022).",
      "source": "https://www.blackbird.vc/portfolio/authsignal"
    },
    "categories": [
      "identity-orchestration",
      "passwordless-specialist",
      "developer-first-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": false,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": false,
        "sso_oidc": "partial",
        "sso_oauth2": "partial",
        "enterprise_federation": false,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": false,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": "partial",
        "fine_grained_permissions": false
      },
      "user_management": {
        "self_service_registration": false,
        "progressive_profiling": false,
        "self_service_account": "partial",
        "bulk_user_import": false,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "ruby",
          "php",
          "java",
          "dotnet"
        ],
        "cli": false,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks + custom rule scripts (JavaScript)"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": "partial",
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 5000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Enterprise volume and custom rules",
      "notable_costs": [
        "Priced per challenge or per MAU depending on plan",
        "Custom rule scripts (Rules Engine) included at standard tier",
        "Pairs with any underlying CIAM, Auth0, Cognito, Keycloak, custom, without replacing it"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 700,
      "tco_at_500k_mau_estimate_usd_per_month": 2500,
      "tco_at_1m_mau_estimate_usd_per_month": 4800,
      "pricing_transparency_score": 4
    },
    "dx_score": 5,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Best-in-class identity orchestration as a layer, sits in front of any underlying CIAM (Auth0, Cognito, Keycloak, custom) without replacing it.",
      "Rules Engine (JavaScript) for risk decisioning, step-up MFA, and adaptive policies, meaningfully more capable than most full-platform CIAM's adaptive layer.",
      "Best-in-class passkey orchestration with conditional UI, device-aware prompting, and recovery design as defaults.",
      "Vendor-neutral design, does not try to replace your CIAM, only enhance it."
    ],
    "limitations": [
      "Not a full CIAM, does not store user accounts, does not handle social login, does not provide SAML SSO.",
      "Adds a vendor and a hop in the auth flow; teams without an existing CIAM should pick a full-platform vendor first.",
      "Compliance footprint is narrower than enterprise SaaS, no FedRAMP, no PCI DSS direct attestation.",
      "Smaller ecosystem; less Stack Overflow coverage than full-platform CIAM."
    ],
    "best_for": [
      "Teams running Auth0, Cognito, or Keycloak who want passkey orchestration without changing primary CIAM",
      "Apps facing serious account-takeover pressure that need adaptive risk and step-up MFA beyond their CIAM's native layer",
      "B2C apps targeting high passkey adoption on top of an existing auth platform"
    ],
    "not_for": [
      "Greenfield apps without an existing CIAM, pick a full-platform vendor first",
      "Workloads requiring FedRAMP or PCI DSS direct attestation",
      "Teams that prefer one vendor for the entire auth stack"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-05-08",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Authsignal Pricing",
        "url": "https://www.authsignal.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Authsignal Documentation",
        "url": "https://docs.authsignal.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Authsignal is the strongest identity orchestration layer in 2026, designed to sit in front of any underlying CIAM (Auth0, Cognito, Keycloak, custom-built) and add the passkey orchestration, adaptive risk decisioning, and step-up MFA logic that most full-platform vendors do badly. For teams with an existing CIAM that want to fix passkey adoption or harden against account takeover without replacing the primary platform, Authsignal is the singular pick. Not a full CIAM, pick one of those first if greenfield.",
    "faqs": [
      {
        "q": "Does Authsignal replace my CIAM?",
        "a": "No. Authsignal is an orchestration layer that sits in front of (or alongside) your existing CIAM, Auth0, Cognito, Keycloak, custom-built, anything. It handles passkey enrollment, MFA challenges, step-up flows, and adaptive risk decisioning; the underlying CIAM continues to handle user storage, social login, SAML, and the rest of the auth surface."
      },
      {
        "q": "When does Authsignal make sense over Descope's Flows?",
        "a": "When you already have a CIAM and don't want to replace it. Descope is a full-platform CIAM whose Flows feature is bundled; Authsignal is the orchestration layer alone, designed to enhance an existing platform without forcing migration. Greenfield teams should usually pick Descope (or another full platform with strong orchestration). Teams with installed Auth0 / Cognito / Keycloak should usually pick Authsignal."
      },
      {
        "q": "What about Corbado?",
        "a": "Corbado is the closest competitor, also an orchestration layer, also passkey-specialist. The two differ on scope: Authsignal covers broader risk decisioning and step-up flows; Corbado is more narrowly passkey-orchestration-focused with deeper passkey-specific tooling."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-08",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:a,jsx:e,jsxs:t}=arguments[0];function _createMdxContent(s){const i={a:\"a\",h2:\"h2\",p:\"p\",...s.components};return t(a,{children:[e(i.h2,{id:\"what-authsignal-is\",children:e(i.a,{className:\"heading-anchor\",href:\"#what-authsignal-is\",children:\"What Authsignal is\"})}),\"\\n\",t(i.p,{children:[\"Authsignal launched in 2021 in Auckland with a clear scope: be the orchestration layer, not the primary CIAM. The product sits in front of (or alongside) an existing auth platform, Auth0, Cognito, Keycloak, custom, and handles the orchestration that full-platform vendors typically do badly: passkey enrollment with device-aware prompting, MFA challenges, \",e(i.a,{href:\"/ciam-compass/glossary/step-up-authentication/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"step-up authentication\"}),\" for sensitive actions, and adaptive risk decisioning via a JavaScript Rules Engine. The buyer is a team that has an installed primary CIAM and is hitting limits on passkey adoption, account-takeover defense, or adaptive MFA.\"]}),\"\\n\",e(i.h2,{id:\"where-authsignal-wins\",children:e(i.a,{className:\"heading-anchor\",href:\"#where-authsignal-wins\",children:\"Where Authsignal wins\"})}),\"\\n\",t(i.p,{children:[\"The vendor-neutral design is the strategic edge. Most CIAM vendors that ship orchestration require you to migrate the entire auth surface to them; \",e(i.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\" takes the opposite stance and slots into whatever exists. For a team running Auth0 in production, swapping to Descope for better orchestration is a 60-90-day migration; layering Authsignal in is days.\"]}),\"\\n\",t(i.p,{children:[\"The passkey orchestration is at the level of Stytch / Descope / Hanko, \",e(i.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\", device-aware prompting, fallback flows, recovery design. Customers consistently see the same 30–50% adoption rates within six months, but on top of their existing CIAM rather than after a migration.\"]}),\"\\n\",t(i.p,{children:[\"The Rules Engine is meaningfully more capable than most full-platform CIAM's adaptive MFA layer. JavaScript rules that evaluate risk signals (device, geo, velocity, behavior) and decide between allow / step-up / block give teams the kind of adaptive logic that vendors like \",e(i.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" expose only at higher tiers, and often less expressively.\"]}),\"\\n\",e(i.p,{children:\"DX is strong. Idiomatic SDKs across major languages, Terraform provider, webhook delivery, and modern docs.\"}),\"\\n\",e(i.h2,{id:\"where-authsignal-hurts\",children:e(i.a,{className:\"heading-anchor\",href:\"#where-authsignal-hurts\",children:\"Where Authsignal hurts\"})}),\"\\n\",t(i.p,{children:[\"It is not a CIAM. No user storage, no \",e(i.a,{href:\"/ciam-compass/glossary/social-login/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"social login\"}),\" flows, no SAML SSO, no Organizations model. For greenfield teams without an existing auth platform, picking Authsignal first is the wrong order, pick a full-platform CIAM first and add Authsignal if you need its orchestration depth.\"]}),\"\\n\",e(i.p,{children:\"Adding a vendor and a hop in the auth flow is real architectural cost. Teams without a clear orchestration problem to solve are better off relying on their primary CIAM's built-in adaptive layer, even if it is weaker.\"}),\"\\n\",t(i.p,{children:[\"Compliance breadth is narrower than enterprise SaaS, SOC 2 Type II yes, ISO 27001 yes, but no FedRAMP, no PCI DSS direct \",e(i.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\". For federal or fintech workloads requiring these specifically, Authsignal is a layered concern alongside the primary CIAM.\"]}),\"\\n\",e(i.p,{children:\"The community and ecosystem are smaller than full-platform vendors.\"}),\"\\n\",e(i.h2,{id:\"how-authsignal-compares\",children:e(i.a,{className:\"heading-anchor\",href:\"#how-authsignal-compares\",children:\"How Authsignal compares\"})}),\"\\n\",t(i.p,{children:[\"The closest direct comparison is \",e(i.a,{href:\"/ciam-compass/compare/authsignal-vs-corbado/\",children:\"Authsignal vs Corbado\"}),\" for the \",e(i.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-orchestration-layer call. Most teams evaluating Authsignal are also evaluating whether to switch full-platform CIAM to one with built-in orchestration, see \",e(i.a,{href:\"/ciam-compass/compare/auth0-vs-descope/\",children:\"Auth0 vs Descope\"}),\" and \",e(i.a,{href:\"/ciam-compass/compare/stytch-vs-descope/\",children:\"Stytch vs Descope\"}),\" for that path.\"]})]})}return{default:function(a={}){const{wrapper:t}=a.components||{};return t?e(t,{...a,children:e(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/authsignal/",
    "edit_path": "content/vendors/authsignal.mdx"
  },
  {
    "type": "vendor",
    "slug": "betterauth",
    "name": "BetterAuth",
    "legal_name": "BetterAuth (open-source project)",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.better-auth.com",
    "docs_url": "https://www.better-auth.com/docs",
    "pricing_url": null,
    "github_url": "https://github.com/better-auth/better-auth",
    "hq": null,
    "founded": 2024,
    "status": "open-source",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 5000000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 5000000,
        "year": 2025,
        "lead": "Peak XV Partners"
      },
      "investors": [
        "Peak XV Partners",
        "Y Combinator",
        "P1 Ventures",
        "Chapter One"
      ],
      "profitable": null,
      "notes": "Open-source TypeScript auth framework built solo by self-taught Ethiopian dev Bereket Engida; $5M seed (2025, YC S25).",
      "source": "https://techcrunch.com/2025/06/25/this-self-taught-ethiopian-dev-built-an-authentication-tool-and-got-into-yc/"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam"
    ],
    "deployment": [
      "self-hosted"
    ],
    "target_segments": [
      "b2b-saas",
      "b2c",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "svelte",
          "remix",
          "nuxt",
          "solid"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Plugin architecture (typed) + custom hooks"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": false,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Self-hosted only, no managed offering",
      "notable_costs": [
        "Library is free under MIT, pay only operational cost",
        "Bring your own database (Postgres / MySQL / SQLite / MongoDB)",
        "No managed cloud offering as of 2026"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 50,
      "tco_at_100k_mau_estimate_usd_per_month": 200,
      "tco_at_500k_mau_estimate_usd_per_month": 800,
      "tco_at_1m_mau_estimate_usd_per_month": 1600,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Code-first auth library with strict TypeScript-first DX, feels like a modern framework primitive rather than a hosted SaaS.",
      "Plugin architecture makes the surface composable, pull in only the auth methods you actually use.",
      "Strict MIT licensing; bring your own database; no vendor lock-in.",
      "Rapidly growing community in the TypeScript ecosystem; widely cited as the modern OSS code-first auth pick."
    ],
    "limitations": [
      "No managed cloud offering, operational responsibility falls entirely on the team.",
      "No compliance attestations, the library cannot deliver SOC 2 / ISO / HIPAA on its own.",
      "Enterprise SAML federation is partial; not at Auth0 / WorkOS level.",
      "Fast-evolving, API stability is improving but breaking changes still occur between minor versions."
    ],
    "best_for": [
      "TypeScript / Next.js teams that prefer code-first auth as a library, not a service",
      "Self-hosted-only environments without managed-CIAM tolerance",
      "Greenfield startups that want to own the auth layer architecture"
    ],
    "not_for": [
      "Teams without operational capacity to run auth as part of their own infrastructure",
      "Workloads requiring SOC 2 / HIPAA / ISO 27001 / PCI DSS attestation at the auth layer",
      "Production B2B SaaS with serious enterprise federation requirements"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 2
    },
    "last_verified": "2026-05-18",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "BetterAuth Documentation",
        "url": "https://www.better-auth.com/docs",
        "accessed": "2026-04-22"
      },
      {
        "title": "BetterAuth GitHub",
        "url": "https://github.com/better-auth/better-auth",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "BetterAuth is the most-discussed code-first OSS auth library in the TypeScript ecosystem in 2026, strict MIT, bring-your-own-database, plugin-architecture extensible, and a DX that feels like a modern framework primitive rather than a SaaS. The trade-off is that without a managed offering, the team owns the operational burden, the compliance story, and the production runtime. For teams that want auth as a library rather than a service, BetterAuth is a strong default; for teams that want managed compliance and SLAs, look elsewhere.",
    "faqs": [
      {
        "q": "Is BetterAuth a CIAM platform or an auth library?",
        "a": "An auth library. There is no managed cloud offering, BetterAuth is installed via npm and runs inside your own application's runtime, backed by your own database. This is materially different from SaaS CIAM and from self-hosted-managed products like Keycloak or FusionAuth."
      },
      {
        "q": "How does BetterAuth compare to NextAuth.js (Auth.js)?",
        "a": "Both are code-first TypeScript auth libraries for Next.js and adjacent frameworks. BetterAuth has gained mindshare in 2024–2025 for cleaner API surface, better TypeScript ergonomics, and a more composable plugin architecture. NextAuth.js / Auth.js has the older, larger ecosystem. For new projects in 2026, BetterAuth is widely cited as the modern pick."
      },
      {
        "q": "Should I use BetterAuth or a SaaS CIAM?",
        "a": "If you want auth as a library you control completely, BetterAuth. If you want managed compliance attestations, hosted Admin Portal UX, vendor SLAs, or to avoid running auth infrastructure yourself, pick a SaaS CIAM (Auth0, Clerk, Stytch, Kinde). The choice is architectural, not feature-based."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-18",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:t,jsxs:a}=arguments[0];function _createMdxContent(r){const n={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return a(e,{children:[t(n.h2,{id:\"what-betterauth-is\",children:t(n.a,{className:\"heading-anchor\",href:\"#what-betterauth-is\",children:\"What BetterAuth is\"})}),\"\\n\",a(n.p,{children:[t(n.a,{href:\"/ciam-compass/vendors/betterauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"BetterAuth\"}),\" is an open-source code-first auth library for the TypeScript / Next.js ecosystem, originating in 2024 and gaining significant adoption through 2025–2026 as the modern alternative to NextAuth.js (Auth.js). It is installed via npm, runs inside the application's own runtime, persists to a database the team owns, and exposes a plugin architecture for composing auth methods. There is no managed cloud offering, BetterAuth is library, not service.\"]}),\"\\n\",t(n.h2,{id:\"where-betterauth-wins\",children:t(n.a,{className:\"heading-anchor\",href:\"#where-betterauth-wins\",children:\"Where BetterAuth wins\"})}),\"\\n\",a(n.p,{children:[\"Code-first DX at the level of modern framework primitives. Strict MIT licensing, bring-your-own-database, no vendor lock-in. Plugin architecture means the auth surface composes cleanly, pull in passkey support, social login, organizations, and \",t(n.a,{href:\"/ciam-compass/glossary/rate-limiting/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"rate limiting\"}),\" as separate plugins rather than monolithic configuration. Rapidly growing TypeScript ecosystem mindshare.\"]}),\"\\n\",t(n.h2,{id:\"where-betterauth-hurts\",children:t(n.a,{className:\"heading-anchor\",href:\"#where-betterauth-hurts\",children:\"Where BetterAuth hurts\"})}),\"\\n\",a(n.p,{children:[\"No managed offering means the team owns operational and compliance responsibility entirely, there is no SOC 2 \",t(n.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\" BetterAuth can deliver on your behalf. Enterprise federation is partial. Fast-evolving codebase still has breaking changes between minor versions occasionally. For production B2B SaaS with serious compliance or federation requirements, a SaaS CIAM is usually the better answer.\"]}),\"\\n\",t(n.h2,{id:\"how-betterauth-compares\",children:t(n.a,{className:\"heading-anchor\",href:\"#how-betterauth-compares\",children:\"How BetterAuth compares\"})}),\"\\n\",a(n.p,{children:[\"The most relevant comparisons are BetterAuth vs Auth.js for the code-first library decision, \",t(n.a,{href:\"/ciam-compass/compare/stack-auth-vs-betterauth/\",children:\"Stack Auth vs BetterAuth\"}),\" for the OSS-Next.js-first call, and \",t(n.a,{href:\"/ciam-compass/compare/auth0-vs-betterauth/\",children:\"Auth0 vs BetterAuth\"}),\" for the library-vs-service architectural decision. For self-hosted-managed alternatives, \",t(n.a,{href:\"/ciam-compass/vendors/supertokens/\",children:\"SuperTokens\"}),\", \",t(n.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\", and \",t(n.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" are the natural comparisons.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?t(a,{...e,children:t(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/betterauth/",
    "edit_path": "content/vendors/betterauth.mdx"
  },
  {
    "type": "vendor",
    "slug": "beyond-identity",
    "name": "Beyond Identity",
    "legal_name": "Beyond Identity, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.beyondidentity.com",
    "docs_url": "https://docs.beyondidentity.com",
    "pricing_url": null,
    "github_url": "https://github.com/gobeyondidentity",
    "hq": "New York, New York, USA",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 205000000,
      "last_round": {
        "stage": "series-c",
        "amount_usd": 100000000,
        "year": 2021,
        "lead": "Evolution Equity Partners"
      },
      "investors": [
        "New Enterprise Associates",
        "Koch Disruptive Technologies",
        "Evolution Equity Partners"
      ],
      "profitable": null,
      "notes": "Founded by Netscape's Jim Clark and TJ Jermoluk; $100M Series C at a $1.1B valuation.",
      "source": "https://www.beyondidentity.com/announcements/beyond-identity-raises-100-million-to-accelerate-adoption-of-invisible-un-phishable-mfa-for-customers-and-employees"
    },
    "categories": [
      "passwordless-specialist",
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": true,
        "magic_links": false,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks + Policy Engine for risk decisioning"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": "Moderate",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based; volume MAU pricing",
      "notable_costs": [
        "Enterprise quote-based pricing; no published per-MAU rates",
        "Workforce IAM and CIAM products are commercially separate",
        "Beyond Identity's Secure Customers (CIAM) and Secure Workforce (IAM) share the same passwordless architecture"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 5000,
      "tco_at_500k_mau_estimate_usd_per_month": 16000,
      "tco_at_1m_mau_estimate_usd_per_month": 28000,
      "pricing_transparency_score": 1
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Pioneering passwordless architecture, uses asymmetric keys bound to TPM / Secure Enclave, going beyond stock WebAuthn for hardware-attested device identity.",
      "Strong enterprise positioning with FedRAMP Moderate authorization and HIPAA support.",
      "Policy Engine for adaptive risk decisioning is among the most capable in the enterprise tier.",
      "Founded by Jim Clark (Netscape), name carries weight in enterprise security buying conversations."
    ],
    "limitations": [
      "Enterprise quote-based pricing with no public rates excludes mid-market evaluation.",
      "The hardware-attested device identity model adds enrollment friction that can hurt B2C consumer flows.",
      "Smaller customer base than larger enterprise CIAM (Auth0, Ping, ForgeRock).",
      "B2C consumer flows are less developed than B2B and workforce."
    ],
    "best_for": [
      "Enterprise security-first deployments wanting hardware-attested passwordless beyond stock WebAuthn",
      "Regulated industries needing FedRAMP Moderate plus passwordless",
      "Workforce IAM use cases where Beyond Identity's device-binding shines"
    ],
    "not_for": [
      "Mid-market or startup deployments without enterprise-quote tolerance",
      "B2C consumer apps prioritizing low-friction signup over device attestation",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-04-13",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Beyond Identity Documentation",
        "url": "https://docs.beyondidentity.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Beyond Identity products",
        "url": "https://www.beyondidentity.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Beyond Identity is the most security-forward passwordless platform in 2026, hardware-attested device identity bound to TPM / Secure Enclave goes beyond stock WebAuthn, and the Policy Engine for adaptive risk decisioning is among the most capable in the enterprise tier. The trade-offs are enterprise-only commercial structure (no public pricing) and additional enrollment friction from the device-binding model. For enterprise security-conscious deployments, particularly with FedRAMP or workforce IAM adjacencies, Beyond Identity is a top pick. For mid-market or low-friction B2C, look elsewhere.",
    "faqs": [
      {
        "q": "How is Beyond Identity different from stock WebAuthn / passkeys?",
        "a": "Beyond Identity uses asymmetric keys bound to the device's TPM (Trusted Platform Module) or Secure Enclave, with hardware attestation that proves the credential lives on a known device. This is a stronger guarantee than synced passkeys (which trust the cloud password manager) and is well-suited to regulated workforce and high-assurance customer scenarios. The trade-off is more enrollment friction."
      },
      {
        "q": "Does Beyond Identity have public pricing?",
        "a": "No, all deployments are enterprise quote-based. Expect five-figure annual minimums typical for the segment. For mid-market or startup evaluation, the lack of public pricing is disqualifying."
      },
      {
        "q": "What's the relationship between Beyond Identity's Customer and Workforce products?",
        "a": "Both are sold separately but share the same hardware-attested passwordless architecture. Secure Customers is CIAM; Secure Workforce is IAM. Organizations buying both benefit from architectural consistency and unified policy."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-13",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:n,jsxs:t}=arguments[0];function _createMdxContent(i){const r={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return t(e,{children:[n(r.h2,{id:\"what-beyond-identity-is\",children:n(r.a,{className:\"heading-anchor\",href:\"#what-beyond-identity-is\",children:\"What Beyond Identity is\"})}),\"\\n\",t(r.p,{children:[n(r.a,{href:\"/ciam-compass/vendors/beyond-identity/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Beyond Identity\"}),\" launched in 2020 with founders including Jim Clark (Netscape) and a security-forward thesis: stock WebAuthn / passkeys trust the cloud password manager, but enterprise scenarios often need stronger guarantees, hardware-attested device identity bound to TPM or Secure Enclave that proves the credential lives on a specific known device. The product splits into Secure Customers (CIAM) and Secure Workforce (IAM) sharing the same passwordless architecture.\"]}),\"\\n\",n(r.h2,{id:\"where-beyond-identity-wins\",children:n(r.a,{className:\"heading-anchor\",href:\"#where-beyond-identity-wins\",children:\"Where Beyond Identity wins\"})}),\"\\n\",t(r.p,{children:[\"Hardware-attested device identity goes beyond stock WebAuthn for high-assurance scenarios, useful in regulated industries, workforce identity, and any scenario where device-binding matters more than enrollment friction. The Policy Engine for adaptive risk decisioning is among the most capable in the enterprise tier. FedRAMP Moderate \",n(r.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" plus HIPAA covers most enterprise compliance needs.\"]}),\"\\n\",n(r.h2,{id:\"where-beyond-identity-hurts\",children:n(r.a,{className:\"heading-anchor\",href:\"#where-beyond-identity-hurts\",children:\"Where Beyond Identity hurts\"})}),\"\\n\",n(r.p,{children:\"Enterprise-only commercial structure, no public pricing, five-figure annual minimums typical, professional services-oriented onboarding. The hardware-attested model adds enrollment friction that can hurt B2C consumer flows. Smaller customer base than large enterprise CIAM incumbents.\"}),\"\\n\",n(r.h2,{id:\"how-beyond-identity-compares\",children:n(r.a,{className:\"heading-anchor\",href:\"#how-beyond-identity-compares\",children:\"How Beyond Identity compares\"})}),\"\\n\",t(r.p,{children:[\"The closest comparisons are \",n(r.a,{href:\"/ciam-compass/compare/auth0-vs-beyond-identity/\",children:\"Auth0 vs Beyond Identity\"}),\" for the enterprise-passwordless call and \",n(r.a,{href:\"/ciam-compass/compare/beyond-identity-vs-stytch/\",children:\"Beyond Identity vs Stytch\"}),\" for the \",n(r.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-orchestration call. For workforce IAM with similar device-binding posture, products outside this CIAM-focused index are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?n(t,{...e,children:n(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/beyond-identity/",
    "edit_path": "content/vendors/beyond-identity.mdx"
  },
  {
    "type": "vendor",
    "slug": "casdoor",
    "name": "Casdoor",
    "legal_name": "Casdoor (open-source project, Casbin Authors)",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://casdoor.org",
    "docs_url": "https://casdoor.org/docs/overview",
    "pricing_url": "https://casdoor.com/",
    "github_url": "https://github.com/casdoor/casdoor",
    "hq": null,
    "founded": 2021,
    "status": "open-source",
    "funding": {
      "model": "foundation-oss",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Open-source IAM from the Casbin community; no disclosed institutional funding.",
      "source": "https://casdoor.org/"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam"
    ],
    "deployment": [
      "self-hosted",
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": true,
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "go",
          "python",
          "java",
          "dotnet",
          "php",
          "rust"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Casbin policy expressions + adapter pattern for storage"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": false,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": false,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Casdoor cloud (paid managed) and Enterprise edition",
      "notable_costs": [
        "Self-hosted Community is Apache 2.0, free at any scale",
        "Casdoor Cloud (managed) and Enterprise edition are commercial offerings",
        "Tight integration with Casbin (the authz library), both projects under same maintainer"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 100,
      "tco_at_100k_mau_estimate_usd_per_month": 350,
      "tco_at_500k_mau_estimate_usd_per_month": 1200,
      "tco_at_1m_mau_estimate_usd_per_month": 2200,
      "pricing_transparency_score": 4
    },
    "dx_score": 3,
    "docs_quality": 3,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 2,
    "strengths": [
      "Tight integration with Casbin (the authz library by the same maintainer), gives Casdoor strong authorization primitives uncommon in OSS CIAM.",
      "Apache 2.0 licensed self-hosted Community.",
      "Broad feature breadth, social providers, MFA, SSO, multi-tenancy, payment integrations.",
      "Active community across both Casdoor and Casbin projects, with strong China-region adoption."
    ],
    "limitations": [
      "DX trails Western OSS CIAM noticeably, admin UI is functional but dated, English documentation has rough edges.",
      "Compliance attestations are operator-earned; no platform-provided SOC 2 / ISO / HIPAA.",
      "No managed-cloud-with-major-region-presence outside the project's own Cloud offering.",
      "Sprawling feature set (the project includes payment and CMS integrations) makes the scope feel less focused than peers."
    ],
    "best_for": [
      "Teams that want OSS CIAM with strong native authorization (Casbin) without separate authz vendor",
      "China-region or Asia-Pacific deployments where Casdoor has strong regional adoption",
      "Developers comfortable with broad-scoped OSS projects"
    ],
    "not_for": [
      "Workloads requiring vendor-attested compliance (SOC 2, HIPAA, FedRAMP, PCI DSS)",
      "Teams preferring tightly-scoped CIAM products",
      "B2C consumer apps with serious adaptive risk needs"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-06-02",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Casdoor Documentation",
        "url": "https://casdoor.org/docs/overview",
        "accessed": "2026-04-22"
      },
      {
        "title": "Casdoor GitHub",
        "url": "https://github.com/casdoor/casdoor",
        "accessed": "2026-04-22"
      },
      {
        "title": "Casdoor Pricing",
        "url": "https://casdoor.com/",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Casdoor is the OSS CIAM with the strongest native authorization integration via Casbin (same maintainer), Apache 2.0 licensed and broad-featured. The trade-offs are dated DX, English-documentation rough edges, and a sprawling scope that spans CIAM plus adjacent domains. For teams that value Casbin authz tightly coupled to identity, or for China-region deployments where Casdoor has strong adoption, it is a credible OSS pick. For Western enterprise with strict compliance needs, look at Keycloak / FusionAuth / Zitadel instead.",
    "faqs": [
      {
        "q": "What is Casbin and how does it relate to Casdoor?",
        "a": "Casbin is a popular open-source authorization library supporting RBAC, ABAC, and ACL policy models, by the same maintainer as Casdoor. Casdoor integrates Casbin natively for the authz layer, which gives it stronger fine-grained permissions than most OSS CIAM that ship only RBAC."
      },
      {
        "q": "Is Casdoor's documentation in English?",
        "a": "Yes, but with rough edges, the project is China-originated and the English documentation lags the Chinese version in some places. For teams comfortable cross-referencing GitHub issues, this is workable; for teams expecting Auth0-grade docs, the gap is real."
      },
      {
        "q": "Should I pick Casdoor or Keycloak?",
        "a": "Keycloak has the larger Western community and ecosystem, plus the Java-heavy enterprise tooling. Casdoor has stronger native authorization (Casbin) and Apache 2.0 licensing without commercial-use clauses. For integrated authn+authz from one OSS vendor, Casdoor; for largest Western community, Keycloak."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-06-02",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:a,jsx:e,jsxs:s}=arguments[0];function _createMdxContent(o){const r={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return s(a,{children:[e(r.h2,{id:\"what-casdoor-is\",children:e(r.a,{className:\"heading-anchor\",href:\"#what-casdoor-is\",children:\"What Casdoor is\"})}),\"\\n\",s(r.p,{children:[\"Casdoor launched in 2021 from the Casbin Authors team, the same maintainers behind Casbin, the popular open-source \",e(r.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" library. The product is a self-hosted OSS CIAM under Apache 2.0, with Casbin natively integrated as the authz layer. The thesis: most OSS CIAM ships RBAC and stops, leaving teams to bolt on a separate authz library; Casdoor ships them together.\"]}),\"\\n\",e(r.h2,{id:\"where-casdoor-wins\",children:e(r.a,{className:\"heading-anchor\",href:\"#where-casdoor-wins\",children:\"Where Casdoor wins\"})}),\"\\n\",s(r.p,{children:[\"Native Casbin integration means strong authorization primitives, RBAC, ABAC, ReBAC, without a second vendor. Apache 2.0 licensing across the codebase. Broad feature breadth covering \",e(r.a,{href:\"/ciam-compass/glossary/social-login/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"social login\"}),\", MFA, SSO, multi-tenancy, and adjacent integrations. Active community with notable adoption in China and Asia-Pacific.\"]}),\"\\n\",e(r.h2,{id:\"where-casdoor-hurts\",children:e(r.a,{className:\"heading-anchor\",href:\"#where-casdoor-hurts\",children:\"Where Casdoor hurts\"})}),\"\\n\",e(r.p,{children:\"DX trails Western OSS CIAM, admin UI is functional but dated, English documentation has rough edges, and the project's broad scope spans beyond CIAM into payments and CMS adjacencies. Compliance attestations are operator-earned. For Western enterprise with strict procurement requirements, the rough edges show.\"}),\"\\n\",e(r.h2,{id:\"how-casdoor-compares\",children:e(r.a,{className:\"heading-anchor\",href:\"#how-casdoor-compares\",children:\"How Casdoor compares\"})}),\"\\n\",s(r.p,{children:[\"The closest comparisons are \",e(r.a,{href:\"/ciam-compass/compare/keycloak-vs-casdoor/\",children:\"Keycloak vs Casdoor\"}),\", \",e(r.a,{href:\"/ciam-compass/compare/casdoor-vs-fusionauth/\",children:\"Casdoor vs FusionAuth\"}),\", and \",e(r.a,{href:\"/ciam-compass/compare/authress-vs-casdoor/\",children:\"Authress vs Casdoor\"}),\" for the authn-plus-authz call. For modern Western OSS CIAM, \",e(r.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\", \",e(r.a,{href:\"/ciam-compass/vendors/authentik/\",children:\"Authentik\"}),\", and \",e(r.a,{href:\"/ciam-compass/vendors/logto/\",children:\"Logto\"}),\" are the alternatives.\"]})]})}return{default:function(a={}){const{wrapper:s}=a.components||{};return s?e(s,{...a,children:e(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/casdoor/",
    "edit_path": "content/vendors/casdoor.mdx"
  },
  {
    "type": "vendor",
    "slug": "clerk",
    "name": "Clerk",
    "legal_name": "Clerk Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://clerk.com",
    "docs_url": "https://clerk.com/docs",
    "pricing_url": "https://clerk.com/pricing",
    "github_url": "https://github.com/clerk",
    "hq": "San Francisco, California, USA",
    "founded": 2019,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 55500000,
      "last_round": {
        "stage": "series-b",
        "amount_usd": 30000000,
        "year": 2024,
        "lead": "CRV"
      },
      "investors": [
        "CRV",
        "Stripe",
        "Andreessen Horowitz",
        "Madrona"
      ],
      "profitable": null,
      "notes": "$30M Series B in Jan 2024 with a strategic Stripe partnership; expanding from authentication into authorization.",
      "source": "https://clerk.com/blog/series-b"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "react",
          "next",
          "remix",
          "expo",
          "node",
          "go",
          "python",
          "ruby"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + JWT templates"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": "partial",
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 25,
      "enterprise_quote_required_above": "Enterprise SSO and SOC 2 add-ons",
      "notable_costs": [
        "Per-MAO (monthly active organizations) pricing on B2B tier",
        "Enhanced authentication (passkeys, MFA) gated to higher tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 25,
      "tco_at_100k_mau_estimate_usd_per_month": 800,
      "tco_at_500k_mau_estimate_usd_per_month": 2800,
      "tco_at_1m_mau_estimate_usd_per_month": 5500,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 5,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Best-in-class Next.js / React DX, the default integration is 15 minutes from npm install to working login.",
      "Polished default UI components that most teams ship without customization.",
      "Conditional UI for passkeys is on by default.",
      "Transparent, predictable pricing through 100k MAU."
    ],
    "limitations": [
      "Enterprise SSO connection breadth is narrower than Auth0 for unusual IdPs.",
      "No FGA / Zanzibar-style fine-grained authorization, pair with a separate vendor.",
      "Smaller compliance footprint (no FedRAMP, ISO 27001 is in progress).",
      "Extension model is webhooks + JWT templates; no inline server-side hook execution."
    ],
    "best_for": [
      "Native Next.js and Node.js apps under 100k MAU",
      "Product teams that want drop-in React UI, not an enterprise identity program",
      "Teams that want default UI components without designer effort"
    ],
    "not_for": [
      "Enterprise stacks that need Java, .NET, or a long-tail SAML catalog",
      "Apps requiring FedRAMP, ISO 27001, or extensive enterprise federation",
      "Authorization-heavy use cases needing fine-grained permissions",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Clerk Pricing",
        "url": "https://clerk.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Clerk Documentation",
        "url": "https://clerk.com/docs",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Clerk is the default for native Next.js and Node.js apps under 100k MAU. Drop-in UI is the win. It is not an enterprise CIAM: federation long tail, Java/.NET, FedRAMP, and ISO 27001 are missing or thin. Do not put Clerk on an RFP that needs the rest of the enterprise stack. For that job use Auth0, WorkOS, or SSOJet. For passwordless-native, use MojoAuth or Stytch.",
    "faqs": [
      {
        "q": "Is Clerk a real Auth0 alternative for B2B SaaS?",
        "a": "Yes for native Next.js and Node.js apps under 100k MAU. Clerk Organizations cover common IdPs. It is not an enterprise CIAM: long-tail SAML, Java/.NET, FedRAMP, and ISO 27001 are missing or thin. For that surface use Auth0, WorkOS, or SSOJet."
      },
      {
        "q": "Does Clerk support passkeys?",
        "a": "Yes, with conditional UI on by default, the autofill prompt surfaces existing passkeys without an explicit button."
      },
      {
        "q": "What does Clerk cost at 500k MAU?",
        "a": "Roughly $2,500–$3,000 per month at the standard tier, before SOC 2 add-ons and Enterprise SSO connections. Always confirm with Clerk for a custom quote at this scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Editorial: Clerk scoped to native Next.js and Node.js. Not an enterprise-stack CIAM (federation long tail, Java/.NET, FedRAMP, ISO 27001)."
      },
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-03-25",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(s){const n={a:\"a\",code:\"code\",h2:\"h2\",p:\"p\",...s.components};return r(e,{children:[a(n.h2,{id:\"what-clerk-is\",children:a(n.a,{className:\"heading-anchor\",href:\"#what-clerk-is\",children:\"What Clerk is\"})}),\"\\n\",r(n.p,{children:[a(n.a,{href:\"/ciam-compass/vendors/clerk/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Clerk\"}),\" is a developer-first CIAM SaaS launched in 2019, focused on giving React and Next.js teams the fastest path from \",a(n.code,{children:\"npm install\"}),\" to a production-grade login flow. The default integration ships polished UI components, a \",a(n.code,{children:\"<SignIn />\"}),\" and \",a(n.code,{children:\"<UserButton />\"}),\", that most teams use without customization, paired with hooks (\",a(n.code,{children:\"useUser\"}),\", \",a(n.code,{children:\"useOrganization\"}),\") that mirror the patterns React developers already know.\"]}),\"\\n\",r(n.p,{children:[\"The B2B story is mature: Organizations are first-class, with invitations, role assignment, and SSO-per-org built into the default flow. The auth surface covers passwords, magic links, OTP, social, and passkeys, with \",a(n.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\" on by default for passkey adoption.\"]}),\"\\n\",a(n.h2,{id:\"where-clerk-wins\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-clerk-wins\",children:\"Where Clerk wins\"})}),\"\\n\",r(n.p,{children:[\"The DX win is real and underrated. A Next.js team using the App Router can have working auth, B2B Organizations, and a default account page in under 30 minutes, with no designer effort. Pricing is predictable through 100k \",a(n.a,{href:\"/ciam-compass/glossary/mau/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MAU\"}),\" and the free tier (10k MAU) covers most prototypes.\"]}),\"\\n\",r(n.p,{children:[a(n.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Passkey\"}),\" adoption is unusually high among Clerk customers because conditional UI is the default, not an opt-in. This is the orchestration win that separates Clerk from larger but less opinionated platforms.\"]}),\"\\n\",a(n.h2,{id:\"where-clerk-hurts\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-clerk-hurts\",children:\"Where Clerk hurts\"})}),\"\\n\",r(n.p,{children:[a(n.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Federation\"}),\" breadth is narrower than Auth0, common IdPs (Okta, Entra, Google Workspace) are well-supported, but unusual SAML connections (older PingFederate deployments, some healthcare IdPs) require more custom work. Compliance breadth is also smaller: SOC 2 Type II yes, FedRAMP no, ISO 27001 in progress.\"]}),\"\\n\",r(n.p,{children:[\"There is no built-in FGA or Zanzibar-style fine-grained \",a(n.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\". Teams needing this typically pair Clerk with OpenFGA, Authzed, or Permify. Audit log streaming is more limited than Auth0's; high-volume customers needing real-time SIEM forwarding will hit edges.\"]}),\"\\n\",a(n.h2,{id:\"how-clerk-compares\",children:a(n.a,{className:\"heading-anchor\",href:\"#how-clerk-compares\",children:\"How Clerk compares\"})}),\"\\n\",r(n.p,{children:[\"The most common direct comparison is \",a(n.a,{href:\"/ciam-compass/compare/auth0-vs-clerk/\",children:\"Auth0 vs Clerk\"}),\". For pure B2B with deeper \",a(n.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" breadth, \",a(n.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" and \",a(n.a,{href:\"/ciam-compass/vendors/frontegg/\",children:\"Frontegg\"}),\" are alternatives. For passkey-first consumer apps, \",a(n.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" is the closest competitor on DX.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/clerk/",
    "edit_path": "content/vendors/clerk.mdx"
  },
  {
    "type": "vendor",
    "slug": "cognito",
    "name": "Amazon Cognito",
    "legal_name": "Amazon Cognito (Amazon Web Services)",
    "parent_company": "Amazon Web Services",
    "acquired_by": null,
    "website": "https://aws.amazon.com/cognito/",
    "docs_url": "https://docs.aws.amazon.com/cognito/",
    "pricing_url": "https://aws.amazon.com/cognito/pricing/",
    "github_url": null,
    "hq": "Seattle, Washington, USA",
    "founded": 2014,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "A managed service inside AWS (Amazon, NASDAQ: AMZN); never separately funded.",
      "source": "https://aws.amazon.com/cognito/"
    },
    "categories": [
      "cloud-native-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": false,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": "partial",
        "adaptive_mfa": true,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": "partial",
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": false,
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "python",
          "go",
          "java",
          "dotnet",
          "php",
          "ruby",
          "cpp",
          "swift",
          "android",
          "kotlin"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": "partial",
        "extension_model": "Lambda triggers (pre-sign-up, post-confirmation, custom auth challenge)"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": "partial",
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": true,
        "account_linking": "partial",
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 50000
      },
      "paid_starts_at_usd": 0,
      "enterprise_quote_required_above": "Cognito user pool MAU pricing applies past free tier",
      "notable_costs": [
        "Free tier: 50k MAU on user pools",
        "Per-MAU pricing scales linearly above free tier ($0.0055/MAU at standard tier)",
        "Lambda invocation costs for triggers add up at high-volume custom auth flows",
        "Advanced Security Features (adaptive MFA, breached password detection) priced separately"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 275,
      "tco_at_500k_mau_estimate_usd_per_month": 2475,
      "tco_at_1m_mau_estimate_usd_per_month": 5225,
      "pricing_transparency_score": 4
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 2,
    "strengths": [
      "Native AWS integration, IAM-mapped tokens, Lambda triggers, CloudWatch / CloudTrail observability, VPC endpoints.",
      "FedRAMP High, PCI Level 1, HIPAA, ISO 27001, broadest compliance footprint in the cloud-native segment.",
      "Free tier (50k MAU) and per-MAU pricing that's competitive at the consumer-app scale.",
      "Mature SDK coverage and CLI tooling; Terraform / CloudFormation IaC are first-class."
    ],
    "limitations": [
      "DX is widely considered worse than Auth0 / Clerk / Stytch, quirky API, UI is dated, error messages are AWS-cryptic.",
      "No B2B Organizations model, multi-tenant SaaS has to build tenancy on top of user pool groups (workable but underwhelming).",
      "Passkey support added but orchestration is bare; UI is the AWS hosted UI, which is functional but unbranded by default.",
      "Breaking changes between user pool versions have historically required user data migration; v1 → v2 was painful."
    ],
    "best_for": [
      "Apps already deeply embedded in AWS that benefit from IAM token integration",
      "Workloads requiring FedRAMP High, PCI DSS Level 1, or other AWS-blessed attestations",
      "Cost-sensitive consumer apps at high MAU"
    ],
    "not_for": [
      "Teams that prioritize developer velocity over operational integration",
      "B2B SaaS needing first-class Organizations / SCIM / audit-per-org",
      "Multi-cloud or AWS-agnostic deployments"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Amazon Cognito Pricing",
        "url": "https://aws.amazon.com/cognito/pricing/",
        "accessed": "2026-08-19"
      },
      {
        "title": "Amazon Cognito Documentation",
        "url": "https://docs.aws.amazon.com/cognito/",
        "accessed": "2026-08-19"
      },
      {
        "title": "Cognito Compliance Programs",
        "url": "https://aws.amazon.com/compliance/services-in-scope/",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Amazon Cognito is the right CIAM choice when the application is already deep in AWS and the buyer values IAM integration plus FedRAMP / PCI / HIPAA over developer velocity. Native WebAuthn passkeys now ship in Managed Login; orchestration quality is still thin compared with Stytch or Descope. Per-MAU economics beat SaaS competitors above 500k MAU. Outside AWS-native architectures, the DX gap relative to Auth0 / Clerk / Stytch is hard to justify.",
    "faqs": [
      {
        "q": "When does Cognito make sense over Auth0?",
        "a": "When the workload already runs on AWS, when the IAM-mapped token model unlocks downstream service authorization, when FedRAMP High is required, or when per-MAU cost above 500k MAU is the binding constraint. For B2B SaaS or consumer apps not deeply tied to AWS, Auth0's DX advantage usually wins."
      },
      {
        "q": "Does Cognito support B2B Organizations?",
        "a": "Not first-class. Multi-tenant SaaS on Cognito is typically built using user pool groups, claims, and Lambda triggers, workable but materially less ergonomic than Auth0 Organizations, WorkOS, or Frontegg."
      },
      {
        "q": "What is FedRAMP High and why does it matter?",
        "a": "FedRAMP is the U.S. federal government's compliance baseline for cloud services. \"High\" is the strictest tier, required for most federal workloads handling controlled unclassified information. Cognito (via AWS GovCloud and standard regions) is FedRAMP High authorized; few non-AWS CIAM vendors match this."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-03-17",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:t}=arguments[0];function _createMdxContent(o){const n={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return t(e,{children:[a(n.h2,{id:\"what-amazon-cognito-is\",children:a(n.a,{className:\"heading-anchor\",href:\"#what-amazon-cognito-is\",children:\"What Amazon Cognito is\"})}),\"\\n\",t(n.p,{children:[\"Cognito is AWS's customer identity platform, launched in 2014 and split into two products: User Pools (the auth directory) and Identity Pools (federated IAM credentials for AWS resources). The buyer is typically an AWS-native engineering team that wants identity to integrate with the rest of their AWS footprint, IAM-mapped tokens, Lambda triggers, CloudWatch logs, KMS \",a(n.a,{href:\"/ciam-compass/glossary/encryption/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"encryption\"}),\", VPC isolation. Cognito is rarely the right answer for an AWS-agnostic team; it is often the only right answer for an AWS-deep one.\"]}),\"\\n\",a(n.h2,{id:\"where-cognito-wins\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-cognito-wins\",children:\"Where Cognito wins\"})}),\"\\n\",a(n.p,{children:\"The integration story is unmatched. A token issued by Cognito can directly authorize an S3 read, a DynamoDB query, or a Lambda invocation via IAM, with no application code translating the user identity into AWS permissions. For data-plane apps on AWS, this is a substantial architectural simplification that no other CIAM offers.\"}),\"\\n\",a(n.p,{children:\"Compliance breadth is a near-tie with the largest enterprise platforms. FedRAMP High, PCI DSS Level 1, HIPAA, ISO 27001/27018, SOC 2 Type II, all attested at the AWS service level. For federal, healthcare, or fintech workloads, this matters more than DX.\"}),\"\\n\",t(n.p,{children:[\"Per-MAU pricing is competitive at scale. At 1M MAU, expect roughly $5,000/month vs $9,500+/month on \",a(n.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\", and Cognito's free tier (50k MAU) covers most early-stage apps for free.\"]}),\"\\n\",a(n.h2,{id:\"where-cognito-hurts\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-cognito-hurts\",children:\"Where Cognito hurts\"})}),\"\\n\",a(n.p,{children:\"DX is the lasting weakness. The API surface has grown organically rather than being designed; error messages are AWS-cryptic; the hosted UI is functional but bland and requires custom HTML themes for branded pages. SDK quality is good for Java / .NET / mobile, average for JS / Node / Python / Go.\"}),\"\\n\",t(n.p,{children:[\"The B2B story is weak. There's no first-class Organizations model, multi-tenant SaaS uses user pool groups and custom claims, which works but feels like a workaround compared to Auth0 Organizations, WorkOS, or \",a(n.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\". SCIM is not natively supported.\"]}),\"\\n\",t(n.p,{children:[a(n.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Passkey\"}),\" support shipped but the orchestration is bare. Expect AWS-hosted UI passkey flows that work but don't drive the kind of adoption Stytch or Descope deliver.\"]}),\"\\n\",a(n.p,{children:\"Migration in or out is painful in both directions. User data export is doable but the password hash format requires careful handling; pre/post-confirmation Lambda triggers don't translate cleanly to other vendors' hooks models.\"}),\"\\n\",a(n.h2,{id:\"how-cognito-compares\",children:a(n.a,{className:\"heading-anchor\",href:\"#how-cognito-compares\",children:\"How Cognito compares\"})}),\"\\n\",t(n.p,{children:[\"The most common direct comparison is \",a(n.a,{href:\"/ciam-compass/compare/auth0-vs-cognito/\",children:\"Auth0 vs Cognito\"}),', which is largely a \"DX vs AWS-native integration\" call. Within hyperscaler-native CIAM, ',a(n.a,{href:\"/ciam-compass/vendors/entra-external-id/\",children:\"Microsoft Entra External ID\"}),\" and \",a(n.a,{href:\"/ciam-compass/vendors/firebase-auth/\",children:\"Firebase Auth\"}),\" are the parallel options on Azure and GCP. For self-hosted with broader compliance autonomy, \",a(n.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" is the alternative.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?a(t,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/cognito/",
    "edit_path": "content/vendors/cognito.mdx"
  },
  {
    "type": "vendor",
    "slug": "corbado",
    "name": "Corbado",
    "legal_name": "Corbado GmbH",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.corbado.com",
    "docs_url": "https://docs.corbado.com",
    "pricing_url": "https://www.corbado.com/pricing",
    "github_url": "https://github.com/corbado",
    "hq": "Munich, Germany",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": null,
      "last_round": {
        "stage": "seed",
        "amount_usd": null,
        "year": 2024,
        "lead": null
      },
      "investors": [
        "10x Founders",
        "PB Holding"
      ],
      "profitable": null,
      "notes": "Munich passkey-rollout specialist; subsidiary of PB Holding GmbH with backing from 10x Founders.",
      "source": "https://www.startbase.com/organization/corbado/"
    },
    "categories": [
      "passwordless-specialist",
      "identity-orchestration",
      "developer-first-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": false,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": false,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": false,
        "sso_oidc": "partial",
        "sso_oauth2": "partial",
        "enterprise_federation": false,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": false,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": "partial",
        "fine_grained_permissions": false
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": false,
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "ios",
          "swift",
          "android",
          "kotlin",
          "go",
          "python",
          "java",
          "dotnet"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + custom UI components"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Volume + dedicated tenancy",
      "notable_costs": [
        "Priced per MAU; pairs with any underlying CIAM",
        "Passkey-specific tooling (analytics, A/B testing, recovery flows) is the core product surface",
        "Self-hosted deployment is not available, managed only"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 700,
      "tco_at_500k_mau_estimate_usd_per_month": 2400,
      "tco_at_1m_mau_estimate_usd_per_month": 4500,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 5,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Deepest passkey-specific tooling in the market, adoption analytics, A/B testing, browser-and-device coverage data, and recovery-flow design that no other vendor ships.",
      "Vendor-neutral by design, slots in front of any underlying CIAM (Auth0, Cognito, Keycloak, custom) without replacement.",
      "Excellent docs and a public passkey adoption knowledge base that the wider industry references.",
      "EU-headquartered with EU data residency, fits sovereignty-conscious buyer profiles."
    ],
    "limitations": [
      "Not a full CIAM, does not handle social login, SAML SSO, B2B Organizations, or authorization.",
      "Adds a vendor and a hop in the auth flow; teams without an existing CIAM should pick a full-platform vendor first.",
      "Compliance footprint is narrow, SOC 2 Type II yes, ISO 27001 yes, but no HIPAA / FedRAMP / PCI DSS.",
      "Smaller community than full-platform CIAM; partner integrations are limited."
    ],
    "best_for": [
      "Teams running an existing CIAM that want to drive passkey adoption above the orchestration-light baseline",
      "B2C consumer apps where passkey adoption analytics and A/B testing on enrollment flows justify a specialist",
      "EU-based products needing GDPR-first design with explicit passkey-orchestration depth"
    ],
    "not_for": [
      "Greenfield apps without an existing CIAM, pick a full-platform vendor first",
      "Workloads requiring HIPAA, PCI DSS, or FedRAMP",
      "Teams that prefer one vendor for the entire auth stack"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-03-20",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Corbado Pricing",
        "url": "https://www.corbado.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Corbado Documentation",
        "url": "https://docs.corbado.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Corbado Passkey Knowledge Base",
        "url": "https://www.corbado.com/blog",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Corbado is the deepest passkey-specialist orchestration layer in 2026, focused exclusively on driving passkey adoption on top of any underlying CIAM, with adoption analytics, A/B testing, and recovery-flow tooling that no full-platform vendor ships. For teams running Auth0 / Cognito / Keycloak who want to fix passkey adoption without changing primary CIAM, Corbado is the singular pick alongside Authsignal. Not a full CIAM, pick one of those first if greenfield.",
    "faqs": [
      {
        "q": "How does Corbado differ from Authsignal?",
        "a": "Both are vendor-neutral orchestration layers that sit in front of an underlying CIAM. Authsignal covers broader risk decisioning and step-up MFA scenarios; Corbado is more narrowly passkey-specialist with deeper passkey-specific tooling, adoption analytics, A/B testing of enrollment flows, browser-and-device coverage data, and recovery flow design. Teams whose binding constraint is passkey adoption specifically tend to pick Corbado; teams whose constraint is broader risk decisioning tend to pick Authsignal."
      },
      {
        "q": "Does Corbado replace my CIAM?",
        "a": "No. Corbado is a layer that handles passkey enrollment, authentication, and recovery flows; the underlying CIAM continues to handle user storage, social login, SAML, and the rest of the auth surface. Most Corbado customers run it in front of Auth0, Cognito, Keycloak, or a custom-built auth system."
      },
      {
        "q": "What's special about Corbado's passkey analytics?",
        "a": "Corbado publishes one of the industry's most-referenced passkey adoption data sets, browser-and-device-level passkey support coverage, adoption rates by industry vertical, and conversion data on enrollment flow variants. Customers get the same analytics for their own deployment, which lets teams A/B test enrollment prompts and measure adoption rather than guess at it."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-20",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:a,jsx:e,jsxs:o}=arguments[0];function _createMdxContent(s){const r={a:\"a\",h2:\"h2\",p:\"p\",...s.components};return o(a,{children:[e(r.h2,{id:\"what-corbado-is\",children:e(r.a,{className:\"heading-anchor\",href:\"#what-corbado-is\",children:\"What Corbado is\"})}),\"\\n\",o(r.p,{children:[\"Corbado launched in 2020 in Munich with a tightly-scoped thesis: passkey adoption is an orchestration problem, not a protocol-support problem, and most CIAM vendors that shipped \",e(r.a,{href:\"/ciam-compass/glossary/webauthn/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"WebAuthn\"}),\" did not ship the prompting, A/B testing, recovery-flow design, and adoption analytics that turn passkey support into measurable adoption. The product is a passkey-specialist orchestration layer that sits in front of any underlying CIAM, with the deepest passkey-specific tooling among the vendors in this index.\"]}),\"\\n\",e(r.h2,{id:\"where-corbado-wins\",children:e(r.a,{className:\"heading-anchor\",href:\"#where-corbado-wins\",children:\"Where Corbado wins\"})}),\"\\n\",o(r.p,{children:[\"The passkey-specific depth is the structural edge. Adoption analytics that show which browsers, devices, and demographics enroll passkeys at what rates; A/B testing on enrollment prompts; \",e(r.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\" handling that knows whether to surface a passkey or a fallback; recovery flows designed for the case where a user loses every device. No full-platform CIAM ships this depth, Stytch and Hanko come closest, but Corbado's narrow focus produces tooling that the full-platform vendors don't bother to build.\"]}),\"\\n\",o(r.p,{children:[\"The vendor-neutral design matches \",e(r.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\"'s strategic stance. Teams running Auth0, Cognito, Keycloak, or a custom-built auth system can layer Corbado in days rather than migrating their primary CIAM. For organizations whose existing CIAM is fine on every axis except passkey adoption, this is the right composition.\"]}),\"\\n\",o(r.p,{children:[\"The public \",e(r.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\" knowledge base is an underrated trust signal. Corbado publishes detailed cross-vendor adoption data and browser-coverage matrices that the wider industry references, which positions the company as the substantive expert in the niche.\"]}),\"\\n\",e(r.p,{children:\"EU-headquartered with EU data residency is a meaningful sovereignty signal for European buyers.\"}),\"\\n\",e(r.h2,{id:\"where-corbado-hurts\",children:e(r.a,{className:\"heading-anchor\",href:\"#where-corbado-hurts\",children:\"Where Corbado hurts\"})}),\"\\n\",o(r.p,{children:[\"It is not a CIAM. No user storage flows beyond passkey credentials, no social login orchestration, no SAML SSO, no B2B Organizations model, no \",e(r.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" layer. Greenfield teams without an existing CIAM should pick a full-platform vendor first.\"]}),\"\\n\",e(r.p,{children:\"Adding a vendor and a hop in the auth flow is real architectural cost. Teams without a clear passkey-adoption problem to solve are better off relying on their primary CIAM's built-in passkey support.\"}),\"\\n\",o(r.p,{children:[\"Compliance breadth is narrower than enterprise SaaS, SOC 2 Type II yes, ISO 27001 yes, no HIPAA, no FedRAMP, no PCI DSS. For workloads requiring those specifically, \",e(r.a,{href:\"/ciam-compass/vendors/corbado/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Corbado\"}),\" is a layered concern alongside the primary CIAM.\"]}),\"\\n\",e(r.p,{children:\"The community is small, partner integrations are limited, and the niche scope means Corbado is not a one-vendor-for-everything answer.\"}),\"\\n\",e(r.h2,{id:\"how-corbado-compares\",children:e(r.a,{className:\"heading-anchor\",href:\"#how-corbado-compares\",children:\"How Corbado compares\"})}),\"\\n\",o(r.p,{children:[\"The closest direct comparison is \",e(r.a,{href:\"/ciam-compass/compare/authsignal-vs-corbado/\",children:\"Authsignal vs Corbado\"}),\" for the orchestration-layer call. Most teams evaluating Corbado are also evaluating whether to switch full-platform CIAM to one with built-in orchestration, see \",e(r.a,{href:\"/ciam-compass/compare/auth0-vs-stytch/\",children:\"Auth0 vs Stytch\"}),\" and \",e(r.a,{href:\"/ciam-compass/compare/auth0-vs-descope/\",children:\"Auth0 vs Descope\"}),\" for that path. For self-hosted passkey-first OSS, \",e(r.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" is the alternative that pairs passkey orchestration with full-platform user management.\"]})]})}return{default:function(a={}){const{wrapper:o}=a.components||{};return o?e(o,{...a,children:e(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/corbado/",
    "edit_path": "content/vendors/corbado.mdx"
  },
  {
    "type": "vendor",
    "slug": "curity",
    "name": "Curity",
    "legal_name": "Curity AB",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://curity.io",
    "docs_url": "https://curity.io/docs/idsvr/latest/",
    "pricing_url": null,
    "github_url": "https://github.com/curityio",
    "hq": "Stockholm, Sweden",
    "founded": 2015,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": null,
      "last_round": {
        "stage": "series-a",
        "amount_usd": null,
        "year": 2023,
        "lead": "GRO Capital"
      },
      "investors": [
        "GRO Capital",
        "Fairpoint Capital"
      ],
      "profitable": null,
      "notes": "Stockholm OAuth/OIDC token-server specialist; growth round from GRO Capital (2023), amount undisclosed.",
      "source": "https://curity.io/investors/"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted",
      "on-prem"
    ],
    "target_segments": [
      "enterprise",
      "public-sector",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "python",
          "go",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Plugins (Java) + Configuration as Code (XML / CLI)"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": true
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": "partial",
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Community Edition free; commercial editions enterprise quote-based",
      "notable_costs": [
        "Curity Identity Server Community Edition is free (with feature limits)",
        "Standard / Enterprise / Pro editions priced via enterprise quote",
        "Strong fit for OAuth-and-OIDC-spec-correct deployments and financial services"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 4500,
      "tco_at_500k_mau_estimate_usd_per_month": 14000,
      "tco_at_1m_mau_estimate_usd_per_month": 25000,
      "pricing_transparency_score": 2
    },
    "dx_score": 4,
    "docs_quality": 5,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Among the most spec-correct OAuth 2.0 / OIDC implementations in the industry, used by financial services and regulated workloads needing strict standards compliance.",
      "Strong on financial-grade APIs (FAPI) and Open Banking specifications, uncommon outside the most enterprise-focused vendors.",
      "Configuration-as-code model (XML or CLI) treats identity configuration like infrastructure-as-code, with full audit and version control.",
      "EU-headquartered with EU data residency."
    ],
    "limitations": [
      "Enterprise-only commercial editions with opaque pricing; Community Edition has feature limits.",
      "Configuration-as-code model has a learning curve compared to admin-UI-driven competitors.",
      "Smaller community than incumbent enterprise CIAM.",
      "No FedRAMP, no PCI DSS direct attestation."
    ],
    "best_for": [
      "Financial services and Open Banking deployments needing FAPI compliance",
      "Standards-purist deployments needing spec-correct OAuth / OIDC",
      "EU-based regulated workloads needing on-prem deployment with sovereignty"
    ],
    "not_for": [
      "Greenfield SaaS prioritizing developer velocity over standards depth",
      "Workloads requiring FedRAMP authorization",
      "Teams uncomfortable with configuration-as-code identity management"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-04-08",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Curity Identity Server documentation",
        "url": "https://curity.io/docs/idsvr/latest/",
        "accessed": "2026-04-22"
      },
      {
        "title": "Curity products",
        "url": "https://curity.io",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Curity is the standards-purist enterprise CIAM in 2026, among the most spec-correct OAuth 2.0 / OIDC implementations available, with strong FAPI and Open Banking support that suits financial services and regulated workloads. The configuration-as-code model treats identity like infrastructure-as-code, which appeals to engineering-mature enterprises. Outside the standards-correctness or FAPI use cases, the enterprise pricing and learning curve make broader-scope CIAM (Auth0, Ping) more practical.",
    "faqs": [
      {
        "q": "What is FAPI and why does it matter?",
        "a": "FAPI (Financial-grade API) is a profile of OAuth 2.0 / OIDC for high-security financial scenarios, Open Banking, payment APIs, fintech. It tightens token, signing, and registration requirements beyond stock OAuth. Curity is among the most-deployed CIAM in production FAPI deployments globally."
      },
      {
        "q": "Is Curity Community Edition usable for production?",
        "a": "Yes within the feature limits, basic OAuth / OIDC, password authentication, and standard flows are supported. Production B2C-or-B2B-SaaS deployments typically need the Standard or higher edition for advanced authentication, custom flows, and clustering."
      },
      {
        "q": "How does Curity compare to Ping Identity?",
        "a": "Both are enterprise-focused with strong on-prem deployment options. Curity is materially smaller, more standards-purist, and EU-headquartered; Ping is larger, more federation-broad, and US-headquartered with FedRAMP. For FAPI / Open Banking specifically, Curity is often the better choice; for general enterprise federation, Ping has broader reach."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-08",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:a}=arguments[0];function _createMdxContent(i){const n={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return a(e,{children:[r(n.h2,{id:\"what-curity-is\",children:r(n.a,{className:\"heading-anchor\",href:\"#what-curity-is\",children:\"What Curity is\"})}),\"\\n\",a(n.p,{children:[r(n.a,{href:\"/ciam-compass/vendors/curity/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Curity\"}),\" launched in 2015 in Stockholm with a standards-purist thesis: the OAuth 2.0 and OIDC specifications had matured enough to enable a CIAM built around spec-correctness, particularly for financial services and Open Banking scenarios that require Financial-grade API (FAPI) compliance. The product is the Curity Identity Server, sold in Community (free with feature limits), Standard, Enterprise, and Pro editions.\"]}),\"\\n\",r(n.h2,{id:\"where-curity-wins\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-curity-wins\",children:\"Where Curity wins\"})}),\"\\n\",a(n.p,{children:[\"Among the most spec-correct OAuth 2.0 / OIDC implementations available, meaningful in regulated environments where strict standards compliance is auditable. Strong \",r(n.a,{href:\"/ciam-compass/glossary/fapi/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"FAPI\"}),\" and Open Banking support uncommon outside the most enterprise-focused vendors. Configuration-as-code treats identity like infrastructure-as-code, with full audit and version control. EU-headquartered with EU data residency.\"]}),\"\\n\",r(n.h2,{id:\"where-curity-hurts\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-curity-hurts\",children:\"Where Curity hurts\"})}),\"\\n\",a(n.p,{children:[\"Enterprise-only commercial editions with opaque pricing exclude mid-market evaluation, although the Community Edition (free with feature limits) provides a partial on-ramp for proof-of-concept work. The configuration-as-code model imposes a learning curve compared to admin-UI-driven competitors, particularly for teams used to Auth0's dashboard or Okta's console. The community is smaller than incumbent enterprise CIAM like Ping or ForgeRock, which means fewer Stack Overflow answers and fewer partner integrations. No FedRAMP \",r(n.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\", no PCI DSS direct attestation.\"]}),\"\\n\",r(n.h2,{id:\"how-curity-compares\",children:r(n.a,{className:\"heading-anchor\",href:\"#how-curity-compares\",children:\"How Curity compares\"})}),\"\\n\",a(n.p,{children:[\"The closest comparisons are \",r(n.a,{href:\"/ciam-compass/compare/auth0-vs-curity/\",children:\"Auth0 vs Curity\"}),\", \",r(n.a,{href:\"/ciam-compass/compare/ping-identity-vs-curity/\",children:\"Ping Identity vs Curity\"}),\", and \",r(n.a,{href:\"/ciam-compass/compare/curity-vs-forgerock/\",children:\"Curity vs ForgeRock\"}),\" for the standards-correctness call. For OSS alternatives with similar deployment autonomy, \",r(n.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",r(n.a,{href:\"/ciam-compass/vendors/wso2-is/\",children:\"WSO2 IS\"}),\" are the comparisons.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?r(a,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/curity/",
    "edit_path": "content/vendors/curity.mdx"
  },
  {
    "type": "vendor",
    "slug": "cyberark-customer-identity",
    "name": "CyberArk Identity",
    "legal_name": "CyberArk Identity (CyberArk Software, Ltd.; lineage Centrify → Idaptive → CyberArk Identity)",
    "parent_company": "CyberArk Software, Ltd.",
    "acquired_by": "CyberArk (Idaptive acquisition closed May 2020, $70M)",
    "website": "https://www.cyberark.com/products/customer-identity/",
    "docs_url": "https://docs.cyberark.com",
    "pricing_url": null,
    "github_url": null,
    "hq": "Newton, Massachusetts, USA / Petach Tikva, Israel",
    "founded": 2018,
    "status": "active",
    "funding": {
      "model": "public",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": true,
      "notes": "Part of CyberArk (NASDAQ: CYBR); built on the Idaptive business CyberArk acquired for $70M in 2020.",
      "source": "https://www.cyberark.com/press/cyberark-acquires-identity-as-a-service-leader-idaptive/"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "python",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Workflows + custom rules"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": "Moderate",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based via CyberArk sales",
      "notable_costs": [
        "CyberArk enterprise sales engagement; quote-based",
        "Strong fit for existing CyberArk Privileged Access Management customers",
        "Identity Security Platform bundle pricing typical"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 5500,
      "tco_at_500k_mau_estimate_usd_per_month": 17000,
      "tco_at_1m_mau_estimate_usd_per_month": 30000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Tight integration with CyberArk's Privileged Access Management portfolio, uncommon CIAM-plus-PAM consolidation.",
      "FedRAMP Moderate authorization plus comprehensive enterprise compliance.",
      "Strong adaptive MFA and risk decisioning, inherits Idaptive's security-first design.",
      "CyberArk's enterprise security credibility eases buying-committee evaluation."
    ],
    "limitations": [
      "Enterprise-only commercial structure with no public pricing.",
      "DX trails developer-first tier; admin tooling reflects classic enterprise design.",
      "Outside CyberArk ecosystem, the integration story is weaker.",
      "Smaller customer base than the largest legacy CIAM incumbents."
    ],
    "best_for": [
      "Existing CyberArk Privileged Access Management customers consolidating CIAM",
      "Enterprise security-conscious deployments needing CIAM plus PAM coordination",
      "Regulated industries requiring FedRAMP Moderate"
    ],
    "not_for": [
      "Mid-market SaaS or startups",
      "Greenfield projects without CyberArk context",
      "Developer-velocity-focused teams"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-05-08",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "CyberArk Customer Identity product page",
        "url": "https://www.cyberark.com/products/customer-identity/",
        "accessed": "2026-04-22"
      },
      {
        "title": "CyberArk documentation",
        "url": "https://docs.cyberark.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "CyberArk Customer Identity (formerly Idaptive) is the right CIAM choice for existing CyberArk Privileged Access Management customers consolidating identity into one vendor, the CIAM-plus-PAM combination is uncommon and meaningful for security-conscious enterprises. FedRAMP Moderate plus strong adaptive MFA inherited from Idaptive suit regulated workloads. Outside CyberArk ecosystem, the standard enterprise-CIAM trade-offs apply: high pricing, dated DX, and limited mid-market access.",
    "faqs": [
      {
        "q": "What was Idaptive?",
        "a": "Idaptive was a workforce-and-customer identity platform founded in 2018, originally spun out from Centrify. CyberArk acquired Idaptive in May 2020 for $70M and integrated it into the broader CyberArk Identity Security Platform. The Customer Identity product retains the Idaptive B2C heritage."
      },
      {
        "q": "Why pair CIAM with Privileged Access Management?",
        "a": "Most CIAM and PAM are sold as separate vendors. CyberArk consolidates them, which lets enterprises apply consistent risk decisioning, policy, and audit across customer-facing and privileged-employee identities. For security-conscious organizations operating critical infrastructure, this is a meaningful architectural simplification."
      },
      {
        "q": "What does CyberArk Customer Identity cost?",
        "a": "Enterprise quote-based via CyberArk sales, typically as part of broader Identity Security Platform bundle pricing. Six-figure annual minimums typical at enterprise scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-08",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      },
      {
        "date": "2026-05-08",
        "summary": "Renamed from 'CyberArk Customer Identity' to 'CyberArk Identity' to reflect the current brand. Lineage clarified in legal_name: Centrify → Idaptive → CyberArk Identity."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:t}=arguments[0];function _createMdxContent(i){const n={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return t(e,{children:[r(n.h2,{id:\"what-cyberark-customer-identity-is\",children:r(n.a,{className:\"heading-anchor\",href:\"#what-cyberark-customer-identity-is\",children:\"What CyberArk Customer Identity is\"})}),\"\\n\",r(n.p,{children:\"CyberArk Customer Identity is CyberArk's CIAM, originating as Idaptive (founded 2018 as a Centrify spinout) and acquired by CyberArk in May 2020 for $70M. The product is integrated into CyberArk's broader Identity Security Platform alongside its dominant Privileged Access Management offerings. The buyer is typically an existing CyberArk PAM customer consolidating CIAM into one vendor for cross-domain risk and audit coordination.\"}),\"\\n\",r(n.h2,{id:\"where-cyberark-customer-identity-wins\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-cyberark-customer-identity-wins\",children:\"Where CyberArk Customer Identity wins\"})}),\"\\n\",t(n.p,{children:[\"The CIAM-plus-PAM consolidation is uncommon in the index and meaningful for security-conscious enterprises that want consistent policy, risk decisioning, and audit across customer and privileged-employee identities. Strong adaptive \",r(n.a,{href:\"/ciam-compass/glossary/mfa/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MFA\"}),\" inherited from Idaptive's security-first heritage. FedRAMP Moderate plus comprehensive enterprise compliance.\"]}),\"\\n\",r(n.h2,{id:\"where-cyberark-customer-identity-hurts\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-cyberark-customer-identity-hurts\",children:\"Where CyberArk Customer Identity hurts\"})}),\"\\n\",r(n.p,{children:\"Enterprise-only commercial structure with opaque pricing. DX trails developer-first tier. Outside CyberArk ecosystem, the integration story is weaker. Smaller customer base than the largest legacy CIAM incumbents.\"}),\"\\n\",r(n.h2,{id:\"how-cyberark-customer-identity-compares\",children:r(n.a,{className:\"heading-anchor\",href:\"#how-cyberark-customer-identity-compares\",children:\"How CyberArk Customer Identity compares\"})}),\"\\n\",t(n.p,{children:[\"The closest comparisons are \",r(n.a,{href:\"/ciam-compass/compare/auth0-vs-cyberark-customer-identity/\",children:\"Auth0 vs CyberArk Customer Identity\"}),\" for the developer-first-vs-enterprise-PAM call, \",r(n.a,{href:\"/ciam-compass/compare/ping-identity-vs-cyberark-customer-identity/\",children:\"Ping Identity vs CyberArk Customer Identity\"}),\", and \",r(n.a,{href:\"/ciam-compass/compare/beyond-identity-vs-cyberark-customer-identity/\",children:\"Beyond Identity vs CyberArk Customer Identity\"}),\" for the security-forward enterprise tier.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?r(t,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/cyberark-customer-identity/",
    "edit_path": "content/vendors/cyberark-customer-identity.mdx"
  },
  {
    "type": "vendor",
    "slug": "descope",
    "name": "Descope",
    "legal_name": "Descope, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://descope.com",
    "docs_url": "https://docs.descope.com",
    "pricing_url": "https://descope.com/pricing",
    "github_url": "https://github.com/descope",
    "hq": "Los Altos, California, USA",
    "founded": 2022,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 88000000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 53000000,
        "year": 2023,
        "lead": "Lightspeed Venture Partners"
      },
      "investors": [
        "Lightspeed Venture Partners",
        "GGV Capital",
        "Unusual Ventures",
        "Dell Technologies Capital",
        "Silicon Valley CISO Investments"
      ],
      "profitable": null,
      "notes": "One of the largest seed rounds in CIAM history: $53M at launch, extended to $88M. Founded by the Demisto (Palo Alto Networks) team.",
      "source": "https://techcrunch.com/2023/02/15/passwordless-authentication-startup-descope-lands-whopping-53m-seed-round/"
    },
    "categories": [
      "developer-first-ciam",
      "identity-orchestration",
      "b2c-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": "partial",
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": "partial",
        "fga_engine": "partial",
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "php",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Flows (no-code visual editor) + Connectors"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": true,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": "partial",
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": "partial",
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 7500
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "B2B SSO and Custom Flows",
      "notable_costs": [
        "B2B add-on for SSO connections and SCIM",
        "Identity orchestration (Flows) included at all tiers",
        "List price does not scale as gently as passwordless-native specialists; enterprise volume is quote-shaped"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 850,
      "tco_at_500k_mau_estimate_usd_per_month": 3000,
      "tco_at_1m_mau_estimate_usd_per_month": 5800,
      "pricing_transparency_score": 3
    },
    "dx_score": 5,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": false,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Identity orchestration (Flows) is the product: the strongest no-code visual editor in this index for branching MFA, risk-based step-up, and third-party connectors.",
      "Native MCP support for AI agent identity, early mover among full-platform CIAM vendors.",
      "WebAuthn exists as a Flow block, useful when you already bought Descope for orchestration, not as a passwordless-first default.",
      "Founded by the Demisto / Palo Alto Networks team; bot defense and risk decisioning show that background."
    ],
    "limitations": [
      "Not a passwordless-native or passkey-native CIAM. Passkeys and magic links are Flow components, not the product DNA. For native passkeys, look at MojoAuth or Stytch.",
      "Scaled pricing is limited. Volume at 500k-plus MAU is quote-shaped and does not decline as clearly as MojoAuth's published MAU table.",
      "Flow editor adds a learning curve; teams who want code-only auth may find it heavier than Stytch or Clerk.",
      "Compliance footprint is narrower, no FedRAMP, no PCI DSS direct attestation."
    ],
    "best_for": [
      "Teams that want identity orchestration without writing the journey themselves",
      "Mid-market SaaS wiring risk engines, IdPs, and step-up into one visual flow",
      "Early adopters of agentic / AI-agent identity via MCP"
    ],
    "not_for": [
      "Teams whose primary job is native passkeys or passwordless-first login",
      "Cost-sensitive deployments at 500k-plus MAU looking for published scale pricing",
      "Workloads requiring FedRAMP or PCI DSS",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Descope Pricing",
        "url": "https://descope.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Descope Documentation",
        "url": "https://docs.descope.com",
        "accessed": "2026-08-19"
      },
      {
        "title": "Descope Series A announcement (2022)",
        "url": "https://descope.com/blog/",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Descope is the identity-orchestration pick in 2026, not the passwordless-native pick. Flows is the strongest visual auth designer in this index. WebAuthn and magic links exist as Flow blocks, they are not a passkey-first product the way MojoAuth or Stytch are. Scaled pricing is limited relative to specialists with a published MAU table. Pick Descope to author journeys. Pick MojoAuth or Stytch to enroll passkeys. Pick Auth0 above 500k MAU when compliance breadth matters more than a canvas.",
    "faqs": [
      {
        "q": "What is Descope Flows?",
        "a": "Flows is Descope's visual identity orchestration layer, a no-code editor that lets teams design login, signup, MFA, and recovery flows with conditional branching, risk-based decisioning, and reusable building blocks. It functions as the orchestration layer that vendors like Authsignal sell separately."
      },
      {
        "q": "Does Descope support AI agent identity (MCP)?",
        "a": "Yes, Descope ships native MCP support for issuing scoped, short-lived tokens to AI agents and distinguishing them from human-issued tokens. Among full-platform CIAM vendors, Descope is among the earliest to support this in production."
      },
      {
        "q": "Is Descope a passwordless or passkey-native vendor?",
        "a": "No. Descope is an identity orchestration platform. Passkeys, magic links, and OTP are available as Flow components, documented as methods you drop into a visual journey. That is not the same as a passwordless-native CIAM (MojoAuth, Stytch) where those methods are the default product. If passkey adoption is the job, start with MojoAuth or Stytch."
      },
      {
        "q": "How does Descope compare to Auth0 on price?",
        "a": "Descope is cheaper than Auth0 below 500k MAU at standard configurations. At 500k-plus MAU the list is quote-shaped and does not scale as gently as MojoAuth's published MAU table. Do not pick Descope as the cost winner at consumer scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Editorial correction: Descope is orchestration-first, not passkey-native. passkey_native set false, passwordless_only_flows partial, orchestration score 3/5. Scaled pricing flagged as limited vs MojoAuth's published MAU table."
      },
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-04-14",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(o){const t={a:\"a\",em:\"em\",h2:\"h2\",p:\"p\",...o.components};return s(e,{children:[a(t.h2,{id:\"what-descope-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-descope-is\",children:\"What Descope is\"})}),\"\\n\",s(t.p,{children:[a(t.a,{href:\"/ciam-compass/vendors/descope/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Descope\"}),\" launched in 2022, founded by veterans of Imperva and Identitymind. The pitch from day one was identity orchestration, that the bottleneck in modern CIAM rollouts isn't auth protocol support but the \",a(t.em,{children:\"flow logic\"}),\" on top: when to step up, when to silently allow, when to enroll a \",a(t.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\", what to do when a user lands without one. The Flows visual editor is the product's differentiator and the reason most teams pick Descope over Auth0 or a passwordless specialist.\"]}),\"\\n\",a(t.h2,{id:\"where-descope-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-descope-wins\",children:\"Where Descope wins\"})}),\"\\n\",s(t.p,{children:[\"Flows is the headline. Where competitors expose a code SDK and ask the team to wire up \",a(t.a,{href:\"/ciam-compass/glossary/mfa/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MFA\"}),\" decisioning, Descope ships a visual editor that handles conditional branching, risk-based step-up, recovery, and third-party connectors as composable blocks. Passkeys and magic links are available as methods inside those flows. That is orchestration, not a passwordless-native product.\"]}),\"\\n\",s(t.p,{children:[\"The MCP and AI-agent identity story is also more mature than most full-platform CIAM vendors, Descope ships first-class scoped tokens for agents and patterns for distinguishing agent vs human \",a(t.a,{href:\"/ciam-compass/glossary/authentication/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authentication\"}),\". As MCP-driven AI agents become real production traffic, this matters.\"]}),\"\\n\",s(t.p,{children:[\"The team's security background (Imperva, Identitymind) shows in the risk decisioning, bot defense, and adaptive MFA surface. These are areas where Auth0 has historically been stronger than \",a(t.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" and Clerk; Descope is competitive with Auth0 here while being materially cheaper.\"]}),\"\\n\",a(t.h2,{id:\"where-descope-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-descope-hurts\",children:\"Where Descope hurts\"})}),\"\\n\",s(t.p,{children:[\"It is not passkey-native and not passwordless-native. If the job is enrollment, start with \",a(t.a,{href:\"/ciam-compass/vendors/mojoauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"MojoAuth\"}),\" or Stytch. Using Descope for that job is buying a canvas to reconstruct a specialist.\"]}),\"\\n\",s(t.p,{children:[\"Scaled pricing is limited. Compass TCO at 1M \",a(t.a,{href:\"/ciam-compass/glossary/mau/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MAU\"}),\" is about $5,800, and volume above that is quote-shaped. MojoAuth publishes a declining per-MAU table through 10M MAU. Do not pick Descope as the cost winner at enterprise consumer scale.\"]}),\"\\n\",s(t.p,{children:[\"Community size is the lasting friction. \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" and Clerk have more sample apps and more third-party integrations. Code-first teams who do not want a visual editor will find Flows heavier than Stytch or MojoAuth.\"]}),\"\\n\",s(t.p,{children:[\"Compliance breadth is narrower than Auth0, no FedRAMP, no PCI DSS direct \",a(t.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\".\"]}),\"\\n\",a(t.h2,{id:\"how-descope-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-descope-compares\",children:\"How Descope compares\"})}),\"\\n\",s(t.p,{children:[\"The two most direct comparisons are \",a(t.a,{href:\"/ciam-compass/compare/stytch-vs-descope/\",children:\"Stytch vs Descope\"}),\" and \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-descope/\",children:\"Auth0 vs Descope\"}),\". For pure B2B SSO with deep \",a(t.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" is closer. For self-hosted, \",a(t.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",a(t.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\" remain the standard alternatives. For orchestration as a separate layer wrapping any underlying CIAM, \",a(t.a,{href:\"/ciam-compass/vendors/authsignal/\",children:\"Authsignal\"}),\" is the specialist option.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/descope/",
    "edit_path": "content/vendors/descope.mdx"
  },
  {
    "type": "vendor",
    "slug": "entra-external-id",
    "name": "Microsoft Entra External ID",
    "legal_name": "Microsoft Entra External ID",
    "parent_company": "Microsoft Corporation",
    "acquired_by": null,
    "website": "https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-external-id",
    "docs_url": "https://learn.microsoft.com/en-us/entra/external-id/",
    "pricing_url": "https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing",
    "github_url": null,
    "hq": "Redmond, Washington, USA",
    "founded": 2024,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Part of Microsoft Entra (NASDAQ: MSFT); funded internally, never a standalone company.",
      "source": "https://www.microsoft.com/en-us/security/business/identity-access/microsoft-entra-external-id"
    },
    "categories": [
      "enterprise-ciam",
      "cloud-native-ciam",
      "b2c-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": false,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": "partial",
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": true,
        "sdks": [
          "js",
          "node",
          "react",
          "dotnet",
          "python",
          "java",
          "go",
          "ios",
          "swift",
          "android",
          "kotlin"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Azure Functions + Custom policies (External Identities)"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": "partial",
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": true,
        "account_linking": "partial",
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 50000
      },
      "paid_starts_at_usd": 0,
      "enterprise_quote_required_above": "Per-MAU pricing past free tier; volume discounts via Azure EA",
      "notable_costs": [
        "Free tier: 50k MAU on standard authentication",
        "Per-MAU pricing applies above free tier, competitive at consumer scale",
        "Premium features (P1 / P2) priced separately for advanced threat detection",
        "Azure infrastructure costs for Logic Apps, Functions, and audit log retention add up"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 165,
      "tco_at_500k_mau_estimate_usd_per_month": 1500,
      "tco_at_1m_mau_estimate_usd_per_month": 3300,
      "pricing_transparency_score": 3
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Successor to Azure AD B2C with materially modernized DX, simplified policy model, and unified Entra console.",
      "FedRAMP High, PCI Level 1, HIPAA, ISO 27001/27018, strongest compliance footprint among hyperscaler CIAM.",
      "Native Azure integration, Conditional Access, Logic Apps, Sentinel, and the broader Microsoft security graph.",
      "Generous free tier (50k MAU) and competitive per-MAU pricing at consumer scale."
    ],
    "limitations": [
      "DX is improved over Azure AD B2C but still trails Auth0 / Clerk / Stytch, Microsoft's documentation tone, terminology, and admin console are AAD-shaped.",
      "B2B Organizations model is partial, multi-tenancy works through Entra tenants but lacks the SaaS-native ergonomics of WorkOS or Frontegg.",
      "No native FGA / Zanzibar-style fine-grained authorization.",
      "Migrations between Azure AD B2C (the predecessor) and External ID are non-trivial; legacy customers carry policy debt."
    ],
    "best_for": [
      "Organizations already standardized on Microsoft 365 / Entra / Azure",
      "Workloads requiring FedRAMP High, PCI Level 1, or strict Microsoft-compliance baselines",
      "Cost-sensitive consumer apps in the Microsoft ecosystem"
    ],
    "not_for": [
      "Teams that prioritize developer velocity and DX over Microsoft-ecosystem integration",
      "B2B SaaS needing first-class Organizations / SCIM / per-tenant audit",
      "Multi-cloud or AWS / GCP-native deployments"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Microsoft Entra External ID overview",
        "url": "https://learn.microsoft.com/en-us/entra/external-id/",
        "accessed": "2026-08-19"
      },
      {
        "title": "Microsoft Entra pricing",
        "url": "https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Azure AD B2C FAQ (support until at least May 2030; P2 retired 15 March 2026)",
        "url": "https://learn.microsoft.com/en-us/azure/active-directory-b2c/faq",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Microsoft Entra External ID is the modern successor to Azure AD B2C. New B2C licenses stopped on 1 May 2025. Azure AD B2C P2 / Identity Protection retired on 15 March 2026. Existing B2C P1 tenants remain supported until at least May 2030, but they are in maintenance mode with no new features. Entra External ID is the right CIAM when the organization already runs Microsoft 365 and Azure, or needs FedRAMP High. High Scale Compatibility mode now exists for large B2C-to-External-ID migrations. Outside a Microsoft shop, developer-first CIAM still wins on velocity.",
    "faqs": [
      {
        "q": "How is Entra External ID different from Azure AD B2C?",
        "a": "Entra External ID is the successor product, generally available in 2024, with a unified Entra admin console, simplified policy model, and modernized SDK surface. Azure AD B2C P1 remains supported for existing customers until at least May 2030. P2 / Identity Protection retired on 15 March 2026. New B2C licenses have not been sold since 1 May 2025. Migrations are non-trivial; custom policies must be redesigned, and High Scale Compatibility mode still omits some B2C features including some passkey and social-IdP cases."
      },
      {
        "q": "Did Azure AD B2C shut down on 15 March 2026?",
        "a": "No. That date retired Azure AD B2C Premium P2 (Identity Protection) for all customers. Microsoft has committed to supporting remaining Azure AD B2C tenants until at least May 2030. The platform is frozen. New work belongs on Entra External ID."
      },
      {
        "q": "Does Entra External ID support FedRAMP?",
        "a": "Yes, FedRAMP High via Azure Government and the in-scope commercial regions. Combined with PCI Level 1 and HIPAA, this is the broadest compliance footprint among hyperscaler-native CIAM, materially ahead of Cognito and Firebase Auth on attestation breadth."
      },
      {
        "q": "When does Entra External ID make sense over Auth0?",
        "a": "When the organization runs on Microsoft 365 / Azure and benefits from Conditional Access integration, Sentinel security graph integration, or Logic Apps automation. For AWS-native or developer-velocity-focused teams, Auth0 retains a meaningful DX advantage."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Corrected Azure AD B2C timeline: 15 March 2026 retired P2 / Identity Protection only. P1 tenants remain supported until at least May 2030. Portal changelog and alternatives pages aligned to the Microsoft Learn FAQ."
      },
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-05-22",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      },
      {
        "date": "2026-05-08",
        "summary": "Verdict updated for Entra External ID GA (September 2024) and Azure AD B2C end-of-sale (1 May 2025). The March 2026 tenant-shutdown reading in this entry was later corrected: only P2 retired that day."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(t){const r={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return n(e,{children:[a(r.h2,{id:\"what-entra-external-id-is\",children:a(r.a,{className:\"heading-anchor\",href:\"#what-entra-external-id-is\",children:\"What Entra External ID is\"})}),\"\\n\",a(r.p,{children:\"Entra External ID is Microsoft's customer identity product, generally available in 2024 as the successor to Azure AD B2C. The product line sits inside the broader Entra (formerly Azure AD) family, same admin console, same conditional access engine, same audit pipeline, but with a distinct tenant model for external customer identities and a policy surface designed for B2C and B2B-mixed workloads. The buyer is typically an organization already running Microsoft 365 or Azure infrastructure, where unified identity governance across employees, partners, and customers is the strategic anchor.\"}),\"\\n\",a(r.h2,{id:\"where-entra-external-id-wins\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-entra-external-id-wins\",children:\"Where Entra External ID wins\"})}),\"\\n\",a(r.p,{children:\"The Microsoft-stack integration is the structural advantage. Conditional Access policies that govern employee identities can extend coherently to external identities; Microsoft Sentinel captures the audit signal in the same SIEM pane; Logic Apps and Azure Functions extend the policy surface without leaving the Microsoft tooling. For organizations whose security operations are already built around Microsoft, this avoids a parallel toolchain.\"}),\"\\n\",a(r.p,{children:\"Compliance breadth is unmatched among hyperscaler CIAM. FedRAMP High, PCI DSS Level 1, HIPAA, ISO 27001/27018, GDPR, all attested at the Microsoft service level. For federal workloads, healthcare, and fintech, Entra External ID often lands as the only fully-attested cloud-native option.\"}),\"\\n\",n(r.p,{children:[\"The free tier (50k MAU) and per-MAU pricing curve are competitive with Cognito and below most SaaS CIAM at consumer scale. For high-MAU consumer apps in the Microsoft ecosystem, the unit economics favor Entra over \",a(r.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" by a wide margin.\"]}),\"\\n\",a(r.p,{children:\"The DX is materially improved over Azure AD B2C, simplified policy model, unified console, modernized SDKs, though still not at the level of developer-first CIAM.\"}),\"\\n\",a(r.h2,{id:\"where-entra-external-id-hurts\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-entra-external-id-hurts\",children:\"Where Entra External ID hurts\"})}),\"\\n\",n(r.p,{children:[\"DX is the lasting friction. Microsoft's documentation tone is reference-first, the terminology is Azure-AD-shaped, and the admin console reflects enterprise-IT design rather than developer-product design. Teams accustomed to Auth0 / Clerk / \",a(r.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" find the onboarding curve longer.\"]}),\"\\n\",n(r.p,{children:[\"The B2B Organizations model is partial. Multi-tenancy works through Entra tenants but lacks the SaaS-native ergonomics of WorkOS or \",a(r.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\", no embedded Admin Portal, no per-tenant feature flags, no first-class Organizations object. For B2B SaaS specifically, the gap is meaningful.\"]}),\"\\n\",n(r.p,{children:[\"There's no native Zanzibar-style FGA. ABAC works through claims and Conditional Access; for fine-grained per-resource permissions, pair with an \",a(r.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" service.\"]}),\"\\n\",a(r.p,{children:\"Migrations from Azure AD B2C to External ID are non-trivial. Custom policies do not port cleanly; the new External Identities policy model is simpler but different. Legacy AAD B2C customers carry policy debt.\"}),\"\\n\",a(r.p,{children:\"Outside the Microsoft ecosystem, the integration story is weaker. AWS-native or GCP-native architectures typically reach for Cognito or Firebase Auth instead.\"}),\"\\n\",a(r.h2,{id:\"how-entra-external-id-compares\",children:a(r.a,{className:\"heading-anchor\",href:\"#how-entra-external-id-compares\",children:\"How Entra External ID compares\"})}),\"\\n\",n(r.p,{children:[\"The closest hyperscaler comparisons are \",a(r.a,{href:\"/ciam-compass/compare/cognito-vs-entra-external-id/\",children:\"Cognito vs Entra External ID\"}),\" and \",a(r.a,{href:\"/ciam-compass/compare/entra-external-id-vs-firebase-auth/\",children:\"Firebase Auth vs Entra External ID\"}),\". For developer velocity at comparable compliance footprint, \",a(r.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" is the alternative. For strict on-prem deployment with similar compliance autonomy, \",a(r.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" is the self-hosted option.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/entra-external-id/",
    "edit_path": "content/vendors/entra-external-id.mdx"
  },
  {
    "type": "vendor",
    "slug": "firebase-auth",
    "name": "Firebase Authentication",
    "legal_name": "Firebase Authentication (Google Cloud Identity Platform)",
    "parent_company": "Google LLC",
    "acquired_by": null,
    "website": "https://firebase.google.com/products/auth",
    "docs_url": "https://firebase.google.com/docs/auth",
    "pricing_url": "https://firebase.google.com/pricing",
    "github_url": null,
    "hq": "Mountain View, California, USA",
    "founded": 2014,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Part of Firebase, acquired by Google (Alphabet, NASDAQ: GOOGL) in 2014.",
      "source": "https://firebase.google.com/products/auth"
    },
    "categories": [
      "cloud-native-ciam",
      "b2c-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": "partial",
        "biometric": true,
        "hardware_keys": "partial",
        "sso_saml": "partial",
        "sso_oidc": "partial",
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": "partial",
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": "partial",
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": false,
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "flutter",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Cloud Functions for Firebase + Auth Triggers"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": "partial",
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": "partial",
        "pci_dss": "partial",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "partial",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": "partial",
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 50000
      },
      "paid_starts_at_usd": 0,
      "enterprise_quote_required_above": "Identity Platform pricing past Spark/Blaze plan limits",
      "notable_costs": [
        "Free Spark plan covers 50k MAU (Identity Platform free tier)",
        "Above 50k MAU, per-MAU pricing on Blaze plan applies",
        "SAML / OIDC and multi-tenancy require Identity Platform upgrade (paid)",
        "Cloud Functions for Auth Triggers billed per-invocation"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 250,
      "tco_at_500k_mau_estimate_usd_per_month": 2300,
      "tco_at_1m_mau_estimate_usd_per_month": 4800,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 5,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": false,
    "passkey_orchestration_quality": 2,
    "strengths": [
      "Most polished mobile DX in the index, Flutter, iOS, Android SDKs are first-class with comprehensive samples.",
      "Tight integration with the broader Firebase suite (Firestore, Cloud Functions, Crashlytics, Analytics).",
      "Generous free tier (50k MAU) and predictable per-MAU pricing on Blaze plan.",
      "Massive community and Stack Overflow coverage from the broader Firebase ecosystem."
    ],
    "limitations": [
      "B2C-first by design, no first-class B2B Organizations, weak SAML / OIDC support outside Identity Platform upgrade.",
      "Passkey support is only partial, UI-orchestration is bare and adoption rates lag dedicated passkey-first vendors.",
      "Compliance breadth is good but FedRAMP and HIPAA are partial / case-dependent.",
      "Vendor lock-in is real, Firebase Auth tokens map to Firebase services in ways that resist migration."
    ],
    "best_for": [
      "Mobile-first B2C apps already on Firebase / GCP",
      "Cost-sensitive consumer apps at the 10k–500k MAU range",
      "Greenfield projects choosing Google Cloud as the primary platform"
    ],
    "not_for": [
      "B2B SaaS needing first-class Organizations / SCIM / Enterprise SSO",
      "Workloads requiring FedRAMP High or PCI DSS direct attestation",
      "Multi-cloud or AWS / Azure-native architectures"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 4
    },
    "last_verified": "2026-05-06",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Firebase Authentication overview",
        "url": "https://firebase.google.com/products/auth",
        "accessed": "2026-04-22"
      },
      {
        "title": "Firebase pricing",
        "url": "https://firebase.google.com/pricing",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Firebase Authentication is the right CIAM choice for mobile-first B2C apps already running on Firebase / Google Cloud, with generous free tier and predictable per-MAU pricing. The trade-off is a B2C-first product that does not handle B2B Organizations or Enterprise SSO well; the upgrade to Identity Platform fills some gaps but at increased complexity. For Google Cloud-native consumer apps, Firebase Auth is hard to beat; for B2B SaaS or non-GCP architectures, look elsewhere.",
    "faqs": [
      {
        "q": "Is Firebase Auth the same as Google Cloud Identity Platform?",
        "a": "Identity Platform is the upgraded paid version of Firebase Authentication, with additional features like SAML / OIDC SSO, multi-tenancy, and audit logging. Firebase Auth is the entry-level free product; Identity Platform is the enterprise-ready upgrade in Google Cloud's tooling."
      },
      {
        "q": "Does Firebase Auth support passkeys?",
        "a": "Partial as of 2026, protocol-level WebAuthn support is rolling out via Identity Platform, but the orchestration UI is bare. Adoption rates lag dedicated passkey-first vendors like Stytch, Hanko, or Corbado."
      },
      {
        "q": "When should I pick Firebase Auth over Cognito?",
        "a": "When the application is GCP-native and benefits from Firebase suite integration (Firestore, Cloud Functions, Analytics). Cognito is the right pick for AWS-native architectures; Firebase Auth for GCP-native. Outside the hyperscaler-native question, both trail developer-first CIAM on DX."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-06",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(s){const i={a:\"a\",h2:\"h2\",p:\"p\",...s.components};return r(e,{children:[a(i.h2,{id:\"what-firebase-authentication-is\",children:a(i.a,{className:\"heading-anchor\",href:\"#what-firebase-authentication-is\",children:\"What Firebase Authentication is\"})}),\"\\n\",r(i.p,{children:[a(i.a,{href:\"/ciam-compass/vendors/firebase-auth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Firebase Authentication\"}),\" is Google's customer identity product, originally part of Firebase (acquired by Google in 2014) and now also sold as Google Cloud Identity Platform, the paid upgrade with SAML / OIDC SSO, multi-tenancy, and enterprise compliance features. The buyer is typically a mobile-first B2C app already using Firebase services (Firestore, Cloud Functions, Crashlytics, Analytics) where Firebase Auth integrates cleanly.\"]}),\"\\n\",a(i.h2,{id:\"where-firebase-auth-wins\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-firebase-auth-wins\",children:\"Where Firebase Auth wins\"})}),\"\\n\",r(i.p,{children:[\"Polished mobile DX with first-class iOS, Android, and Flutter SDKs and comprehensive samples. Tight integration with Firebase services makes Firebase Auth the path-of-least-resistance for Firebase-native apps. Generous free tier (50k \",a(i.a,{href:\"/ciam-compass/glossary/mau/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MAU\"}),\") and predictable Blaze-plan per-MAU pricing.\"]}),\"\\n\",a(i.h2,{id:\"where-firebase-auth-hurts\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-firebase-auth-hurts\",children:\"Where Firebase Auth hurts\"})}),\"\\n\",r(i.p,{children:[\"B2C-first by design, no B2B Organizations, weak SAML / OIDC outside the Identity Platform upgrade. \",a(i.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Passkey\"}),\" orchestration is bare. Compliance breadth lags Cognito and Entra External ID on FedRAMP and HIPAA. Vendor lock-in via Firebase token semantics is real.\"]}),\"\\n\",a(i.h2,{id:\"how-firebase-auth-compares\",children:a(i.a,{className:\"heading-anchor\",href:\"#how-firebase-auth-compares\",children:\"How Firebase Auth compares\"})}),\"\\n\",r(i.p,{children:[\"The most direct comparisons are \",a(i.a,{href:\"/ciam-compass/compare/cognito-vs-firebase-auth/\",children:\"Cognito vs Firebase Auth\"}),\", \",a(i.a,{href:\"/ciam-compass/compare/auth0-vs-firebase-auth/\",children:\"Auth0 vs Firebase Auth\"}),\", and \",a(i.a,{href:\"/ciam-compass/compare/firebase-auth-vs-supabase-auth/\",children:\"Firebase Auth vs Supabase Auth\"}),\". For non-GCP architectures with similar DX, \",a(i.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" and \",a(i.a,{href:\"/ciam-compass/vendors/clerk/\",children:\"Clerk\"}),\" are the developer-first alternatives.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/firebase-auth/",
    "edit_path": "content/vendors/firebase-auth.mdx"
  },
  {
    "type": "vendor",
    "slug": "forgerock",
    "name": "ForgeRock",
    "legal_name": "ForgeRock Holdings, Inc.",
    "parent_company": "Thoma Bravo (private equity)",
    "acquired_by": "Ping Identity (acquisition closed August 2023)",
    "website": "https://www.forgerock.com",
    "docs_url": "https://backstage.forgerock.com/docs",
    "pricing_url": null,
    "github_url": "https://github.com/ForgeRock",
    "hq": "San Francisco, California, USA",
    "founded": 2010,
    "status": "acquired",
    "funding": {
      "model": "pe-owned",
      "total_raised_usd": 230000000,
      "last_round": {
        "stage": "acquired",
        "amount_usd": null,
        "year": 2023,
        "lead": "Thoma Bravo"
      },
      "investors": [
        "Thoma Bravo",
        "Accel",
        "Meritech Capital",
        "KKR"
      ],
      "profitable": null,
      "notes": "VC-backed (Accel, Meritech, KKR), IPO'd 2021, taken private by Thoma Bravo in 2023 and folded into Ping Identity.",
      "source": "https://www.thomabravo.com/press-releases/thoma-bravo-completes-acquisition-of-forgerock-combines-forgerock-into-ping-identity"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "dotnet",
          "python",
          "go",
          "ios",
          "swift",
          "android",
          "kotlin"
        ],
        "cli": true,
        "terraform_provider": "partial",
        "local_emulator": false,
        "extension_model": "Authentication Trees + custom auth nodes (Java) + scripted nodes"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust",
          "TrustArc"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "All deployments, ForgeRock is enterprise quote-based",
      "notable_costs": [
        "ForgeRock Identity Cloud (managed) and self-managed deployments are commercially separate",
        "Per-user / per-MAU pricing varies by deal; expect six-figure annual minimums for self-managed",
        "Professional services often required for complex deployments",
        "Post-Ping-acquisition product roadmap continues but pricing alignment with PingOne is still in progress"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 8000,
      "tco_at_500k_mau_estimate_usd_per_month": 22000,
      "tco_at_1m_mau_estimate_usd_per_month": 38000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Authentication Trees orchestration, among the most mature visual auth-journey builders for enterprise scenarios.",
      "Strong on-prem deployment story with the deepest customization model (custom Java auth nodes) of any platform in this index.",
      "FedRAMP High, PCI Level 1, HIPAA, with consent and lifecycle capabilities suitable for regulated industries.",
      "Strong identity governance integration (lifecycle, certification, role mining) when paired with ForgeRock IGA."
    ],
    "limitations": [
      "Acquired by Ping Identity in 2023, long-term roadmap and product convergence with PingOne is unsettled.",
      "Pricing opacity and six-figure annual minimums; no path for mid-market evaluation.",
      "Java-heavy customization model creates significant lock-in once production trees are deployed.",
      "DX trails the developer-first tier substantially; iteration loops are slow."
    ],
    "best_for": [
      "Existing ForgeRock customers continuing investment in installed deployments",
      "Large enterprise / public-sector with complex federation and on-prem requirements",
      "Regulated industries needing identity governance integrated with CIAM"
    ],
    "not_for": [
      "New CIAM evaluations below the enterprise-quote threshold",
      "Mid-market SaaS or startups prioritizing developer velocity",
      "Teams uncertain about post-acquisition roadmap stability"
    ],
    "migration_difficulty": {
      "inbound": 5,
      "outbound": 5
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "ForgeRock Documentation",
        "url": "https://backstage.forgerock.com/docs",
        "accessed": "2026-08-19"
      },
      {
        "title": "Ping Identity ForgeRock acquisition close announcement",
        "url": "https://www.pingidentity.com",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "ForgeRock continues as a distinct platform within Ping Identity's portfolio in 2026, with Authentication Trees orchestration, deep on-prem deployment, and Java-heavy customization that suit large enterprise and public-sector buyers with installed deployments. For new CIAM evaluations, the post-acquisition roadmap uncertainty and the complexity of choosing between PingOne and ForgeRock Identity Cloud weigh heavily, most new buyers should evaluate PingOne first, and reach for ForgeRock only when on-prem or governance integration specifically requires it.",
    "faqs": [
      {
        "q": "Is ForgeRock still a separate company from Ping Identity?",
        "a": "No, Ping Identity acquired ForgeRock in August 2023 (both privately held under Thoma Bravo). The ForgeRock platform continues to be sold and developed, but the long-term product strategy involves integration with PingOne. As of 2026 the two platforms remain commercially distinct."
      },
      {
        "q": "Should I pick ForgeRock or PingOne for a new deployment?",
        "a": "For most new deployments, PingOne is the recommended path, fewer migration concerns, broader cloud-native posture, and clearer roadmap alignment with the combined company's investment. ForgeRock makes sense for buyers requiring on-prem deployment, deep Java customization via Authentication Trees, or integration with ForgeRock Identity Governance."
      },
      {
        "q": "What does ForgeRock cost?",
        "a": "Enterprise quote-based with six-figure annual minimums typical. Identity Cloud (managed) is generally less expensive than self-managed deployments at comparable scale. Below those thresholds, ForgeRock is not commercially accessible."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-03-19",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:n,jsxs:t}=arguments[0];function _createMdxContent(o){const i={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return t(e,{children:[n(i.h2,{id:\"what-forgerock-is\",children:n(i.a,{className:\"heading-anchor\",href:\"#what-forgerock-is\",children:\"What ForgeRock is\"})}),\"\\n\",t(i.p,{children:[\"ForgeRock launched in 2010 as a fork of Sun's OpenSSO project, and grew into one of the largest enterprise CIAM platforms before being acquired by \",n(i.a,{href:\"/ciam-compass/vendors/ping-identity/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Ping Identity\"}),\" in August 2023. Both companies were taken private under Thoma Bravo. The ForgeRock platform, Identity Cloud (managed), self-managed Identity Platform, plus the Identity Governance and Autonomous Identity products, continues as a distinct portfolio within the combined company.\"]}),\"\\n\",n(i.h2,{id:\"where-forgerock-wins\",children:n(i.a,{className:\"heading-anchor\",href:\"#where-forgerock-wins\",children:\"Where ForgeRock wins\"})}),\"\\n\",t(i.p,{children:[n(i.a,{href:\"/ciam-compass/glossary/authentication/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authentication\"}),\" Trees is the orchestration differentiator. The visual auth-journey builder predates competitors like DaVinci or Descope's Flows by years, and the customization model, first-class custom Java auth nodes plus scripted nodes, gives engineering teams more expressive control than visual editors that constrain to a node palette. For enterprise auth journeys with custom risk signals, integration with proprietary backends, and complex multi-step KYC, the depth pays off.\"]}),\"\\n\",t(i.p,{children:[\"The on-prem deployment story is among the strongest in the index. \",n(i.a,{href:\"/ciam-compass/vendors/forgerock/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"ForgeRock\"}),\" Identity Platform has been deployed in some of the world's largest installations, banks, governments, telecoms, with the operational maturity that comes from running at that scale across decades. For workloads that require on-prem identity stores with strict data sovereignty, ForgeRock is one of the few platforms that ships this credibly.\"]}),\"\\n\",n(i.p,{children:\"Identity Governance integration is meaningful. When CIAM and IGA come from the same vendor, lifecycle, certification, and role mining flows can share data models without integration tax, uncommon in this index, where most vendors do CIAM only.\"}),\"\\n\",t(i.p,{children:[\"Compliance is full-stack: FedRAMP High, PCI DSS Level 1, HIPAA, ISO 27001/27018, with \",n(i.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\" and preference center capabilities that match regulated-industry expectations.\"]}),\"\\n\",n(i.h2,{id:\"where-forgerock-hurts\",children:n(i.a,{className:\"heading-anchor\",href:\"#where-forgerock-hurts\",children:\"Where ForgeRock hurts\"})}),\"\\n\",n(i.p,{children:\"The post-Ping-acquisition uncertainty is the lasting friction. Two platforms that both ship cloud, on-prem, and orchestration products are now under one company; convergence is announced but the timeline is unclear. For new buyers, the decision between PingOne and ForgeRock Identity Cloud is harder than it was pre-acquisition, and migrations between the two are not yet a smooth path.\"}),\"\\n\",n(i.p,{children:\"Pricing opacity is severe even by enterprise CIAM standards. No published pricing, six-figure annual minimums typical, professional-services-heavy onboarding. For mid-market evaluation this is disqualifying.\"}),\"\\n\",n(i.p,{children:\"The Java-heavy customization model creates significant lock-in once production Authentication Trees are deployed. Trees with custom Java nodes do not port to any other platform without rewriting; even within the Ping portfolio, migrating to DaVinci is a substantial project.\"}),\"\\n\",t(i.p,{children:[\"DX trails the developer-first tier substantially. The admin tooling reflects 2010-era enterprise design choices; SDK coverage is functional but slower-iteration than Auth0 / \",n(i.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" / Clerk.\"]}),\"\\n\",n(i.h2,{id:\"how-forgerock-compares\",children:n(i.a,{className:\"heading-anchor\",href:\"#how-forgerock-compares\",children:\"How ForgeRock compares\"})}),\"\\n\",t(i.p,{children:[\"The most relevant within-portfolio comparison is \",n(i.a,{href:\"/ciam-compass/compare/ping-identity-vs-forgerock/\",children:\"Ping Identity vs ForgeRock\"}),\" for buyers choosing between the two combined-company platforms. For developer-first enterprise CIAM at lower cost, \",n(i.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" is the alternative. For modern orchestration at mid-market price points, \",n(i.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"}),\" covers a similar use case. For self-hosted with similar deployment autonomy, \",n(i.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" is the open-source option.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?n(t,{...e,children:n(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/forgerock/",
    "edit_path": "content/vendors/forgerock.mdx"
  },
  {
    "type": "vendor",
    "slug": "frontegg",
    "name": "Frontegg",
    "legal_name": "Frontegg, Ltd.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://frontegg.com",
    "docs_url": "https://developers.frontegg.com/",
    "pricing_url": "https://frontegg.com/pricing",
    "github_url": "https://github.com/frontegg",
    "hq": "Tel Aviv, Israel",
    "founded": 2019,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 70000000,
      "last_round": {
        "stage": "series-b",
        "amount_usd": 40000000,
        "year": 2022,
        "lead": "Stripes"
      },
      "investors": [
        "Insight Partners",
        "Stripes",
        "Pitango",
        "Global Founders Capital",
        "i3 Equity"
      ],
      "profitable": null,
      "notes": "Tel Aviv B2B user-management platform; $40M Series B in 2022 on top of a $25M Series A.",
      "source": "https://techcrunch.com/2022/07/28/with-40m-in-new-funding-frontegg-looks-to-expand-its-b2b-user-management-service/"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "angular",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks + Hooks (per-event server-side handlers)"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": true,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 7500
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Enterprise SSO and per-tenant features",
      "notable_costs": [
        "Tier-gated features, Adaptive MFA, advanced audit, white-label require higher plans",
        "Per-organization billing component for B2B Enterprise SSO",
        "Self-service Admin Portal included at all paid tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 900,
      "tco_at_500k_mau_estimate_usd_per_month": 3400,
      "tco_at_1m_mau_estimate_usd_per_month": 6500,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Self-service Admin Portal, end-customers' admins manage their own users, SSO, MFA, and audit without engineering involvement; one of the strongest B2B admin UX implementations.",
      "Mature B2B Organizations / multi-tenant model with per-tenant feature flags and entitlements.",
      "Hooks (server-side per-event handlers) extend customization beyond webhooks without proprietary serverless lock-in.",
      "Strong embeddable login + signup components that ship with reasonable defaults out of the box."
    ],
    "limitations": [
      "No native FGA / Zanzibar-style fine-grained authorization, pair with OpenFGA, Authzed, or Permify.",
      "Compliance footprint is solid for B2B SaaS but lacks FedRAMP and direct PCI DSS attestation.",
      "B2C-grade features (progressive profiling, advanced fraud signals) are weaker than Auth0 or Stytch.",
      "Passkey orchestration is improving but not yet at the level of Stytch or Descope."
    ],
    "best_for": [
      "B2B SaaS that wants a polished self-service Admin Portal for end-customer IT teams",
      "Mid-market SaaS evaluating Auth0 alternatives where the Organizations model and per-tenant entitlements matter",
      "Teams that need server-side hooks beyond simple webhooks without buying into proprietary serverless"
    ],
    "not_for": [
      "Pure B2C consumer apps requiring deep progressive profiling and fraud signals",
      "Workloads requiring FedRAMP or PCI DSS direct attestation",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Frontegg Pricing",
        "url": "https://frontegg.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Frontegg Documentation",
        "url": "https://developers.frontegg.com/",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Frontegg is the strongest B2B SaaS CIAM in 2026 by Admin Portal and self-service end-customer experience, the buyer is a SaaS engineering team that needs to ship enterprise-grade IT admin features without building them, and Frontegg delivers more of that out of the box than Auth0 or WorkOS. The trade-off is narrower B2C feature coverage and a smaller ecosystem than Auth0; for B2B-first SaaS the Admin Portal alone often justifies the choice.",
    "faqs": [
      {
        "q": "How is Frontegg different from WorkOS?",
        "a": "WorkOS is API-first and B2B-focused at the protocol level, SSO, SCIM, audit logs as composable APIs. Frontegg ships those plus an embedded Admin Portal that end-customer admins use directly to manage their own users, SSO connections, MFA policies, and audit history. For SaaS apps where the buyer is the IT admin, Frontegg's Admin Portal materially reduces engineering effort vs WorkOS."
      },
      {
        "q": "Does Frontegg have a free tier?",
        "a": "Yes, up to 7,500 MAU on the standard plan. Advanced features (Adaptive MFA, white-label, audit retention beyond standard) require higher plans."
      },
      {
        "q": "Can Frontegg replace Auth0 for B2B SaaS?",
        "a": "For most mid-market B2B SaaS under 500k MAU, yes, Frontegg's Organizations model, Enterprise SSO, MFA, and Admin Portal cover the core feature set. Auth0 retains advantages on B2C consumer flows, FGA, and ecosystem maturity at very large enterprise scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-05-12",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(r){const t={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return n(e,{children:[a(t.h2,{id:\"what-frontegg-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-frontegg-is\",children:\"What Frontegg is\"})}),\"\\n\",n(t.p,{children:[a(t.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),' launched in 2019 in Tel Aviv with a tight thesis: B2B SaaS engineering teams ship the same enterprise-IT-admin features over and over, Organizations, Enterprise SSO, MFA policies, audit logs, role management, and an embedded Admin Portal that end-customer admins use directly is the missing UX layer. The product line is the Admin Portal plus the auth and authz primitives that back it. The buyer is an engineering team that wants to land enterprise contracts without building an \"admin console v3\" in-house.']}),\"\\n\",a(t.h2,{id:\"where-frontegg-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-frontegg-wins\",children:\"Where Frontegg wins\"})}),\"\\n\",n(t.p,{children:[\"The Admin Portal is the differentiator. End-customer IT admins log in directly to their own tenant view, manage users, configure SSO connections, set \",a(t.a,{href:\"/ciam-compass/glossary/mfa/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MFA\"}),\" policies, view audit logs, and download exports, without filing a support ticket with the SaaS team. For a B2B SaaS shipping into enterprise customers, this removes a meaningful slice of engineering work that competitors leave to the application team to build.\"]}),\"\\n\",a(t.p,{children:\"The Organizations model is mature, with per-tenant feature flags and entitlements that extend beyond simple multi-tenancy into the SaaS billing surface. Hooks, server-side per-event handlers, give richer extensibility than pure webhooks without locking customers into proprietary serverless functions.\"}),\"\\n\",a(t.p,{children:\"Embeddable login and signup components ship with reasonable defaults that most B2B SaaS teams can use without significant theming.\"}),\"\\n\",a(t.h2,{id:\"where-frontegg-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-frontegg-hurts\",children:\"Where Frontegg hurts\"})}),\"\\n\",n(t.p,{children:[a(t.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authorization\"}),\" is shallow. There's no native Zanzibar-style FGA, and ABAC is partial. For SaaS apps with fine-grained per-resource permissions, pair with OpenFGA, Authzed, or Permify.\"]}),\"\\n\",n(t.p,{children:[\"Compliance breadth is good for B2B (SOC 2 Type II, ISO 27001, HIPAA, GDPR) but does not yet include FedRAMP or direct PCI DSS \",a(t.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\". For federal or fintech workloads requiring those, look elsewhere.\"]}),\"\\n\",n(t.p,{children:[\"B2C features lag. \",a(t.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Progressive profiling\"}),\", advanced fraud signals, and consumer-grade passkey orchestration are weaker than Auth0, Stytch, or Descope. For a B2C consumer app with B2B Enterprise SSO needs, the cleaner answer is a B2C-strong vendor (Auth0, Stytch, MojoAuth) rather than Frontegg's B2B-first model.\"]}),\"\\n\",n(t.p,{children:[\"The ecosystem is materially smaller than \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\"'s. Stack Overflow coverage is thinner; the partner network is younger.\"]}),\"\\n\",a(t.h2,{id:\"how-frontegg-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-frontegg-compares\",children:\"How Frontegg compares\"})}),\"\\n\",n(t.p,{children:[\"The closest direct comparisons are \",a(t.a,{href:\"/ciam-compass/compare/workos-vs-frontegg/\",children:\"WorkOS vs Frontegg\"}),\" and \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-frontegg/\",children:\"Auth0 vs Frontegg\"}),\". For modern B2B-only with lower price points, \",a(t.a,{href:\"/ciam-compass/vendors/ssojet/\",children:\"SSOJet\"}),\" is the alternative. For broader B2C + B2B coverage, \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" and \",a(t.a,{href:\"/ciam-compass/vendors/mojoauth/\",children:\"MojoAuth\"}),\" cover both segments from a single platform.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/frontegg/",
    "edit_path": "content/vendors/frontegg.mdx"
  },
  {
    "type": "vendor",
    "slug": "fusionauth",
    "name": "FusionAuth",
    "legal_name": "FusionAuth, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://fusionauth.io",
    "docs_url": "https://fusionauth.io/docs",
    "pricing_url": "https://fusionauth.io/pricing",
    "github_url": "https://github.com/FusionAuth",
    "hq": "Denver, Colorado, USA",
    "founded": 2018,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 65000000,
      "last_round": {
        "stage": "growth",
        "amount_usd": 65000000,
        "year": 2023,
        "lead": "Updata Partners"
      },
      "investors": [
        "Updata Partners"
      ],
      "profitable": true,
      "notes": "Bootstrapped and profitable for its first five years; took a single $65M growth round from Updata in late 2023.",
      "source": "https://techcrunch.com/2023/11/01/authentication-startup-fusionauth-raises-65m-its-first-outside-round/"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "self-hosted",
      "cloud-saas",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "ios",
          "swift",
          "android",
          "kotlin",
          "java",
          "python",
          "go",
          "php",
          "ruby",
          "dotnet",
          "dart"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Lambda functions (JavaScript, in-product) + webhooks"
      },
      "security": {
        "bot_detection": "partial",
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": "partial",
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": 0,
      "enterprise_quote_required_above": "Self-hosted Community is free; paid editions add features and support",
      "notable_costs": [
        "Self-hosted Community edition is free, covers most core features",
        "Self-hosted Starter / Essentials / Enterprise tiers add features (advanced threat detection, SLA support, themes)",
        "FusionAuth Cloud (managed) priced per-MAU like a SaaS CIAM",
        "Self-host operating cost (DB, infrastructure, engineering), typically lighter than Keycloak"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 100,
      "tco_at_100k_mau_estimate_usd_per_month": 400,
      "tco_at_500k_mau_estimate_usd_per_month": 1500,
      "tco_at_1m_mau_estimate_usd_per_month": 3000,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 5,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Single-binary self-host that runs on a laptop in 5 minutes, operational profile dramatically lighter than Keycloak.",
      "Genuine free Community edition under custom Open Source-style license, with paid tiers adding features rather than gating core auth.",
      "Excellent docs and developer experience by self-hosted CIAM standards, closer to Auth0 / Stytch DX than Keycloak's.",
      "Both self-hosted and managed (FusionAuth Cloud) options from one product, same code, same APIs."
    ],
    "limitations": [
      "License is Apache-2.0-style for Community but not OSI-certified open source, some procurement teams flag this.",
      "No native FGA / Zanzibar-style fine-grained authorization.",
      "Compliance footprint for the managed Cloud is narrower than enterprise SaaS, no FedRAMP, no ISO 27001.",
      "Smaller community than Keycloak; partner ecosystem is younger."
    ],
    "best_for": [
      "Teams that want self-hosted CIAM with lighter ops than Keycloak",
      "Apps that need to switch between self-hosted and managed without changing vendors",
      "B2B SaaS in regulated industries needing data control without enterprise-CIAM pricing"
    ],
    "not_for": [
      "Workloads requiring FedRAMP or strict ISO 27001 attestations on the managed product",
      "Authorization-heavy use cases requiring Zanzibar-style FGA",
      "Procurement environments that require strictly OSI-certified licenses"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "FusionAuth Pricing",
        "url": "https://fusionauth.io/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "FusionAuth Documentation",
        "url": "https://fusionauth.io/docs",
        "accessed": "2026-08-19"
      },
      {
        "title": "FusionAuth License",
        "url": "https://fusionauth.io/license",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "FusionAuth is the right answer when you want self-hosted CIAM without taking on Keycloak's operational weight, and want the option to switch to managed without changing vendors. Single-binary deploy, modern docs, and a genuinely usable Community tier make it the practical default for self-host evaluations in 2026, particularly for B2C and mid-market B2B SaaS that don't need FedRAMP or Zanzibar-style FGA.",
    "faqs": [
      {
        "q": "Is FusionAuth open source?",
        "a": "FusionAuth Community edition is freely available under a custom Apache-2.0-style license with some commercial-use clauses, but it is not OSI-certified. For most teams this is functionally equivalent to OSS; for procurement requiring strict OSI compliance, Keycloak or Ory are alternatives."
      },
      {
        "q": "How does FusionAuth compare to Keycloak?",
        "a": "FusionAuth is materially lighter operationally, single binary instead of a Java/JBoss-style stack, modern docs, faster onboarding. Keycloak has a larger community, broader theme/SPI ecosystem, and stricter open-source licensing. For teams choosing self-hosted CIAM in 2026, FusionAuth is the lighter-ops answer; Keycloak is the larger-ecosystem answer."
      },
      {
        "q": "Can I run FusionAuth self-hosted and switch to Cloud later?",
        "a": "Yes, same product, same APIs, same admin UI. User export / import is straightforward. This is unique among the vendors in this index; everyone else forces a one-way commitment to self-hosted or managed."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-04-23",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(o){const s={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return n(e,{children:[a(s.h2,{id:\"what-fusionauth-is\",children:a(s.a,{className:\"heading-anchor\",href:\"#what-fusionauth-is\",children:\"What FusionAuth is\"})}),\"\\n\",n(s.p,{children:[a(s.a,{href:\"/ciam-compass/vendors/fusionauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"FusionAuth\"}),\" launched in 2018 with a focused product: ship a CIAM platform that self-hosts in five minutes from a single binary, with a genuinely free Community tier and the option to upgrade to managed Cloud or paid self-hosted editions. The product is mature: full OAuth 2.0 / OIDC / SAML, MFA, passkeys, B2B Tenants, advanced theming, webhook delivery, and Lambda functions written in JavaScript that run inside the auth server. The buyer is typically a team that has weighed Keycloak's operational tax against SaaS CIAM costs and wants a third option.\"]}),\"\\n\",a(s.h2,{id:\"where-fusionauth-wins\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-fusionauth-wins\",children:\"Where FusionAuth wins\"})}),\"\\n\",n(s.p,{children:[\"The single-binary deploy is the headline. A team with no prior auth-infrastructure experience can have FusionAuth running locally with Docker Compose in under ten minutes, which is closer to a SaaS onboarding experience than to \",a(s.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\"'s. Production deployments need the standard stateful-service operational discipline (HA, backups, schema migrations) but the operational profile is materially lighter.\"]}),\"\\n\",n(s.p,{children:[\"The Community tier is genuinely usable, not a feature-gated trial. Core auth, MFA, passkeys, OAuth/\",a(s.a,{href:\"/ciam-compass/glossary/oidc/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"OIDC\"}),\", basic tenants, and most admin features are available without paying. Paid tiers add advanced features (threat detection, advanced theming, SLA support) rather than withholding the core.\"]}),\"\\n\",a(s.p,{children:\"The same product runs as self-hosted and as managed FusionAuth Cloud. APIs are identical; user export / import works between deployments. This is unique in the index, everyone else forces a one-way bet on self-hosted or managed.\"}),\"\\n\",a(s.p,{children:\"DX is well above the open-source-CIAM median. Docs are modern and well-organized; SDK coverage spans the major languages; the admin console is functional and reasonably current.\"}),\"\\n\",a(s.h2,{id:\"where-fusionauth-hurts\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-fusionauth-hurts\",children:\"Where FusionAuth hurts\"})}),\"\\n\",n(s.p,{children:[\"The license is the lasting friction. The Community edition uses a custom Apache-2.0-style license with some commercial-use clauses, close enough to OSS for most teams but not OSI-certified. Procurement teams that require strict open-source compliance (notably some public-sector buyers) flag this; for those buyers, Keycloak or \",a(s.a,{href:\"/ciam-compass/vendors/ory/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Ory\"}),\" are cleaner.\"]}),\"\\n\",n(s.p,{children:[\"There's no native Zanzibar-style FGA. \",a(s.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authorization\"}),\" stays at RBAC plus rule-based ABAC; for fine-grained per-resource permissions at scale, pair with OpenFGA / Authzed / Permify.\"]}),\"\\n\",n(s.p,{children:[\"Compliance for the managed Cloud is narrower than enterprise SaaS, SOC 2 Type II yes, ISO 27001 no, FedRAMP no. For federal workloads or strict enterprise audit checklists, FusionAuth Cloud falls short of \",a(s.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\", Cognito, or Entra External ID.\"]}),\"\\n\",a(s.p,{children:\"The community is large but smaller than Keycloak's. Stack Overflow coverage is good but thinner than Keycloak's at production-edge cases.\"}),\"\\n\",a(s.h2,{id:\"how-fusionauth-compares\",children:a(s.a,{className:\"heading-anchor\",href:\"#how-fusionauth-compares\",children:\"How FusionAuth compares\"})}),\"\\n\",n(s.p,{children:[\"The closest comparisons are \",a(s.a,{href:\"/ciam-compass/compare/keycloak-vs-fusionauth/\",children:\"Keycloak vs FusionAuth\"}),\" for the self-host call and \",a(s.a,{href:\"/ciam-compass/compare/auth0-vs-fusionauth/\",children:\"Auth0 vs FusionAuth\"}),\" for the SaaS-vs-self-host call. For modern OSS architecture, \",a(s.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory\"}),\" and \",a(s.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" are alternatives. For lighter B2C-only OSS, \",a(s.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" and \",a(s.a,{href:\"/ciam-compass/vendors/supertokens/\",children:\"SuperTokens\"}),\" are the modern picks.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/fusionauth/",
    "edit_path": "content/vendors/fusionauth.mdx"
  },
  {
    "type": "vendor",
    "slug": "hanko",
    "name": "Hanko",
    "legal_name": "Hanko GmbH",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.hanko.io",
    "docs_url": "https://docs.hanko.io",
    "pricing_url": "https://www.hanko.io/pricing",
    "github_url": "https://github.com/teamhanko",
    "hq": "Kiel, Germany",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 1500000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 1300000,
        "year": 2023,
        "lead": "adesso ventures"
      },
      "investors": [
        "High-Tech Gründerfonds",
        "adesso ventures",
        "Smart Infrastructure Ventures"
      ],
      "profitable": null,
      "notes": "German open-source passkey APIs; seed from HTGF (2020) and a €1.2M round led by adesso ventures (2023).",
      "source": "https://siliconcanals.com/berlin-adesso-ventures-invests-hanko/"
    },
    "categories": [
      "passwordless-specialist",
      "open-source-ciam",
      "developer-first-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": "partial",
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": false
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "svelte",
          "go"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Webhooks + custom UI elements (web components)"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": "partial",
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Self-hosted Pro and Enterprise licenses",
      "notable_costs": [
        "Hanko Cloud is per-MAU; self-hosted Community edition is AGPL-licensed and free",
        "Self-hosted Pro / Enterprise licenses available for commercial-use compliance",
        "Pre-built UI web components (Hanko Elements) included at all tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 700,
      "tco_at_500k_mau_estimate_usd_per_month": 2400,
      "tco_at_1m_mau_estimate_usd_per_month": 4500,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Best-in-class passkey orchestration among open-source CIAM, conditional UI, device-aware prompting, fallback design, with AGPL self-hostability.",
      "Hanko Elements (web components) ship a pre-built passkey-first login UI that drops into any framework without theming work.",
      "Strong DX with idiomatic SDKs across JS frameworks (React, Next, Vue, Svelte) plus Go for backend.",
      "EU-headquartered with EU data residency and GDPR-first product design."
    ],
    "limitations": [
      "Authorization is rudimentary, RBAC is partial, no FGA, no ABAC. Pair with OpenFGA / Authzed if needed.",
      "Compliance footprint is narrow, SOC 2 in progress, ISO 27001 not yet, no HIPAA / FedRAMP / PCI DSS.",
      "B2B Organizations and Enterprise SAML are partial; Hanko is B2C-passkey-first, not a full B2B platform.",
      "Smaller community and ecosystem than Auth0 / Stytch / Clerk."
    ],
    "best_for": [
      "B2C consumer apps prioritizing high passkey adoption with self-host option",
      "EU-based products needing GDPR-first design and EU data residency",
      "Teams that want a passkey-first product with both managed and self-hosted options"
    ],
    "not_for": [
      "B2B SaaS requiring deep Enterprise SSO and Organizations",
      "Workloads requiring HIPAA, PCI DSS, ISO 27001, or FedRAMP",
      "Authorization-heavy use cases requiring FGA or ABAC at scale"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-03-26",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Hanko Pricing",
        "url": "https://www.hanko.io/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Hanko Documentation",
        "url": "https://docs.hanko.io",
        "accessed": "2026-04-22"
      },
      {
        "title": "Hanko GitHub",
        "url": "https://github.com/teamhanko",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Hanko is the open-source passkey-first CIAM in 2026. Orchestration quality sits with Stytch and MojoAuth, not with Descope. Descope is a journey builder. Hanko is a passkey product with AGPL self-host and EU residency by default. Use it when adoption is the goal and B2B Enterprise SSO is not. For B2B SaaS or FedRAMP-shaped workloads, the narrow scope shows.",
    "faqs": [
      {
        "q": "How does Hanko's passkey support compare to Stytch?",
        "a": "Both ship best-in-class passkey orchestration. Hanko's Elements (pre-built web components) make the rollout faster for teams using major JS frameworks; Stytch's flow-level orchestration covers more enrollment edge cases. Adoption rates among customers of both are at the top of the market, 30–50%+ within six months when properly deployed."
      },
      {
        "q": "What does AGPL mean for self-hosted Hanko?",
        "a": "AGPL requires that any modifications to Hanko itself be released under AGPL if you offer Hanko as a network service. For most teams running Hanko as part of their own application, this is a non-issue. Hanko also offers commercial Pro / Enterprise self-hosted licenses for organizations whose legal team prefers traditional commercial terms."
      },
      {
        "q": "Can Hanko handle B2B SaaS authentication?",
        "a": "Partially, basic multi-tenancy and OIDC SSO work, but Organizations / Enterprise SAML / SCIM are not at the maturity of WorkOS, Frontegg, or Auth0 B2B. For B2B-first SaaS, look elsewhere; for B2C with light B2B needs, Hanko is workable."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-26",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:a,jsx:e,jsxs:n}=arguments[0];function _createMdxContent(o){const t={a:\"a\",code:\"code\",h2:\"h2\",p:\"p\",...o.components};return n(a,{children:[e(t.h2,{id:\"what-hanko-is\",children:e(t.a,{className:\"heading-anchor\",href:\"#what-hanko-is\",children:\"What Hanko is\"})}),\"\\n\",n(t.p,{children:[\"Hanko launched in 2020 in Kiel, Germany, with a tightly-scoped thesis: most CIAM vendors shipped WebAuthn support but few shipped the orchestration layer that turns it into adoption. The Hanko product is built passkey-first from the ground up, Elements (pre-built web components for React / Next / Vue / Svelte) drop a passkey-first login UI into any app, and the backend handles the \",e(t.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\", device-aware prompting, and fallback flow design that teams would otherwise need to build themselves.\"]}),\"\\n\",e(t.h2,{id:\"where-hanko-wins\",children:e(t.a,{className:\"heading-anchor\",href:\"#where-hanko-wins\",children:\"Where Hanko wins\"})}),\"\\n\",n(t.p,{children:[\"The passkey orchestration is specialist-tier, at parity with Stytch and \",e(t.a,{href:\"/ciam-compass/vendors/mojoauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"MojoAuth\"}),\" on enrollment quality, not with Descope. Descope is an identity orchestration platform. Passkeys are a Flow method there, not the product. Hanko ships passkey-first defaults. Customer adoption on those defaults lands well above the 5 to 10% stall on protocol-only CIAMs. Among open-source CIAM, Hanko is unique in shipping this quality with a self-host option.\"]}),\"\\n\",n(t.p,{children:[e(t.a,{href:\"/ciam-compass/vendors/hanko/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Hanko\"}),\" Elements (web components) is the underrated product. A team can replace a custom login form with \",e(t.code,{children:\"<hanko-auth>\"}),\" and have a \",e(t.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-first registration and login flow without theming, branding work, or framework-specific glue code. For teams that want passkeys without building the UI, this is the fastest path in the index.\"]}),\"\\n\",e(t.p,{children:\"EU-headquartered with EU data residency by default. For European products with GDPR sensitivity or wariness of US data jurisdiction, this is a meaningful trust signal. Self-hosting via AGPL Community edition gives teams full data sovereignty.\"}),\"\\n\",e(t.p,{children:\"DX is high for the OSS CIAM tier, modern docs, idiomatic SDKs, fast onboarding.\"}),\"\\n\",e(t.h2,{id:\"where-hanko-hurts\",children:e(t.a,{className:\"heading-anchor\",href:\"#where-hanko-hurts\",children:\"Where Hanko hurts\"})}),\"\\n\",n(t.p,{children:[e(t.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authorization\"}),' is rudimentary. RBAC is partial, no ABAC, no FGA. For applications that need anything beyond \"is this user authenticated and what role do they have,\" pair with OpenFGA, Authzed, or Permify.']}),\"\\n\",e(t.p,{children:\"Compliance is the narrowest in the index. SOC 2 Type II is in progress as of late 2025; ISO 27001, HIPAA, PCI DSS, and FedRAMP are not yet attested. For consumer apps in regulated industries or B2B SaaS shipping into compliance-conscious enterprise, this is disqualifying.\"}),\"\\n\",n(t.p,{children:[\"The B2B story is partial. Multi-tenancy and OIDC SSO work, but Organizations / Enterprise SAML / SCIM Directory Sync are not at the maturity of WorkOS, \",e(t.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\", or Auth0 B2B. Hanko is a B2C-passkey-first product; B2B SaaS should pick a B2B-first vendor instead.\"]}),\"\\n\",n(t.p,{children:[\"The community and ecosystem are smaller than \",e(t.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" or Clerk's. Stack Overflow coverage is thin; partner integrations are limited.\"]}),\"\\n\",e(t.h2,{id:\"how-hanko-compares\",children:e(t.a,{className:\"heading-anchor\",href:\"#how-hanko-compares\",children:\"How Hanko compares\"})}),\"\\n\",n(t.p,{children:[\"The most direct comparisons are \",e(t.a,{href:\"/ciam-compass/compare/stytch-vs-hanko/\",children:\"Stytch vs Hanko\"}),\" for the passkey-first call and \",e(t.a,{href:\"/ciam-compass/compare/hanko-vs-corbado/\",children:\"Hanko vs Corbado\"}),\" for the OSS-passkey-specialist call. For broader OSS CIAM, \",e(t.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\", \",e(t.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\", and \",e(t.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory\"}),\" are the alternatives. For passkey orchestration as a layer in front of any underlying CIAM, \",e(t.a,{href:\"/ciam-compass/vendors/authsignal/\",children:\"Authsignal\"}),\" and \",e(t.a,{href:\"/ciam-compass/vendors/corbado/\",children:\"Corbado\"}),\" are the specialist picks.\"]})]})}return{default:function(a={}){const{wrapper:n}=a.components||{};return n?e(n,{...a,children:e(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/hanko/",
    "edit_path": "content/vendors/hanko.mdx"
  },
  {
    "type": "vendor",
    "slug": "ibm-security-verify",
    "name": "IBM Verify",
    "legal_name": "IBM Verify (IBM Corporation; formerly IBM Security Verify, rebranded 2025)",
    "parent_company": "IBM Corporation",
    "acquired_by": null,
    "website": "https://www.ibm.com/products/verify-identity",
    "docs_url": "https://www.ibm.com/docs/en/security-verify",
    "pricing_url": null,
    "github_url": "https://github.com/IBM-Security",
    "hq": "Armonk, New York, USA",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Part of IBM Security (NYSE: IBM); funded internally.",
      "source": "https://www.ibm.com/products/verify-identity"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "python",
          "dotnet",
          "go"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Identity Adapters + custom JavaScript flows"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": true
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based; six-figure annual minimums typical",
      "notable_costs": [
        "IBM enterprise sales engagement; quote-based pricing",
        "Verify SaaS, Verify Access (on-prem), and IBM Identity Governance are commercially related products",
        "Strong fit for existing IBM Cloud or IBM Power infrastructure shops"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 7000,
      "tco_at_500k_mau_estimate_usd_per_month": 22000,
      "tco_at_1m_mau_estimate_usd_per_month": 38000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Full IBM enterprise support, FedRAMP High, and integration with broader IBM Security portfolio (QRadar, Guardium, Cloud Pak for Security).",
      "Mature on-prem deployment via Verify Access, uncommon depth for legacy enterprise federation.",
      "Strong consent management and identity governance integration with IBM Identity Governance.",
      "Post-quantum cryptography roadmap is more advanced than most CIAM vendors."
    ],
    "limitations": [
      "Enterprise-only commercial structure; no public pricing or self-service evaluation.",
      "DX trails developer-first tier substantially; admin tooling reflects classic IBM enterprise design.",
      "Outside existing IBM ecosystem, the integration story is weaker.",
      "Sprawling product naming (Verify SaaS, Verify Access, Verify Governance, Verify Trust) creates evaluation complexity."
    ],
    "best_for": [
      "Existing IBM enterprise shops with Cloud Pak for Security or QRadar deployments",
      "Public-sector and regulated workloads requiring FedRAMP High and post-quantum cryptography readiness",
      "Enterprises needing CIAM plus Identity Governance from one vendor"
    ],
    "not_for": [
      "Mid-market SaaS or startups",
      "Greenfield projects without IBM ecosystem context",
      "Teams prioritizing developer velocity over enterprise depth"
    ],
    "migration_difficulty": {
      "inbound": 5,
      "outbound": 5
    },
    "last_verified": "2026-05-08",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "IBM Security Verify product page",
        "url": "https://www.ibm.com/products/verify-identity",
        "accessed": "2026-04-22"
      },
      {
        "title": "IBM Security Verify documentation",
        "url": "https://www.ibm.com/docs/en/security-verify",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "IBM Security Verify is the right CIAM choice for existing IBM enterprise shops with Cloud Pak for Security or QRadar deployments, where integration with the broader IBM Security portfolio justifies the platform on its own. FedRAMP High plus advanced post-quantum cryptography roadmap suit federal and high-assurance scenarios. Outside the IBM ecosystem, the DX gap and enterprise-only commercial structure make it the wrong answer for greenfield projects or mid-market evaluation.",
    "faqs": [
      {
        "q": "What is the difference between Verify SaaS and Verify Access?",
        "a": "Verify SaaS is the cloud-hosted CIAM. Verify Access is the on-prem product (formerly IBM Security Access Manager / ISAM), a Java-based access management platform. Both are sold under the broader Security Verify umbrella but serve different deployment scenarios."
      },
      {
        "q": "Does IBM Security Verify work outside IBM ecosystems?",
        "a": "Yes, protocols are standard (SAML / OIDC / OAuth 2.0), and the SaaS product runs on IBM Cloud. But the integration story is materially stronger for existing IBM customers with Cloud Pak for Security, QRadar SIEM, and IBM Identity Governance. Without that context, alternatives are usually a better fit."
      },
      {
        "q": "What does IBM Security Verify cost?",
        "a": "Enterprise quote-based with six-figure annual minimums typical. For mid-market evaluation, the entry threshold is disqualifying. Engage IBM enterprise sales for actual pricing."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-08",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      },
      {
        "date": "2026-05-08",
        "summary": "Renamed from 'IBM Security Verify' to 'IBM Verify' to reflect IBM's 2025 portfolio rebrand. The product family is unified under the 'IBM Verify' name; legacy 'Security' branding remains only in adjacent products (e.g., IBM Security Verify Governance)."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:i}=arguments[0];function _createMdxContent(t){const a={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return i(e,{children:[r(a.h2,{id:\"what-ibm-security-verify-is\",children:r(a.a,{className:\"heading-anchor\",href:\"#what-ibm-security-verify-is\",children:\"What IBM Security Verify is\"})}),\"\\n\",r(a.p,{children:\"IBM Security Verify is IBM's CIAM platform, consolidating earlier products (IBM Security Access Manager, IBM Cloud Identity) into a unified portfolio in 2020. The product family covers Verify SaaS (cloud), Verify Access (on-prem), Verify Trust (risk decisioning), and Verify Governance (IGA). The buyer is typically an existing IBM enterprise shop where integration with the broader IBM Security portfolio (Cloud Pak for Security, QRadar SIEM, Guardium) justifies the platform.\"}),\"\\n\",r(a.h2,{id:\"where-ibm-security-verify-wins\",children:r(a.a,{className:\"heading-anchor\",href:\"#where-ibm-security-verify-wins\",children:\"Where IBM Security Verify wins\"})}),\"\\n\",i(a.p,{children:[\"Full IBM enterprise support and integration with the broader IBM Security ecosystem. FedRAMP High \",r(a.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\". Mature on-prem deployment via Verify Access provides legacy enterprise federation depth. Post-quantum cryptography roadmap is more advanced than most CIAM vendors. Identity Governance integration via Verify Governance provides authn-plus-IGA from one vendor.\"]}),\"\\n\",r(a.h2,{id:\"where-ibm-security-verify-hurts\",children:r(a.a,{className:\"heading-anchor\",href:\"#where-ibm-security-verify-hurts\",children:\"Where IBM Security Verify hurts\"})}),\"\\n\",r(a.p,{children:\"Enterprise-only commercial structure with opaque pricing and six-figure annual minimums. DX trails developer-first tier substantially. Outside existing IBM ecosystem, the integration story is materially weaker. Sprawling product naming creates evaluation complexity.\"}),\"\\n\",r(a.h2,{id:\"how-ibm-security-verify-compares\",children:r(a.a,{className:\"heading-anchor\",href:\"#how-ibm-security-verify-compares\",children:\"How IBM Security Verify compares\"})}),\"\\n\",i(a.p,{children:[\"The closest comparisons are \",r(a.a,{href:\"/ciam-compass/compare/ping-identity-vs-ibm-security-verify/\",children:\"Ping Identity vs IBM Security Verify\"}),\" and \",r(a.a,{href:\"/ciam-compass/compare/forgerock-vs-ibm-security-verify/\",children:\"ForgeRock vs IBM Security Verify\"}),\" for the legacy enterprise tier. For developer-first enterprise CIAM at lower cost, \",r(a.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" is the alternative; for self-hosted with similar deployment autonomy, \",r(a.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",r(a.a,{href:\"/ciam-compass/vendors/wso2-is/\",children:\"WSO2 IS\"}),\" are the OSS options.\"]})]})}return{default:function(e={}){const{wrapper:i}=e.components||{};return i?r(i,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/ibm-security-verify/",
    "edit_path": "content/vendors/ibm-security-verify.mdx"
  },
  {
    "type": "vendor",
    "slug": "keycloak",
    "name": "Keycloak",
    "legal_name": "Keycloak (Red Hat / CNCF Sandbox)",
    "parent_company": "Red Hat (IBM)",
    "acquired_by": null,
    "website": "https://www.keycloak.org",
    "docs_url": "https://www.keycloak.org/documentation",
    "pricing_url": null,
    "github_url": "https://github.com/keycloak/keycloak",
    "hq": null,
    "founded": 2014,
    "status": "open-source",
    "funding": {
      "model": "foundation-oss",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "CNCF incubating project sponsored by Red Hat (IBM); commercialised as Red Hat build of Keycloak, not separately funded.",
      "source": "https://www.cncf.io/projects/keycloak/"
    },
    "categories": [
      "open-source-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "self-hosted",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": "partial",
        "sms_otp": "partial",
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": "partial",
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "java",
          "js",
          "node",
          "python",
          "go",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "SPI extensions (Java) + custom themes"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": "partial",
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": false,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": "partial",
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Red Hat build of Keycloak (commercial support) is quote-based",
      "notable_costs": [
        "Self-hosted infrastructure cost (cluster nodes, database, observability)",
        "Engineering operating cost, typically 0.5–1.0 FTE-equivalent at production scale",
        "Optional Red Hat support contract for SLA-backed assistance"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 250,
      "tco_at_100k_mau_estimate_usd_per_month": 800,
      "tco_at_500k_mau_estimate_usd_per_month": 2500,
      "tco_at_1m_mau_estimate_usd_per_month": 5000,
      "pricing_transparency_score": 5
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 2,
    "strengths": [
      "Most widely deployed open-source CIAM globally, enormous community, Stack Overflow coverage, third-party themes and extensions.",
      "Fully self-hostable with no vendor lock-in; data residency and sovereignty are unconstrained.",
      "Mature SAML / OIDC / OAuth 2.0 support, including the kind of legacy IdP bridges enterprise federation needs.",
      "Free at any MAU, meaningful for high-MAU consumer apps that would otherwise pay $10k+/mo to a SaaS CIAM."
    ],
    "limitations": [
      "Operating cost is real, production deployments typically need 0.5–1.0 FTE for upgrades, security patching, and incident response.",
      "DX is dated compared to Auth0 / Stytch / Clerk, the admin console is functional but not modern, SDKs prioritize Java.",
      "No native FGA, no first-class compliance attestations (SOC 2, ISO, HIPAA must be earned by the operator), no MCP support.",
      "Passkey support exists but UI orchestration is bare; expect <10% adoption without significant theming work."
    ],
    "best_for": [
      "Public sector and regulated workloads requiring on-prem / sovereign deployment",
      "High-MAU consumer apps where SaaS pricing is the binding constraint",
      "Enterprises with existing Java / Red Hat operational footprint"
    ],
    "not_for": [
      "Teams without operational capacity to run a stateful service in production",
      "Apps that need first-class passkey orchestration without theming work",
      "Mid-market SaaS that values developer velocity over data sovereignty"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 2
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Keycloak Documentation",
        "url": "https://www.keycloak.org/documentation",
        "accessed": "2026-08-19"
      },
      {
        "title": "Keycloak GitHub repository",
        "url": "https://github.com/keycloak/keycloak",
        "accessed": "2026-08-19"
      },
      {
        "title": "Red Hat build of Keycloak",
        "url": "https://access.redhat.com/products/red-hat-build-of-keycloak",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Keycloak is the de-facto open-source CIAM in 2026 and remains the right choice when data sovereignty, on-prem deployment, or zero per-MAU cost are non-negotiable. The trade-off is operational cost, running Keycloak well is closer to running PostgreSQL than running an SDK, and teams without that capacity should reach for FusionAuth (lighter ops) or a SaaS instead.",
    "faqs": [
      {
        "q": "Is Keycloak free?",
        "a": "Yes. Keycloak is open-source under the Apache 2.0 license, sponsored by Red Hat (IBM), and free to deploy at any scale. Operating costs (infrastructure, engineering time, optional support contract) are real and should be modeled, see the build-vs-buy guide."
      },
      {
        "q": "How much does Keycloak cost to operate at 1M MAU?",
        "a": "A typical 1M MAU production deployment costs $3,000–$8,000 per month in infrastructure and amortized engineering time, depending on HA topology, regional footprint, and support tier. Compare to $9,500+/mo on Auth0 at the same scale, Keycloak wins the unit economics, loses on engineering velocity."
      },
      {
        "q": "Does Keycloak support passkeys?",
        "a": "Yes, since version 19+. The default UI is functional but not orchestrated, expect <10% adoption without theming and prompting work. Teams pursuing serious passkey rollouts on Keycloak typically pair it with Authsignal or Corbado as an orchestration layer, or migrate to a passkey-native vendor."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-04-10",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:o}=arguments[0];function _createMdxContent(n){const t={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return o(e,{children:[a(t.h2,{id:\"what-keycloak-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-keycloak-is\",children:\"What Keycloak is\"})}),\"\\n\",o(t.p,{children:[\"Keycloak is the dominant open-source CIAM platform, Apache 2.0 licensed, originally developed at Red Hat, now stewarded as a CNCF Sandbox project with active contribution from IBM, government agencies, and a broad enterprise community. It runs as a stateful Java service backed by a database (PostgreSQL is the standard), and is most often deployed on Kubernetes for HA. The product is mature: SAML, OIDC, OAuth 2.0, identity brokering, \",a(t.a,{href:\"/ciam-compass/glossary/social-login/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"social login\"}),\", MFA, theming, and a full admin REST API.\"]}),\"\\n\",a(t.h2,{id:\"where-keycloak-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-keycloak-wins\",children:\"Where Keycloak wins\"})}),\"\\n\",o(t.p,{children:[\"Data sovereignty is the unbeatable proposition. For public-sector workloads, regulated industries, and any deployment where the customer dataset cannot leave their infrastructure, \",a(t.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\" is the only credible option among the platforms in this index that doesn't require self-building.\"]}),\"\\n\",o(t.p,{children:[\"The unit economics matter at scale. A 1M MAU SaaS CIAM bill of $9,500+/month on \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" becomes $3,000–$8,000/month of infrastructure plus engineering on Keycloak, with the ability to choose hardware, region, and operational topology unconstrained.\"]}),\"\\n\",o(t.p,{children:[\"The community is the largest in CIAM. Stack Overflow has near-complete coverage of operational issues; the GitHub repo accepts community PRs; theme and SPI extensions exist for nearly every legacy \",a(t.a,{href:\"/ciam-compass/glossary/idp/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"IdP\"}),\" integration.\"]}),\"\\n\",a(t.h2,{id:\"where-keycloak-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-keycloak-hurts\",children:\"Where Keycloak hurts\"})}),\"\\n\",a(t.p,{children:\"Operating Keycloak well is engineering work. A typical production deployment needs 0.5–1.0 FTE-equivalent for upgrades, schema migrations, security patching, observability, and incident response. Teams without that capacity end up running Keycloak badly, which means downtime and stale security patches.\"}),\"\\n\",o(t.p,{children:[\"The DX gap relative to Auth0 / Clerk / \",a(t.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" is real. The admin console is dated, the SDK ecosystem prioritizes Java, and theming the user-facing pages takes design effort. For developer velocity, this is a meaningful tax.\"]}),\"\\n\",a(t.p,{children:\"Compliance attestations (SOC 2, ISO, HIPAA, FedRAMP) are earned by the operator, not provided by the platform. For a SaaS CIAM, the vendor's SOC 2 report flows through to your auditors; for self-hosted Keycloak, you produce your own attestations.\"}),\"\\n\",o(t.p,{children:[\"Passkey support exists but orchestration is bare. Expect single-digit adoption without theming work or an external orchestration layer (\",a(t.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\", Corbado).\"]}),\"\\n\",a(t.h2,{id:\"how-keycloak-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-keycloak-compares\",children:\"How Keycloak compares\"})}),\"\\n\",o(t.p,{children:[\"The closest open-source alternative with a lighter operational profile is \",a(t.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\" (commercial-supported OSS, single binary). For modern OSS architecture, \",a(t.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory Kratos / Hydra / Keto\"}),\" and \",a(t.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" are credible. For SaaS migrations, the most common comparison is \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-keycloak/\",children:\"Auth0 vs Keycloak\"}),\".\"]})]})}return{default:function(e={}){const{wrapper:o}=e.components||{};return o?a(o,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/keycloak/",
    "edit_path": "content/vendors/keycloak.mdx"
  },
  {
    "type": "vendor",
    "slug": "kinde",
    "name": "Kinde",
    "legal_name": "Kinde Pty Ltd",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://kinde.com",
    "docs_url": "https://kinde.com/docs",
    "pricing_url": "https://kinde.com/pricing",
    "github_url": "https://github.com/kinde-oss",
    "hq": "Melbourne, Australia",
    "founded": 2022,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 7000000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 7000000,
        "year": 2022,
        "lead": "Blackbird Ventures"
      },
      "investors": [
        "Blackbird Ventures",
        "Felicis Ventures"
      ],
      "profitable": null,
      "notes": "Sydney dev-first auth/billing platform; A$10.6M (~$7M) seed led by Blackbird with Felicis.",
      "source": "https://kinde.com/blog/news/announcing-our-10-million-seed-round-led-by-blackbird/"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "angular",
          "python",
          "go",
          "php",
          "ruby",
          "java"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + custom claims"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10500
      },
      "paid_starts_at_usd": 25,
      "enterprise_quote_required_above": "Enterprise SSO and audit retention",
      "notable_costs": [
        "Free up to 10,500 MAU; paid Plus tier starts at $25/month",
        "Per-organization billing component for B2B with Enterprise SSO",
        "Feature parity at lower tiers than Auth0 (B2B Organizations included at low cost)"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 480,
      "tco_at_500k_mau_estimate_usd_per_month": 1900,
      "tco_at_1m_mau_estimate_usd_per_month": 3600,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Modern DX with idiomatic SDKs and a default UI that feels like the developer-first tier (Clerk, Stytch) at lower cost.",
      "Transparent pricing with B2B Organizations included from low tiers, uncommon among developer-first competitors.",
      "Built feature-flags and entitlements into the Organizations model, useful for SaaS billing scenarios.",
      "Open-source SDKs across major languages with active GitHub presence."
    ],
    "limitations": [
      "Smaller than Auth0 / Clerk on community, ecosystem, and battle-test coverage.",
      "Compliance footprint is narrow, SOC 2 Type II only, no ISO 27001 / HIPAA / FedRAMP / PCI DSS.",
      "No native FGA, no adaptive MFA, no native bot detection.",
      "Australian-headquartered with limited regional infrastructure compared to global incumbents."
    ],
    "best_for": [
      "B2B SaaS startups under 100k MAU prioritizing time-to-launch with modern DX",
      "Teams that want B2B Organizations + feature flags from a single platform",
      "Cost-sensitive teams comparing Clerk and Auth0 alternatives"
    ],
    "not_for": [
      "Workloads requiring HIPAA, FedRAMP, or PCI DSS",
      "B2C apps with serious adaptive risk and bot defense needs",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-03-27",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Kinde Pricing",
        "url": "https://kinde.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Kinde Documentation",
        "url": "https://kinde.com/docs",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Kinde is a credible Clerk alternative for B2B SaaS startups in 2026, modern DX, transparent pricing, and B2B Organizations included from low tiers. The trade-offs are a smaller ecosystem and narrower compliance footprint than developer-first incumbents. For teams under 100k MAU prioritizing fast launch over breadth, Kinde shortlists alongside Clerk and Stytch.",
    "faqs": [
      {
        "q": "How does Kinde compare to Clerk?",
        "a": "Both target the same developer-first tier. Clerk is more polished on Next.js / React DX and has a larger customer base; Kinde includes B2B Organizations and feature flags at lower tiers. For Next.js-heavy teams, Clerk usually wins on velocity; for SaaS-billing-aware teams, Kinde's entitlement model is the differentiator."
      },
      {
        "q": "Does Kinde support Enterprise SSO?",
        "a": "Yes, via SAML / OIDC connections per organization. Setup is per-org and works with the major IdPs; the long tail of legacy SAML edge cases is less covered than Auth0 or WorkOS."
      },
      {
        "q": "What does Kinde cost at 100k MAU?",
        "a": "At standard tiers, expect roughly $400–$600 per month at 100k MAU before Enterprise SSO connection fees and dedicated tenancy. Always confirm with a custom quote at this scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-27",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(r){const i={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return n(e,{children:[a(i.h2,{id:\"what-kinde-is\",children:a(i.a,{className:\"heading-anchor\",href:\"#what-kinde-is\",children:\"What Kinde is\"})}),\"\\n\",n(i.p,{children:[\"Kinde launched in 2022 from Melbourne with a B2B-SaaS-first thesis: ship a modern CIAM with developer DX at the level of Clerk and \",a(i.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\", but with B2B Organizations, feature flags, and entitlements included from low tiers rather than gated to enterprise pricing. The buyer is a B2B SaaS startup that wants to ship enterprise features (Org-level SSO, role management, per-tenant feature flags) without paying enterprise CIAM prices.\"]}),\"\\n\",a(i.h2,{id:\"where-kinde-wins\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-kinde-wins\",children:\"Where Kinde wins\"})}),\"\\n\",n(i.p,{children:[\"The pricing-included-features model is the differentiator. B2B Organizations, entitlements, and feature flags are part of the standard tier instead of upcharges, which makes the unit economics work for SaaS startups at the 10k–100k MAU range that typically can't justify \",a(i.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\"'s pricing. Modern SDKs across major languages and a default UI that feels considered.\"]}),\"\\n\",a(i.h2,{id:\"where-kinde-hurts\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-kinde-hurts\",children:\"Where Kinde hurts\"})}),\"\\n\",n(i.p,{children:[\"Smaller than Auth0 / \",a(i.a,{href:\"/ciam-compass/vendors/clerk/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Clerk\"}),\" on community size, ecosystem, partner integrations, and Stack Overflow coverage. Compliance is SOC 2 only, for HIPAA, FedRAMP, ISO 27001, or PCI DSS, look elsewhere. No native FGA or adaptive risk decisioning. Australian regional infrastructure is more limited than global incumbents.\"]}),\"\\n\",a(i.h2,{id:\"how-kinde-compares\",children:a(i.a,{className:\"heading-anchor\",href:\"#how-kinde-compares\",children:\"How Kinde compares\"})}),\"\\n\",n(i.p,{children:[\"The closest comparisons are \",a(i.a,{href:\"/ciam-compass/compare/clerk-vs-kinde/\",children:\"Clerk vs Kinde\"}),\", \",a(i.a,{href:\"/ciam-compass/compare/auth0-vs-kinde/\",children:\"Auth0 vs Kinde\"}),\", and \",a(i.a,{href:\"/ciam-compass/compare/kinde-vs-workos/\",children:\"Kinde vs WorkOS\"}),\" for the B2B-SaaS-startup choice. For broader compliance and enterprise \",a(i.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\", \",a(i.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" or \",a(i.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" are the alternatives.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/kinde/",
    "edit_path": "content/vendors/kinde.mdx"
  },
  {
    "type": "vendor",
    "slug": "loginradius",
    "name": "LoginRadius",
    "legal_name": "LoginRadius Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.loginradius.com",
    "docs_url": "https://www.loginradius.com/docs/",
    "pricing_url": "https://www.loginradius.com/pricing",
    "github_url": null,
    "hq": "Jaipur, India",
    "founded": 2012,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 17000000,
      "last_round": {
        "stage": "series-a",
        "amount_usd": 17000000,
        "year": 2018,
        "lead": "ForgePoint Capital"
      },
      "investors": [
        "ForgePoint Capital",
        "Microsoft M12",
        "Real Ventures",
        "BDC Capital",
        "Yaletown Partners"
      ],
      "profitable": null,
      "notes": "Vancouver-founded CIAM serving 1B+ identities; $17M Series A from ForgePoint and Microsoft's M12 in 2018.",
      "source": "https://www.loginradius.com/press/loginradius-announces-series-a-funding-from-forgepoint-and-microsoft-venture"
    },
    "categories": [
      "b2c-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": false,
        "sms_otp": "partial",
        "email_otp": "partial",
        "totp": "partial",
        "push_mfa": false,
        "webauthn_passkeys": false,
        "biometric": false,
        "hardware_keys": false,
        "sso_saml": "partial",
        "sso_oidc": "partial",
        "sso_oauth2": "partial",
        "enterprise_federation": false,
        "passwordless_only_flows": false,
        "adaptive_mfa": false,
        "step_up_auth": false
      },
      "authorization": {
        "rbac": "partial",
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": false,
        "fine_grained_permissions": false
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": "partial",
        "organizations": false,
        "multi_tenancy": false,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "php",
          "dotnet"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": null
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": "partial",
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": "partial",
        "gdpr_data_export": true,
        "pii_minimization": false,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": false,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": "partial",
        "iso_27001": "partial",
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": "partial",
        "ccpa": "partial",
        "fedramp": false,
        "eu_data_residency": "partial"
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 7000
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Most paid tiers are quote-only",
      "notable_costs": [
        "Public pricing is limited; most production deployments require sales contact",
        "Pricing transparency rates poorly relative to category leaders",
        "Add-on pricing for MFA channels, social provider count, and consent management"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": null,
      "tco_at_500k_mau_estimate_usd_per_month": null,
      "tco_at_1m_mau_estimate_usd_per_month": null,
      "pricing_transparency_score": 1
    },
    "dx_score": 2,
    "docs_quality": 2,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": false,
    "passkey_orchestration_quality": 1,
    "strengths": [
      "Long-running B2C CIAM with a deployed footprint in social-login and basic registration flows.",
      "Cloud-SaaS only, no infrastructure burden for buyers who do not need self-host.",
      "Historical name recognition among legacy SMB B2C buyers; established documentation of the basic registration / social-login workflow."
    ],
    "limitations": [
      "Standards support has not kept pace with the category: OIDC, OAuth 2.1, and dynamic client registration are partial or absent where modern competitors treat them as table stakes.",
      "No native passkey / WebAuthn support, a material gap in a category where passkeys have become the default new-deployment choice.",
      "No support for modern agentic identity primitives (MCP, agent vs human token separation, web-bot-auth), the platform is behind the 2025/2026 standards push.",
      "Authorization story is shallow: no FGA, no fine-grained permissions, no rebac. RBAC is partial. For anything beyond simple registration + login, you'll bolt on a second product.",
      "Pricing transparency is among the weakest in the index, most tiers are quote-only with limited public list pricing, raising switching-cost and budgeting concerns.",
      "Developer experience trails category leaders: no Terraform provider, no CLI, no local emulator, no GraphQL API, SDK breadth is narrower than peers.",
      "No HIPAA support, material gap for any B2C deployment touching healthcare data.",
      "Compliance attestations (SOC 2, ISO 27001) are listed by the vendor; current status, audit cadence, and report availability should be re-verified directly with the vendor before procurement, published evidence trail is thinner than peers in this index.",
      "No publicly identifiable CISO or named security-leadership disclosure. For a CIAM vendor, whose product *is* security infrastructure, the absence of public security-leadership accountability is a meaningful procurement signal.",
      "REST API quality has degraded versus peer expectations: limited consistency across endpoints, no public API-style guide or versioning policy, and SDK breadth that has not modernized alongside the category. The API is functional but does not meet 2026 developer-experience expectations.",
      "Customer-base signals point to material churn over the last several years, observable case-study removals, reduced public reference-customer activity, and shrinking community presence. Net-new logo momentum is not visible from public sources.",
      "Editorial concern: independent operational reliability and security posture have been recurring questions among customers and partners. Verify current SLA, status-page history, and incident-disclosure practices directly with the vendor before committing to a deployment."
    ],
    "best_for": [
      "Legacy B2C deployments that already run on LoginRadius and need maintenance rather than modernization",
      "Small-team B2C registration flows where social login and basic password auth are the entire requirement"
    ],
    "not_for": [
      "Workloads requiring modern passkey-first authentication",
      "Healthcare or HIPAA-regulated deployments, no HIPAA support",
      "B2B SaaS, enterprise federation, or workforce identity",
      "Teams that need OAuth 2.1, MCP, or modern agentic-identity primitives",
      "Use cases where authorization (RBAC / FGA) matters beyond a binary login check",
      "Deployments where operational reliability or current security-attestation evidence is procurement-blocking, verify directly with the vendor before committing"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-05-30",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "LoginRadius product pages",
        "url": "https://www.loginradius.com",
        "accessed": "2026-05-11"
      },
      {
        "title": "LoginRadius documentation",
        "url": "https://www.loginradius.com/docs/",
        "accessed": "2026-05-11"
      },
      {
        "title": "LoginRadius pricing",
        "url": "https://www.loginradius.com/pricing",
        "accessed": "2026-05-11"
      }
    ],
    "editorial_verdict": "LoginRadius is a long-running B2C CIAM whose product footprint and operational posture have both narrowed materially relative to the category. The product covers basic social login, password registration, and a partial standards surface, but trails modern competitors on passkeys, OAuth 2.1, dynamic client registration, agentic-identity primitives, authorization depth, and developer experience.\n\n**Material gaps versus category leaders in 2026:**\n\n- No HIPAA support. Material for any deployment touching healthcare data.\n- SOC 2 and ISO 27001 are vendor-listed but the public audit and report evidence trail is thinner than peers. Current status should be re-verified directly with the vendor before procurement.\n- No publicly identifiable CISO or named security-leadership disclosure. Unusual for a CIAM vendor whose product is itself security infrastructure.\n- Customer-base signals point to material churn over the last several years (visible case-study removals, reduced public reference activity).\n- REST API quality has degraded versus peer expectations: limited consistency, no public API style guide or versioning policy, narrower SDK breadth than peers.\n\n**Alternatives we recommend for new deployments in 2026:**\n\n- [Auth0](/vendors/auth0/) for established B2C / B2B SaaS CIAM with full standards conformance, native passkeys, and Auth0 FGA for authorization.\n- [Stytch](/vendors/stytch/) for passkey-first developer-focused B2C with modern auth primitives.\n- [Descope](/vendors/descope/) for flow-builder orchestration with strong passkey support.\n- [SAP Customer Data Cloud](/vendors/sap-customer-data-cloud/) for enterprise B2C with consent and preference management at scale.\n\nFor broader category context see the [CIAM Annual Report 2025](/annual-report/2025/) and the [B2C CIAM segment award](/annual-report/2025/awards/b2c-ciam/).\n\n**Bottom line:** treat LoginRadius as a procurement-blocking risk for new deployments until the security-attestation, security-leadership-disclosure, and operational-reliability questions are answered directly by the vendor.\n",
    "faqs": [
      {
        "q": "Does LoginRadius support passkeys?",
        "a": "No, LoginRadius does not natively support WebAuthn or passkeys at the level required for a passkey-first B2C deployment. This is a material gap relative to modern CIAM competitors where passkeys are now the default new-deployment choice."
      },
      {
        "q": "Is LoginRadius a good choice for a new B2C deployment in 2026?",
        "a": "Probably not. The product covers basic social and password login, but it trails the category on standards (OIDC / OAuth 2.1 / DCR), passkeys, agentic-identity primitives, authorization, developer experience, and pricing transparency. For new B2C deployments we recommend evaluating Auth0, Stytch, Descope, or SAP Customer Data Cloud before defaulting to LoginRadius on brand recognition."
      },
      {
        "q": "Why is LoginRadius's editorial coverage on CIAM Compass lighter than other vendors?",
        "a": "Each vendor's profile depth is proportional to the breadth and modernity of the product surface. LoginRadius's current product covers a narrower feature footprint than category leaders, so several capability sections evaluate to 'No' or 'Partial.' The page reflects the platform as it is in 2026, not the historical positioning."
      },
      {
        "q": "How does LoginRadius compare to Auth0?",
        "a": "Auth0 is materially ahead on every axis a 2026 buyer cares about: standards (full OIDC / OAuth 2.1 / DCR vs partial), passkeys (native vs none), agentic-identity primitives (covered vs absent), developer experience (deep SDK + Terraform + CLI vs narrow SDK only), pricing transparency (public per-tier vs quote-only), and authorization (RBAC + FGA via Auth0 FGA vs partial RBAC only). LoginRadius's remaining argument is brand familiarity in legacy B2C deployments; for new builds Auth0 (or a developer-first alternative like Stytch or Descope) is the recommended evaluation path."
      },
      {
        "q": "Should we migrate off LoginRadius?",
        "a": "If you're running a stable B2C deployment that meets your current requirements and you're not blocked on modern features, there's no urgency. If you need passkeys, OAuth 2.1, modern authorization, or you're hitting reliability or pricing friction, a migration off LoginRadius onto a category leader (Auth0, Stytch, Descope) is worth a serious evaluation now rather than later."
      }
    ],
    "coi_disclosure": null,
    "changelog": [],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(r){const i={a:\"a\",h2:\"h2\",li:\"li\",p:\"p\",strong:\"strong\",ul:\"ul\",...r.components};return n(e,{children:[a(i.h2,{id:\"what-loginradius-is\",children:a(i.a,{className:\"heading-anchor\",href:\"#what-loginradius-is\",children:\"What LoginRadius is\"})}),\"\\n\",n(i.p,{children:[\"LoginRadius launched in 2012 with a B2C CIAM thesis: hosted social login, customer registration, and \",a(i.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\" delivered as a SaaS for organizations whose user base is consumers rather than employees. The product is cloud-only and historically targeted small-to-mid-market B2C deployments.\"]}),\"\\n\",a(i.h2,{id:\"where-loginradius-sits-in-2026\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-loginradius-sits-in-2026\",children:\"Where LoginRadius sits in 2026\"})}),\"\\n\",n(i.p,{children:[\"The category around LoginRadius has moved materially in the last several years. Modern B2C CIAM is now passkey-first; standards support has consolidated around OIDC, OAuth 2.1, and dynamic client registration; agentic-identity primitives (MCP, agent-vs-human token separation, web-bot-auth) have become table stakes for any platform expecting to handle AI agent traffic; \",a(i.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" has grown from RBAC to FGA / rebac engines; developer experience expectations include Terraform providers, CLIs, local emulators, and GraphQL APIs.\"]}),\"\\n\",n(i.p,{children:[a(i.a,{href:\"/ciam-compass/vendors/loginradius/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"LoginRadius\"}),\" has not kept pace with most of these shifts. The platform covers basic social and password login adequately, but its product surface lacks much of what a 2026 buyer would consider baseline.\"]}),\"\\n\",a(i.h2,{id:\"where-loginradius-hurts\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-loginradius-hurts\",children:\"Where LoginRadius hurts\"})}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"Standards coverage is partial where peers ship full conformance.\"}),\" OIDC, \",a(i.a,{href:\"/ciam-compass/glossary/oauth-2-1/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"OAuth 2.1\"}),\", and dynamic client registration are partial or absent. SAML and OIDC SSO are listed as partial rather than fully supported. For buyers whose architecture depends on standards-conformant integration, this is a procurement-blocking concern.\"]}),\"\\n\",n(i.p,{children:[n(i.strong,{children:[\"No passkey / \",a(i.a,{href:\"/ciam-compass/glossary/webauthn/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"WebAuthn\"}),\" native support.\"]}),\" In a category where \",a(i.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-first B2C deployments are now the recommended pattern (and where competitors like Stytch, Descope, Hanko, and Corbado have built their products around passkey orchestration), LoginRadius's absence here is a significant gap.\"]}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"No agentic-identity primitives.\"}),\" MCP support, OAuth 2.1, dynamic client registration, agent-vs-human token separation, and web-bot-auth, all absent. This is the 2025/2026 standards push and LoginRadius is not currently part of it.\"]}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"Shallow authorization.\"}),\" RBAC is partial. FGA, \",a(i.a,{href:\"/ciam-compass/glossary/rebac/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"rebac\"}),', fine-grained permissions, API authorization, all absent. For anything beyond a binary \"logged in / not logged in\" check, you\\'ll bolt on a second product.']}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"Pricing transparency is weak.\"}),\" Public pricing is limited to high-level tiers; most production deployments require sales contact. Pricing-transparency score in this index is 1 / 5, among the weakest.\"]}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"Developer experience trails.\"}),\" No Terraform provider, no CLI, no local emulator, no GraphQL API. SDK coverage is narrower than peers. DX score is 2 / 5.\"]}),\"\\n\",n(i.p,{children:[a(i.strong,{children:\"Editorial concern on operational posture.\"}),\" Independent reliability and security posture have been recurring questions among customers and partners in recent years. We have not independently verified specific incidents and don't allege any here, but procurement should verify current SLA, status-page history, and incident-disclosure practices directly with the vendor before committing.\"]}),\"\\n\",a(i.h2,{id:\"how-loginradius-compares\",children:a(i.a,{className:\"heading-anchor\",href:\"#how-loginradius-compares\",children:\"How LoginRadius compares\"})}),\"\\n\",a(i.p,{children:\"For 2026 B2C builds, the recommended evaluation path is one of:\"}),\"\\n\",n(i.ul,{children:[\"\\n\",n(i.li,{children:[a(i.strong,{children:a(i.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"})}),\", established B2C / B2B SaaS CIAM with full standards conformance, native passkeys, deep DX, and \",a(i.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" FGA for authorization.\"]}),\"\\n\",n(i.li,{children:[a(i.strong,{children:a(i.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"})}),\", passkey-first developer-focused B2C with modern auth primitives.\"]}),\"\\n\",n(i.li,{children:[a(i.strong,{children:a(i.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"})}),\", flow-builder approach with strong passkey orchestration.\"]}),\"\\n\",n(i.li,{children:[a(i.strong,{children:a(i.a,{href:\"/ciam-compass/vendors/sap-customer-data-cloud/\",children:\"SAP Customer Data Cloud\"})}),\", enterprise B2C with consent / preference management at scale.\"]}),\"\\n\"]}),\"\\n\",n(i.p,{children:[\"For SMB B2C specifically where price-point is a dominant constraint, \",a(i.a,{href:\"/ciam-compass/vendors/miniorange/\",children:\"miniOrange\"}),\" and \",a(i.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\" cover the same niche LoginRadius targets with more modern feature surface.\"]}),\"\\n\",a(i.p,{children:\"LoginRadius's remaining argument is brand familiarity for buyers who already run it. For new builds, the recommendation is to evaluate the alternatives above before defaulting to LoginRadius on legacy positioning alone.\"})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/loginradius/",
    "edit_path": "content/vendors/loginradius.mdx"
  },
  {
    "type": "vendor",
    "slug": "logto",
    "name": "Logto",
    "legal_name": "Silverhand Co., Ltd.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://logto.io",
    "docs_url": "https://docs.logto.io",
    "pricing_url": "https://logto.io/pricing",
    "github_url": "https://github.com/logto-io/logto",
    "hq": null,
    "founded": 2021,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 4600000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 2500000,
        "year": 2022,
        "lead": null
      },
      "investors": [],
      "profitable": null,
      "notes": "Open-source CIAM by Silverhand Inc.; two seed rounds totalling ~$4.6M (2021-2022).",
      "source": "https://www.crunchbase.com/organization/silverhand-f49f"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam",
      "b2c-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "python",
          "go",
          "php",
          "dotnet",
          "swift",
          "android",
          "kotlin"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Webhooks + custom JWT claims + Connectors (auth provider plugins)"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 5000
      },
      "paid_starts_at_usd": 16,
      "enterprise_quote_required_above": "Enterprise SSO connections + dedicated tenancy",
      "notable_costs": [
        "Self-hosted Community is MPL-2.0 licensed, free at any scale",
        "Logto Cloud free tier covers 5k MAU; paid plans start at $16/month",
        "Connectors (auth provider integrations) are pluggable; pay only for what you deploy"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 16,
      "tco_at_100k_mau_estimate_usd_per_month": 200,
      "tco_at_500k_mau_estimate_usd_per_month": 800,
      "tco_at_1m_mau_estimate_usd_per_month": 1600,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Most aggressive OSS pricing in the index, free tier on Cloud + MPL-2.0 self-hosted Community at any scale.",
      "Pluggable Connector model, auth providers (Google, GitHub, Apple, custom OAuth/SAML) added incrementally without monolithic configuration.",
      "Modern TypeScript codebase with clean SDK ergonomics across major frameworks.",
      "B2B Organizations and multi-tenancy as core data primitives, not bolt-ons."
    ],
    "limitations": [
      "Smaller community than Keycloak, FusionAuth, or Ory.",
      "Compliance footprint on Cloud is narrow, SOC 2 Type II only.",
      "No native FGA, no adaptive MFA, no managed bot defense.",
      "MPL-2.0 licensing is less permissive than Apache 2.0; some procurement teams flag the copyleft clauses."
    ],
    "best_for": [
      "Cost-sensitive teams that want both OSS self-host and managed cloud from one product",
      "B2C and B2B SaaS at low-to-mid MAU prioritizing predictable economics",
      "Greenfield projects that want clean SDK ergonomics in TypeScript-heavy stacks"
    ],
    "not_for": [
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Mid-large enterprise federation requirements",
      "Procurement environments requiring strict Apache-2.0-only licensing"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-03-31",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Logto Pricing",
        "url": "https://logto.io/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Logto Documentation",
        "url": "https://docs.logto.io",
        "accessed": "2026-04-22"
      },
      {
        "title": "Logto GitHub",
        "url": "https://github.com/logto-io/logto",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Logto is the modern OSS CIAM with the most aggressive pricing in 2026, MPL-2.0 self-hosted Community at any scale, Cloud free tier covering 5k MAU, and paid plans starting at $16/month. Connector-based pluggable architecture and clean TypeScript SDKs make it competitive on DX. The trade-off is narrower compliance and smaller community than Keycloak; for cost-sensitive greenfield projects, Logto is one of the strongest picks.",
    "faqs": [
      {
        "q": "What is Logto's MPL-2.0 license?",
        "a": "Mozilla Public License 2.0, a weak copyleft license allowing self-hosted use, modification, and commercial deployment. Modifications to Logto itself must be released under MPL-2.0 if redistributed; the license does not require open-sourcing applications that use Logto. For most procurement teams this is functionally equivalent to permissive OSS; for strict Apache-2.0-only environments, it requires legal review."
      },
      {
        "q": "How does Logto compare to Zitadel?",
        "a": "Both are modern OSS B2B-friendly CIAM with managed and self-hosted options. Logto is more aggressively priced and has TypeScript-heavy DX; Zitadel is more mature with stronger B2B Organizations and Swiss data residency. For early-stage cost sensitivity, Logto; for mid-stage B2B SaaS with sovereignty needs, Zitadel."
      },
      {
        "q": "Does Logto have B2B Organizations?",
        "a": "Yes, Organizations are a core data primitive supporting multi-tenancy, role hierarchies, and per-org settings. The implementation is competitive with Zitadel and Authentik for B2B SaaS, though less mature than dedicated B2B products like WorkOS or Frontegg."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-31",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:o,jsxs:a}=arguments[0];function _createMdxContent(n){const r={a:\"a\",h2:\"h2\",p:\"p\",strong:\"strong\",...n.components};return a(e,{children:[o(r.h2,{id:\"what-logto-is\",children:o(r.a,{className:\"heading-anchor\",href:\"#what-logto-is\",children:\"What Logto is\"})}),\"\\n\",a(r.p,{children:[o(r.a,{href:\"/ciam-compass/vendors/logto/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Logto\"}),\" launched in 2021 as a modern open-source CIAM with TypeScript-first DX, Connector-based pluggable architecture (auth providers compose as separate modules), and aggressive pricing on both self-hosted and managed deployments. The product covers B2C consumer flows, B2B Organizations, and basic enterprise SSO from one codebase.\"]}),\"\\n\",o(r.h2,{id:\"where-logto-wins\",children:o(r.a,{className:\"heading-anchor\",href:\"#where-logto-wins\",children:\"Where Logto wins\"})}),\"\\n\",a(r.p,{children:[\"Aggressive pricing, MPL-2.0 self-hosted at any scale, Cloud free up to 5k \",o(r.a,{href:\"/ciam-compass/glossary/mau/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"MAU\"}),\", paid plans from $16/month. Connector-based architecture means each auth provider integration is a separate module that pays only when used. Modern TypeScript codebase delivers clean SDK ergonomics.\"]}),\"\\n\",o(r.h2,{id:\"where-logto-hurts\",children:o(r.a,{className:\"heading-anchor\",href:\"#where-logto-hurts\",children:\"Where Logto hurts\"})}),\"\\n\",a(r.p,{children:[\"Smaller community than Keycloak / \",o(r.a,{href:\"/ciam-compass/vendors/fusionauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"FusionAuth\"}),\" / Ory. Compliance footprint on Cloud is narrow (SOC 2 only). MPL-2.0 licensing requires legal review at strict-OSS environments. No native FGA, no adaptive MFA, no bot defense.\"]}),\"\\n\",o(r.h2,{id:\"how-logto-compares\",children:o(r.a,{className:\"heading-anchor\",href:\"#how-logto-compares\",children:\"How Logto compares\"})}),\"\\n\",a(r.p,{children:[\"The closest comparisons are \",o(r.a,{href:\"/ciam-compass/compare/logto-vs-zitadel/\",children:\"Logto vs Zitadel\"}),\", \",o(r.a,{href:\"/ciam-compass/compare/logto-vs-fusionauth/\",children:\"Logto vs FusionAuth\"}),\", and \",o(r.a,{href:\"/ciam-compass/compare/auth0-vs-logto/\",children:\"Auth0 vs Logto\"}),\". For broader OSS without managed-cloud, \",o(r.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\", \",o(r.a,{href:\"/ciam-compass/vendors/authentik/\",children:\"Authentik\"}),\", and \",o(r.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory\"}),\" are the alternatives.\"]}),\"\\n\",a(r.p,{children:[o(r.strong,{children:\"Go deeper:\"}),\" \",o(r.a,{href:\"https://guptadeepak.com/open-source-licensing-101-everything-you-need-to-know/\",children:\"Open-source licensing 101\"}),\" explains weak versus strong copyleft and what MPL 2.0 actually permits.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?o(a,{...e,children:o(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/logto/",
    "edit_path": "content/vendors/logto.mdx"
  },
  {
    "type": "vendor",
    "slug": "miniorange",
    "name": "miniOrange",
    "legal_name": "miniOrange Security Software Pvt. Ltd.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.miniorange.com",
    "docs_url": "https://www.miniorange.com/iam/integrations",
    "pricing_url": "https://www.miniorange.com/iam/pricing",
    "github_url": null,
    "hq": "Pune, India",
    "founded": 2012,
    "status": "active",
    "funding": {
      "model": "bootstrapped",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": true,
      "notes": "Bootstrapped and profitable since 2012; the company publicly positions itself as investor-free by choice.",
      "source": "https://www.miniorange.com/blog/why-companies-trust-bootstrapped-software-over-investor-led-solutions/"
    },
    "categories": [
      "enterprise-ciam",
      "b2b-saas-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted",
      "on-prem"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "php",
          "java",
          "dotnet",
          "python"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Plugins for major CMS / SaaS apps + custom adapters"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": "partial",
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 5000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Self-hosted enterprise + dedicated tenancy",
      "notable_costs": [
        "Tiered per-MAU pricing on cloud; on-prem priced separately",
        "Plugin ecosystem for WordPress, Joomla, Magento, and other CMS / SaaS apps",
        "Both cloud and on-prem deployments from one vendor"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 49,
      "tco_at_100k_mau_estimate_usd_per_month": 600,
      "tco_at_500k_mau_estimate_usd_per_month": 2400,
      "tco_at_1m_mau_estimate_usd_per_month": 4800,
      "pricing_transparency_score": 4
    },
    "dx_score": 3,
    "docs_quality": 3,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Broad plugin ecosystem covering WordPress, Joomla, Magento, and many CMS / SaaS apps, uncommon in this index.",
      "Both cloud and on-prem deployment options from one vendor.",
      "Established 2012, long track record in SMB and mid-market deployments.",
      "Lower price points than enterprise CIAM at comparable feature footprint."
    ],
    "limitations": [
      "DX trails developer-first tier, admin UI and APIs reflect SMB-IAM design choices.",
      "Plugin-driven extensibility is heavier than modern hooks / webhooks model.",
      "Documentation is comprehensive but inconsistent in places.",
      "Compliance footprint is solid for B2B but lacks FedRAMP and PCI DSS direct attestation."
    ],
    "best_for": [
      "SMB and mid-market B2B SaaS needing CIAM at lower price than enterprise incumbents",
      "WordPress / Joomla / CMS-driven sites needing pre-built auth integrations",
      "On-prem deployments with budget below enterprise-quote thresholds"
    ],
    "not_for": [
      "Workloads requiring FedRAMP or PCI DSS direct attestation",
      "Teams prioritizing developer-first DX over breadth of integrations",
      "Authorization-heavy use cases requiring FGA"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-06-05",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "miniOrange Plans",
        "url": "https://www.miniorange.com/iam/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "miniOrange IAM Documentation",
        "url": "https://www.miniorange.com/iam/integrations",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "miniOrange is a long-running SMB-and-mid-market CIAM with broad plugin ecosystem coverage (WordPress, Joomla, Magento, and many CMS / SaaS apps) and both cloud and on-prem deployment from one vendor. The price points sit below enterprise CIAM incumbents at comparable feature footprint. The trade-offs are dated DX, inconsistent documentation, and compliance gaps on FedRAMP and PCI DSS. For CMS-driven sites and SMB B2B SaaS needing on-prem flexibility, miniOrange is a credible mid-tier pick.",
    "faqs": [
      {
        "q": "Does miniOrange support WordPress, Joomla, and other CMS platforms?",
        "a": "Yes, pre-built plugins for WordPress, Joomla, Magento, Drupal, and many SaaS apps are a core part of the product. Among CIAM vendors, miniOrange has the broadest CMS-plugin coverage in this index."
      },
      {
        "q": "Can I deploy miniOrange on-prem?",
        "a": "Yes, alongside the cloud offering. On-prem is priced separately and is appropriate for organizations with data sovereignty or hosting-cost constraints."
      },
      {
        "q": "How does miniOrange compare to Auth0?",
        "a": "miniOrange targets SMB and mid-market with broader CMS plugin coverage and lower price points; Auth0 targets developer-first SaaS with deeper compliance footprint and DX. For CMS-driven sites or on-prem needs at SMB scale, miniOrange is competitive; for developer-first SaaS, Auth0 wins."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-06-05",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:n,jsxs:a}=arguments[0];function _createMdxContent(i){const r={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return a(e,{children:[n(r.h2,{id:\"what-miniorange-is\",children:n(r.a,{className:\"heading-anchor\",href:\"#what-miniorange-is\",children:\"What miniOrange is\"})}),\"\\n\",a(r.p,{children:[n(r.a,{href:\"/ciam-compass/vendors/miniorange/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"miniOrange\"}),\" launched in 2012 in Pune, India with a broad SMB-IAM thesis: deliver CIAM, MFA, SSO, and identity orchestration to small-and-mid-market organizations with pre-built integrations for the CMS and SaaS apps they actually use. The product offers cloud and on-prem deployment, broad plugin coverage (WordPress, Joomla, Magento, Drupal, hundreds of SaaS apps), and price points materially below enterprise CIAM.\"]}),\"\\n\",n(r.h2,{id:\"where-miniorange-wins\",children:n(r.a,{className:\"heading-anchor\",href:\"#where-miniorange-wins\",children:\"Where miniOrange wins\"})}),\"\\n\",a(r.p,{children:[\"Plugin breadth is unmatched in this index, for organizations whose stack includes WordPress, Joomla, Magento, or a long list of SaaS apps requiring pre-integrated \",n(r.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\", miniOrange delivers more out-of-box coverage than any competitor. Both cloud and on-prem options from one vendor. Long track record (since 2012) provides production stability.\"]}),\"\\n\",n(r.h2,{id:\"where-miniorange-hurts\",children:n(r.a,{className:\"heading-anchor\",href:\"#where-miniorange-hurts\",children:\"Where miniOrange hurts\"})}),\"\\n\",a(r.p,{children:[\"DX trails developer-first tier, admin UI and APIs reflect SMB-IAM design choices. Plugin-driven extensibility is heavier than modern hooks / webhooks. Documentation is comprehensive but inconsistent. Compliance is solid for B2B but lacks FedRAMP and PCI DSS direct \",n(r.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\".\"]}),\"\\n\",n(r.h2,{id:\"how-miniorange-compares\",children:n(r.a,{className:\"heading-anchor\",href:\"#how-miniorange-compares\",children:\"How miniOrange compares\"})}),\"\\n\",a(r.p,{children:[\"The closest comparisons are \",n(r.a,{href:\"/ciam-compass/compare/auth0-vs-miniorange/\",children:\"Auth0 vs miniOrange\"}),\", \",n(r.a,{href:\"/ciam-compass/compare/keycloak-vs-miniorange/\",children:\"Keycloak vs miniOrange\"}),\" for the SMB-on-prem call, and Okta vs miniOrange for the workforce-IAM-adjacent question. For developer-first DX at lower scale, \",n(r.a,{href:\"/ciam-compass/vendors/kinde/\",children:\"Kinde\"}),\" and \",n(r.a,{href:\"/ciam-compass/vendors/clerk/\",children:\"Clerk\"}),\" are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?n(a,{...e,children:n(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/miniorange/",
    "edit_path": "content/vendors/miniorange.mdx"
  },
  {
    "type": "vendor",
    "slug": "mojoauth",
    "name": "MojoAuth",
    "legal_name": "MojoAuth, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://mojoauth.com",
    "docs_url": "https://mojoauth.com/docs",
    "pricing_url": "https://mojoauth.com/pricing",
    "github_url": "https://github.com/mojoauth",
    "hq": "Mountain View, California, USA",
    "founded": 2024,
    "status": "active",
    "funding": {
      "model": "bootstrapped",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Bootstrapped passwordless API; ~$680K revenue with an 11-person team (2024).",
      "source": "https://getlatka.com/companies/mojoauth"
    },
    "categories": [
      "b2c-ciam",
      "passwordless-specialist",
      "developer-first-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "angular",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "php",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": "partial",
        "local_emulator": false,
        "extension_model": "Webhooks + custom domains + custom UI"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": "partial",
        "integrates_with_cmps": [
          "OneTrust",
          "Cookiebot"
        ]
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Enterprise SSO and dedicated tenancy",
      "notable_costs": [
        "Per-MAU pricing scales gently, meaningfully cheaper than Auth0 above 100k MAU",
        "Enterprise SSO connections billed per-connection at standard B2B tier",
        "Custom domain and white-label UI available without enterprise upcharge"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 49,
      "tco_at_100k_mau_estimate_usd_per_month": 550,
      "tco_at_500k_mau_estimate_usd_per_month": 2200,
      "tco_at_1m_mau_estimate_usd_per_month": 4200,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Passwordless-first product DNA, magic links, email/SMS OTP, and passkeys are first-class with thoughtful orchestration, not bolt-ons.",
      "Enterprise-grade authentication features for consumer apps, SAML/OIDC SSO, advanced MFA, adaptive risk, without an enterprise-tier price.",
      "Pricing transparency and meaningful cost advantage over Auth0 above 100k MAU at comparable feature footprint.",
      "Strong consent management and preference center, uncommon in this tier and useful for GDPR-heavy consumer apps."
    ],
    "limitations": [
      "Smaller ecosystem than Auth0, fewer Stack Overflow answers, fewer third-party integrations, less mature partner network.",
      "No native Zanzibar-style FGA, pair with OpenFGA / Authzed for fine-grained authorization at scale.",
      "Compliance footprint is solid for most use cases but lacks FedRAMP and direct PCI DSS attestation.",
      "Adaptive risk decisioning is improving but less mature than Descope's flow-editor approach."
    ],
    "best_for": [
      "Consumer-facing apps standardizing on modern passwordless flows (passkeys, magic links, OTP)",
      "B2C teams switching off Auth0 for cost or simplicity reasons in the 100k–1M MAU range",
      "Consumer apps with GDPR-grade consent requirements",
      "Consumer apps that need enterprise-grade auth features (SAML SSO, advanced MFA, adaptive) without enterprise-tier pricing"
    ],
    "not_for": [
      "B2B SaaS targeting workforce identity or per-Org enterprise SSO at scale (use Frontegg, WorkOS, Auth0 Organizations, or SSOJet)",
      "Workloads requiring FedRAMP or direct PCI DSS attestation",
      "Applications requiring Zanzibar-style FGA at scale",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "MojoAuth Pricing",
        "url": "https://mojoauth.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "MojoAuth Documentation",
        "url": "https://mojoauth.com/docs",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "MojoAuth is a growing passwordless-native CIAM. Passkeys, magic links, and OTP are the product, not Flow blocks. Published MAU pricing scales through enterprise volume (free tier through a declining per-MAU table into the millions) without Auth0's invoice shape. Put it on the 2026 shortlist next to Stytch for passkeys, not next to Descope. Descope is orchestration. MojoAuth is passwordless. Community and FedRAMP still trail Auth0.",
    "faqs": [
      {
        "q": "Is MojoAuth a credible Auth0 alternative for consumer apps?",
        "a": "Yes for most B2C use cases under 1M MAU. Capability coverage is broadly comparable on auth, MFA, passkeys, and consumer-facing flows; pricing is materially lower above 100k MAU; the compliance and ecosystem gaps narrow the case for FedRAMP-bound and federation-heavy enterprise workloads. For B2B SaaS targeting workforce identity, look at Frontegg, WorkOS, Auth0 Organizations, or SSOJet instead."
      },
      {
        "q": "Is MojoAuth a B2B CIAM?",
        "a": "No, MojoAuth is a B2C CIAM. The product targets consumer-facing apps with modern passwordless flows and enterprise-grade auth features (SAML SSO, advanced MFA, adaptive risk). For B2B SaaS use cases that center on per-Organization SSO, SCIM provisioning, and embedded customer admin portals, the right shortlist is Frontegg, WorkOS, Auth0 Organizations, or SSOJet."
      },
      {
        "q": "How does MojoAuth's passkey support compare?",
        "a": "MojoAuth is passkey-native. Device-aware prompting, conditional UI, and recovery are the default product, not a visual-editor add-on. Compass scores it 5/5 on passkey orchestration, alongside Stytch. Descope is not in that tier: it is an orchestration platform with WebAuthn as a Flow method."
      },
      {
        "q": "What does 'enterprise auth for consumer apps' mean?",
        "a": "Many B2C apps need authentication features that originated in the enterprise stack: SAML / OIDC SSO (e.g., a consumer app that integrates with a partner's IdP), advanced MFA factors, adaptive risk-based authentication, and audit-grade logging. MojoAuth bundles these into B2C pricing tiers rather than reserving them for enterprise contracts."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Editorial: passwordless-native positioning, passkey_orchestration_quality 5/5, scaled enterprise pricing called out vs Descope's limited volume curve."
      },
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-06-01",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:a,jsx:e,jsxs:t}=arguments[0];function _createMdxContent(o){const s={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return t(a,{children:[e(s.h2,{id:\"what-mojoauth-is\",children:e(s.a,{className:\"heading-anchor\",href:\"#what-mojoauth-is\",children:\"What MojoAuth is\"})}),\"\\n\",t(s.p,{children:[\"MojoAuth launched in 2024 with a passwordless-first scope, magic links, email and SMS OTP, social login, aimed at consumer apps that wanted to ship without password infrastructure. It has since expanded into B2B Organizations, Enterprise SSO with SAML and OIDC, SCIM provisioning, and \",e(s.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", covering both segments from a single product surface, which is uncommon in this tier.\"]}),\"\\n\",e(s.h2,{id:\"where-mojoauth-wins\",children:e(s.a,{className:\"heading-anchor\",href:\"#where-mojoauth-wins\",children:\"Where MojoAuth wins\"})}),\"\\n\",t(s.p,{children:[\"The single-platform B2C-plus-B2B story is the differentiator. Most CIAM vendors force a choice: Auth0 covers both but at enterprise pricing; Stytch splits into separate B2C and B2B products with distinct billing; WorkOS is B2B-first; Clerk is mid-market B2B SaaS. \",e(s.a,{href:\"/ciam-compass/vendors/mojoauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"MojoAuth\"}),\" ships consumer flows and B2B Organizations from the same product, which simplifies the buy decision for SaaS apps that have both end-user and tenant-admin journeys.\"]}),\"\\n\",t(s.p,{children:[\"Passkey orchestration is well above the orchestration-light market median. Device-aware prompting, \",e(s.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\", and recovery flows are designed in rather than bolted on, which translates into materially better adoption than vendors who shipped raw WebAuthn support without the prompting layer.\"]}),\"\\n\",e(s.p,{children:\"Consent management and preference center support is unusual for the tier, most developer-first vendors leave this to a separate CMP integration. MojoAuth ships first-class consent capture with audit trail, which matters for GDPR-heavy consumer apps.\"}),\"\\n\",t(s.p,{children:[\"Pricing is meaningfully lower than \",e(s.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" above 100k MAU at comparable feature footprint. Custom domains and white-label UI are available without an enterprise upcharge.\"]}),\"\\n\",e(s.h2,{id:\"where-mojoauth-hurts\",children:e(s.a,{className:\"heading-anchor\",href:\"#where-mojoauth-hurts\",children:\"Where MojoAuth hurts\"})}),\"\\n\",e(s.p,{children:\"The ecosystem is smaller than Auth0's. Fewer Stack Overflow answers, fewer third-party integrations, less mature partner network. For most teams this is a non-issue; for teams that depend on Stack Overflow being the unblocker at 2 AM, it's a real friction.\"}),\"\\n\",t(s.p,{children:[\"There's no native Zanzibar-style FGA. For B2B SaaS designing fine-grained \",e(s.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" at scale, pair with OpenFGA, Authzed, or Permify.\"]}),\"\\n\",t(s.p,{children:[\"Compliance breadth is solid (SOC 2, ISO 27001, HIPAA, GDPR, CCPA) but does not yet include FedRAMP or direct PCI DSS \",e(s.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\". For most consumer and B2B SaaS this is fine; for federal or fintech workloads requiring those specifically, it isn't.\"]}),\"\\n\",e(s.h2,{id:\"how-mojoauth-compares\",children:e(s.a,{className:\"heading-anchor\",href:\"#how-mojoauth-compares\",children:\"How MojoAuth compares\"})}),\"\\n\",t(s.p,{children:[\"The most relevant direct comparisons are \",e(s.a,{href:\"/ciam-compass/compare/mojoauth-vs-auth0/\",children:\"MojoAuth vs Auth0\"}),\" for the cost-and-coverage call and \",e(s.a,{href:\"/ciam-compass/compare/mojoauth-vs-stytch/\",children:\"MojoAuth vs Stytch\"}),\" for the passwordless-orchestration call. For pure B2B with deeper \",e(s.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" breadth, \",e(s.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" and \",e(s.a,{href:\"/ciam-compass/vendors/ssojet/\",children:\"SSOJet\"}),\" are alternatives. For self-hosted, \",e(s.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",e(s.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\" are the standard options.\"]})]})}return{default:function(a={}){const{wrapper:t}=a.components||{};return t?e(t,{...a,children:e(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/mojoauth/",
    "edit_path": "content/vendors/mojoauth.mdx"
  },
  {
    "type": "vendor",
    "slug": "oracle-idcs",
    "name": "Oracle IAM Identity Domains",
    "legal_name": "Oracle IAM Identity Domains (formerly Oracle Identity Cloud Service / IDCS)",
    "parent_company": "Oracle Corporation",
    "acquired_by": null,
    "website": "https://www.oracle.com/security/cloud-security/identity-cloud/",
    "docs_url": "https://docs.oracle.com/en/cloud/paas/identity-cloud/",
    "pricing_url": null,
    "github_url": null,
    "hq": "Austin, Texas, USA",
    "founded": 2017,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Identity domains inside Oracle Cloud Infrastructure (NYSE: ORCL).",
      "source": "https://www.oracle.com/security/cloud-security/identity-cloud/"
    },
    "categories": [
      "enterprise-ciam",
      "cloud-native-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "hybrid"
    ],
    "target_segments": [
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "python",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "OCI Functions + custom workflows"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote via Oracle sales",
      "notable_costs": [
        "Per-user / per-MAU pricing typical for Oracle Cloud services",
        "Bundled with Oracle Cloud Infrastructure (OCI) deployments",
        "Strong fit for existing Oracle Database / Fusion Apps / Oracle Cloud customers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 5500,
      "tco_at_500k_mau_estimate_usd_per_month": 18000,
      "tco_at_1m_mau_estimate_usd_per_month": 32000,
      "pricing_transparency_score": 2
    },
    "dx_score": 3,
    "docs_quality": 3,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Native integration with Oracle Cloud Infrastructure (OCI) and Oracle Fusion Applications.",
      "FedRAMP High, PCI Level 1, HIPAA, full enterprise compliance footprint.",
      "Mature Oracle enterprise sales and support model.",
      "Strong fit for existing Oracle Database and Fusion Apps customers."
    ],
    "limitations": [
      "DX is dated and reflects classic Oracle enterprise design.",
      "Outside Oracle ecosystem, the integration story is weak.",
      "Pricing opacity and Oracle commercial complexity.",
      "Vendor lock-in via OCI integration is significant once production deployments are live."
    ],
    "best_for": [
      "Existing Oracle Cloud Infrastructure customers",
      "Oracle Fusion Applications deployments needing federated CIAM",
      "Public-sector workloads requiring FedRAMP High via Oracle Cloud"
    ],
    "not_for": [
      "Greenfield projects without Oracle ecosystem context",
      "Mid-market SaaS or startups",
      "Multi-cloud deployments not centered on Oracle"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 5
    },
    "last_verified": "2026-05-26",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Oracle IAM Identity Domains documentation",
        "url": "https://docs.oracle.com/en-us/iaas/Content/Identity/home.htm",
        "accessed": "2026-05-08"
      },
      {
        "title": "Oracle Cloud Service Changes (IDCS → Identity Domains migration)",
        "url": "https://docs.oracle.com/en-us/iaas/Content/servicechanges.htm",
        "accessed": "2026-05-08"
      }
    ],
    "editorial_verdict": "Oracle merged the standalone IDCS service into OCI IAM Identity Domains; existing IDCS tenants have been migrated and the brand is now 'Oracle IAM Identity Domains'. IDCS authentication methods are being deprecated in OCI services starting April 11, 2026. The platform is the right CIAM choice for existing Oracle Cloud Infrastructure customers and Oracle Fusion Applications deployments where native integration justifies the platform. FedRAMP High plus full enterprise compliance footprint suits regulated workloads on Oracle Cloud. Outside Oracle ecosystem, the DX gap and pricing opacity still make it the wrong answer for greenfield evaluation.",
    "faqs": [
      {
        "q": "Does Oracle IDCS work outside Oracle Cloud?",
        "a": "Yes technically, standard protocols (SAML, OIDC, OAuth 2.0) work with any application. But the integration value is materially stronger for existing OCI / Oracle Database / Fusion Apps customers. Greenfield non-Oracle projects rarely choose IDCS over Auth0 or Cognito."
      },
      {
        "q": "What's the relationship to Oracle Access Manager (OAM)?",
        "a": "OAM is the legacy on-prem product (part of Oracle Identity and Access Management Suite); IDCS is the cloud-native successor. Many Oracle enterprise customers run both during migration. Hybrid deployments are common."
      },
      {
        "q": "What does Oracle IDCS cost?",
        "a": "Enterprise quote via Oracle sales. Typically per-user or per-MAU pricing as part of broader OCI commercial agreements; transparency is low and total cost depends heavily on Oracle commercial relationship."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-26",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      },
      {
        "date": "2026-05-08",
        "summary": "Renamed from 'Oracle Identity Cloud Service' to 'Oracle IAM Identity Domains' to reflect Oracle's consolidation of IDCS into OCI IAM. Verdict notes April 11, 2026 deprecation of IDCS authentication methods in OCI services."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:a}=arguments[0];function _createMdxContent(i){const c={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return a(e,{children:[r(c.h2,{id:\"what-oracle-identity-cloud-service-is\",children:r(c.a,{className:\"heading-anchor\",href:\"#what-oracle-identity-cloud-service-is\",children:\"What Oracle Identity Cloud Service is\"})}),\"\\n\",a(c.p,{children:[\"Oracle Identity Cloud Service (IDCS) is Oracle's cloud-native CIAM, launched in 2017 as the successor to the legacy Oracle Access Manager. The product runs on Oracle Cloud Infrastructure (OCI) and serves as the identity layer for OCI-deployed applications, Oracle Fusion Applications, and \",r(c.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\" with on-prem Oracle deployments. The buyer is typically an existing Oracle enterprise shop where IDCS integration justifies the platform.\"]}),\"\\n\",r(c.h2,{id:\"where-oracle-idcs-wins\",children:r(c.a,{className:\"heading-anchor\",href:\"#where-oracle-idcs-wins\",children:\"Where Oracle IDCS wins\"})}),\"\\n\",r(c.p,{children:\"Native integration with OCI and Oracle Fusion Applications. FedRAMP High, PCI DSS Level 1, HIPAA, full enterprise compliance footprint. Mature Oracle enterprise sales and support. Strong fit for existing Oracle Database and Fusion Apps customers.\"}),\"\\n\",r(c.h2,{id:\"where-oracle-idcs-hurts\",children:r(c.a,{className:\"heading-anchor\",href:\"#where-oracle-idcs-hurts\",children:\"Where Oracle IDCS hurts\"})}),\"\\n\",r(c.p,{children:\"DX trails developer-first tier. Outside Oracle ecosystem the integration story is weak. Pricing opacity and Oracle commercial complexity. Vendor lock-in via OCI integration is significant.\"}),\"\\n\",r(c.h2,{id:\"how-oracle-idcs-compares\",children:r(c.a,{className:\"heading-anchor\",href:\"#how-oracle-idcs-compares\",children:\"How Oracle IDCS compares\"})}),\"\\n\",a(c.p,{children:[\"The closest comparisons are \",r(c.a,{href:\"/ciam-compass/compare/auth0-vs-oracle-idcs/\",children:\"Auth0 vs Oracle IDCS\"}),\" and \",r(c.a,{href:\"/ciam-compass/compare/cognito-vs-oracle-idcs/\",children:\"Cognito vs Oracle IDCS\"}),\" for the cloud-native call. For other legacy enterprise CIAM, \",r(c.a,{href:\"/ciam-compass/vendors/ping-identity/\",children:\"Ping Identity\"}),\", \",r(c.a,{href:\"/ciam-compass/vendors/forgerock/\",children:\"ForgeRock\"}),\", and \",r(c.a,{href:\"/ciam-compass/vendors/ibm-security-verify/\",children:\"IBM Security Verify\"}),\" are the peers.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?r(a,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/oracle-idcs/",
    "edit_path": "content/vendors/oracle-idcs.mdx"
  },
  {
    "type": "vendor",
    "slug": "ory",
    "name": "Ory",
    "legal_name": "Ory Corp.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.ory.sh",
    "docs_url": "https://www.ory.sh/docs",
    "pricing_url": "https://www.ory.sh/pricing",
    "github_url": "https://github.com/ory",
    "hq": "Munich, Germany",
    "founded": 2017,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 27500000,
      "last_round": {
        "stage": "series-a",
        "amount_usd": 22500000,
        "year": 2021,
        "lead": "Insight Partners"
      },
      "investors": [
        "Insight Partners",
        "Balderton Capital",
        "In-Q-Tel"
      ],
      "profitable": null,
      "notes": "Open-source identity (Kratos, Hydra, Keto); $22.5M Series A plus a $5M extension. In-Q-Tel (CIA-linked) on the cap table.",
      "source": "https://www.insightpartners.com/ideas/cloud-security-provider-ory-corp-raises-22-million-in-series-a-round-led-by-insight-partners/"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "self-hosted",
      "cloud-saas",
      "hybrid"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": "partial",
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": true,
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "go",
          "python",
          "php",
          "ruby",
          "java",
          "dotnet",
          "rust"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Webhooks + custom UI nodes (self-service flows are configurable, not hooks-driven)"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": "partial",
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": "partial",
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": "partial",
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 25000
      },
      "paid_starts_at_usd": 29,
      "enterprise_quote_required_above": "Enterprise on Ory Network with custom SLAs",
      "notable_costs": [
        "Self-hosted Ory components are Apache 2.0, free to run; pay only operational cost",
        "Ory Network (managed) is per-MAU like a SaaS CIAM, with EU data residency by default",
        "Keto (FGA) self-hosted is free; managed Keto on Ory Network priced separately"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 29,
      "tco_at_100k_mau_estimate_usd_per_month": 350,
      "tco_at_500k_mau_estimate_usd_per_month": 1400,
      "tco_at_1m_mau_estimate_usd_per_month": 2800,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Most modern open-source CIAM architecture in 2026, Go-based, Kubernetes-native, components composable (Kratos / Hydra / Keto / Oathkeeper).",
      "Keto ships native Zanzibar-style FGA, one of two genuinely OSS Zanzibar implementations alongside OpenFGA.",
      "Strict Apache 2.0 licensing across all components; no commercial-use clauses or contributor licensing surprises.",
      "EU-headquartered with EU data residency on Ory Network managed offering, meaningful for European buyers."
    ],
    "limitations": [
      "Component model means more moving parts, Kratos for users, Hydra for OAuth server, Keto for authz, Oathkeeper for proxy, operational scope is broader than Keycloak or FusionAuth.",
      "B2B Organizations model is less first-class than dedicated B2B vendors (WorkOS, Frontegg).",
      "Adaptive risk decisioning and bot defense are weak; pair with Authsignal or external risk engines.",
      "DX is improving but the component decomposition imposes a learning curve some teams find too high."
    ],
    "best_for": [
      "Teams that want OSS CIAM with native FGA without running a separate authz vendor",
      "EU-based or data-residency-sensitive deployments wanting managed CIAM with EU sovereignty",
      "Kubernetes-native architectures comfortable composing services"
    ],
    "not_for": [
      "Teams that want a single deployable artifact (look at FusionAuth or Keycloak)",
      "B2B SaaS prioritizing Admin Portal UX (look at Frontegg)",
      "Workloads requiring FedRAMP or PCI DSS direct attestation"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 2
    },
    "last_verified": "2026-03-12",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Ory Pricing",
        "url": "https://www.ory.sh/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Ory Documentation",
        "url": "https://www.ory.sh/docs",
        "accessed": "2026-04-22"
      },
      {
        "title": "Ory GitHub",
        "url": "https://github.com/ory",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Ory is the most architecturally modern open-source CIAM in 2026, Go-based, Kubernetes-native, composable components, strict Apache 2.0, with native Zanzibar-style FGA via Keto that no other full-platform vendor in this index ships natively. The trade-off is operational scope: running four composable services rather than one binary suits Kubernetes-native teams and frustrates everyone else. For teams that want OSS plus FGA from one vendor, Ory is the singular pick.",
    "faqs": [
      {
        "q": "What are Kratos, Hydra, Keto, and Oathkeeper?",
        "a": "Kratos is the user identity and self-service flows server. Hydra is the OAuth 2.0 / OIDC authorization server. Keto is the Zanzibar-style fine-grained authorization service. Oathkeeper is the identity-aware reverse proxy that enforces auth at the network edge. They compose; you can run any subset."
      },
      {
        "q": "Is Ory Network the only paid product?",
        "a": "Effectively yes, the components are Apache 2.0 and free to self-host. Ory Network is the managed offering that runs the components for you with EU data residency, support, and the Ory Console. Paid plans on Ory Network start at $29/month."
      },
      {
        "q": "How does Ory FGA (Keto) compare to OpenFGA?",
        "a": "Both are Zanzibar implementations. Keto pre-dates OpenFGA and is more tightly integrated with the rest of the Ory stack; OpenFGA is a CNCF project with broader vendor neutrality. For teams already running Ory components, Keto is the natural choice; for teams running other CIAM, OpenFGA is the more common pick."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-03-12",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(r){const t={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return n(e,{children:[a(t.h2,{id:\"what-ory-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-ory-is\",children:\"What Ory is\"})}),\"\\n\",n(t.p,{children:[\"Ory was founded in 2017 in Munich with a thesis that the OSS CIAM market needed a Kubernetes-native, components-first alternative to Keycloak's monolithic Java service. The product line consists of four Apache 2.0 services that compose: Kratos (identity and self-service), Hydra (OAuth 2.0 / OIDC \",a(t.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" server), Keto (Zanzibar-style fine-grained authorization), and Oathkeeper (identity-aware proxy). Ory Network is the managed offering, sold per-MAU with EU data residency by default. The buyer is typically a team that wants OSS CIAM with modern operational ergonomics, or a team running on EU infrastructure that needs sovereignty.\"]}),\"\\n\",a(t.h2,{id:\"where-ory-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-ory-wins\",children:\"Where Ory wins\"})}),\"\\n\",n(t.p,{children:[\"The architecture is the differentiator. Each component is a single Go binary with a small footprint, designed for Kubernetes deployment with the standard stateless-service patterns. Schema migrations are first-class. Components compose: a team can run only Kratos for user management, only Hydra for OAuth server, only Keto for \",a(t.a,{href:\"/ciam-compass/glossary/fga/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"FGA\"}),\", or any combination, without paying for what isn't needed.\"]}),\"\\n\",n(t.p,{children:[\"Keto's native \",a(t.a,{href:\"/ciam-compass/glossary/zanzibar/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Zanzibar\"}),\"-style FGA is unique in this index. Among full-platform CIAM vendors, only Auth0 (with Auth0 FGA) and WorkOS (with WorkOS FGA) ship native Zanzibar; everything else asks teams to bring OpenFGA, Authzed, or Permify alongside. Ory ships it as a first-class component.\"]}),\"\\n\",n(t.p,{children:[\"Strict Apache 2.0 across all components avoids the licensing friction that complicates \",a(t.a,{href:\"/ciam-compass/vendors/fusionauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"FusionAuth\"}),\" procurement at strict-OSS-only buyers. EU headquarters and EU data residency on Ory Network is a meaningful trust signal for European buyers wary of US data jurisdiction.\"]}),\"\\n\",n(t.p,{children:[\"The community is large for an OSS CIAM, second only to \",a(t.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\", with active GitHub repos, regular releases, and a CNCF-adjacent ecosystem.\"]}),\"\\n\",a(t.h2,{id:\"where-ory-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-ory-hurts\",children:\"Where Ory hurts\"})}),\"\\n\",a(t.p,{children:'The component model imposes operational breadth. Running Kratos plus Hydra plus Keto plus Oathkeeper is four stateful services rather than one binary. Teams comfortable with Kubernetes find this fine; teams expecting a \"single auth deployment\" experience find it heavy. FusionAuth is the obvious lighter-ops alternative.'}),\"\\n\",n(t.p,{children:[\"B2B Organizations is less first-class than dedicated B2B vendors. Multi-tenancy works through Kratos schemas and project boundaries; the Admin Portal experience is not at \",a(t.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\"'s level.\"]}),\"\\n\",n(t.p,{children:[\"Risk decisioning, adaptive MFA, and bot defense are weak. For consumer apps facing serious account-takeover pressure, pair with \",a(t.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\" or external fraud signals.\"]}),\"\\n\",a(t.p,{children:\"DX is improving but the component decomposition imposes a learning curve. The four-services-conceptually-distinct model is right but takes time to internalize.\"}),\"\\n\",a(t.h2,{id:\"how-ory-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-ory-compares\",children:\"How Ory compares\"})}),\"\\n\",n(t.p,{children:[\"The closest open-source comparisons are \",a(t.a,{href:\"/ciam-compass/compare/keycloak-vs-ory/\",children:\"Keycloak vs Ory\"}),\" for the OSS-CIAM choice and \",a(t.a,{href:\"/ciam-compass/compare/ory-vs-fusionauth/\",children:\"Ory vs FusionAuth\"}),\" for the modern-OSS pick. For SaaS migrations, \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-ory/\",children:\"Auth0 vs Ory\"}),\" is a common question. For EU-sovereign managed CIAM, the closest commercial alternative is \",a(t.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\", which targets a similar buyer with a single-service architecture.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/ory/",
    "edit_path": "content/vendors/ory.mdx"
  },
  {
    "type": "vendor",
    "slug": "ping-identity",
    "name": "Ping Identity",
    "legal_name": "Ping Identity Holding Corp.",
    "parent_company": "Thoma Bravo (private equity)",
    "acquired_by": "Thoma Bravo (acquisition closed October 2022, $2.8B)",
    "website": "https://www.pingidentity.com",
    "docs_url": "https://docs.pingidentity.com",
    "pricing_url": "https://www.pingidentity.com/en/platform/pricing.html",
    "github_url": "https://github.com/pingidentity",
    "hq": "Denver, Colorado, USA",
    "founded": 2002,
    "status": "active",
    "funding": {
      "model": "pe-owned",
      "total_raised_usd": null,
      "last_round": {
        "stage": "acquired",
        "amount_usd": 2800000000,
        "year": 2022,
        "lead": "Thoma Bravo"
      },
      "investors": [
        "Thoma Bravo",
        "Vista Equity Partners"
      ],
      "profitable": true,
      "notes": "Vista Equity bought it in 2016, IPO'd it (NYSE: PING) in 2019; Thoma Bravo took it private for $2.8B in 2022 and merged ForgeRock into it.",
      "source": "https://press.pingidentity.com/2022-10-18-Thoma-Bravo-Completes-Acquisition-of-Ping-Identity"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration"
    ],
    "deployment": [
      "cloud-saas",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": "partial",
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "dotnet",
          "python",
          "go",
          "ios",
          "swift",
          "android",
          "kotlin"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "DaVinci flow orchestration + custom node SDK"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": "partial",
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": "High",
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust",
          "TrustArc"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "All deployments, Ping is enterprise quote-based",
      "notable_costs": [
        "PingOne SaaS, PingFederate (on-prem), and DaVinci orchestration are commercially separate products",
        "Per-user / per-MAU / per-feature pricing varies by deal; expect five-figure annual minimums",
        "Professional services often required for complex enterprise federation deployments"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 6000,
      "tco_at_500k_mau_estimate_usd_per_month": 18000,
      "tco_at_1m_mau_estimate_usd_per_month": 30000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "DaVinci visual flow orchestration is among the most capable in the market for complex enterprise auth journeys.",
      "FedRAMP High, PCI Level 1, HIPAA, full enterprise compliance footprint with on-prem deployment options.",
      "Deep enterprise federation breadth, supports the long tail of legacy IdPs, custom SAML edge cases, and federation chaining that hyperscaler CIAM struggles with.",
      "Strong governance, lifecycle, and consent capabilities suitable for regulated industries (banking, insurance, healthcare)."
    ],
    "limitations": [
      "Pricing opacity is real, no public pricing, five-figure annual minimums, professional-services-heavy onboarding.",
      "DX trails the developer-first tier substantially, slower iteration loops, heavier admin tooling, longer time-to-first-login.",
      "Product family is fragmented post-ForgeRock acquisition: PingOne, PingFederate, PingAccess, DaVinci, ForgeRock Identity Cloud.",
      "Vendor lock-in via DaVinci flows is significant once production journeys are deployed."
    ],
    "best_for": [
      "Large enterprise and public-sector workloads with complex federation and on-prem requirements",
      "Regulated industries requiring deep governance, consent, and lifecycle management",
      "Organizations with existing Ping or ForgeRock footprint"
    ],
    "not_for": [
      "Mid-market SaaS or startups prioritizing developer velocity",
      "Cost-sensitive consumer apps below the enterprise-quote threshold",
      "Teams that prefer transparent SaaS pricing"
    ],
    "migration_difficulty": {
      "inbound": 5,
      "outbound": 5
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Ping Identity Documentation",
        "url": "https://docs.pingidentity.com",
        "accessed": "2026-08-19"
      },
      {
        "title": "Ping Identity Pricing",
        "url": "https://www.pingidentity.com/en/platform/pricing.html",
        "accessed": "2026-08-19"
      },
      {
        "title": "Thoma Bravo Ping Identity acquisition (2022)",
        "url": "https://www.thomabravo.com",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Ping Identity remains the right CIAM choice for large enterprise and public-sector workloads with complex federation, on-prem requirements, or regulated-industry compliance baselines that hyperscaler CIAM cannot meet. DaVinci flow orchestration is genuinely capable for complex auth journeys. The trade-offs, opaque pricing, fragmented post-ForgeRock product family, heavy professional services, make Ping the wrong answer for everything below the enterprise-quote threshold. After the 2023 ForgeRock acquisition the combined product surface is broader but more confusing.",
    "faqs": [
      {
        "q": "What is the relationship between Ping Identity and ForgeRock?",
        "a": "Ping acquired ForgeRock in August 2023 (announced October 2022, closed 2023). Both companies were taken private by Thoma Bravo. The combined company sells both product families under the Ping brand; ForgeRock Identity Cloud and PingOne are still distinct platforms in 2026, with cross-product integration still in progress. New customers should evaluate which platform fits their workload rather than assuming convergence."
      },
      {
        "q": "Does Ping have a free tier?",
        "a": "No. All Ping deployments are enterprise quote-based, with five-figure annual minimums typical. For teams below that threshold, look at Auth0, WorkOS, or open-source alternatives."
      },
      {
        "q": "What is DaVinci?",
        "a": "DaVinci is Ping's visual flow orchestration product, a no-code editor for designing complex enterprise auth journeys with conditional logic, risk decisioning, and integration nodes. Among full-platform CIAM, DaVinci is the most mature visual orchestrator for enterprise scenarios; the trade-off is vendor lock-in once production flows are deployed."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-06-03",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:n,jsxs:i}=arguments[0];function _createMdxContent(t){const a={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return i(e,{children:[n(a.h2,{id:\"what-ping-identity-is\",children:n(a.a,{className:\"heading-anchor\",href:\"#what-ping-identity-is\",children:\"What Ping Identity is\"})}),\"\\n\",i(a.p,{children:[n(a.a,{href:\"/ciam-compass/vendors/ping-identity/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Ping Identity\"}),\" is one of the longest-running enterprise CIAM platforms, founded in 2002, public from 2019 to 2022, taken private by Thoma Bravo in October 2022 for $2.8B, and merged with ForgeRock in 2023. The product family covers PingOne (cloud), PingFederate (on-prem), PingAccess (web access management), and DaVinci (visual flow orchestration), plus the ForgeRock Identity Cloud platform that joined the portfolio post-acquisition. The buyer is typically a large enterprise or public-sector organization that needs deep federation, on-prem deployment, or a compliance baseline that hyperscaler CIAM cannot meet.\"]}),\"\\n\",n(a.h2,{id:\"where-ping-identity-wins\",children:n(a.a,{className:\"heading-anchor\",href:\"#where-ping-identity-wins\",children:\"Where Ping Identity wins\"})}),\"\\n\",i(a.p,{children:[\"The \",n(a.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\" depth is the structural advantage. Twenty-plus years of enterprise SAML / OIDC / WS-Federation work shows up as edge-case coverage that hyperscaler CIAM lacks, older PingFederate connections, custom XACML policies, federation chaining across legacy IdPs, and the kind of healthcare-and-banking federation patterns that took decades to standardize.\"]}),\"\\n\",i(a.p,{children:[\"DaVinci flow orchestration is genuinely capable. Among visual auth-journey builders, it sits at the top of the enterprise tier, handling conditional logic, risk decisioning, third-party integration nodes, and complex MFA step-up scenarios that smaller orchestrators cannot express. For regulated industries with multi-step \",n(a.a,{href:\"/ciam-compass/glossary/kyc/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"KYC\"}),\" / consent / verification journeys, DaVinci's expressiveness justifies the platform on its own.\"]}),\"\\n\",i(a.p,{children:[\"Compliance is full-stack: FedRAMP High, PCI DSS Level 1, HIPAA, ISO 27001/27018, with on-prem deployment options for jurisdictions or workloads that require it. Combined with \",n(a.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", preference center, and purpose-specific consent capabilities, uncommon in this index, Ping is appropriate for the most regulated buyer profiles.\"]}),\"\\n\",n(a.h2,{id:\"where-ping-identity-hurts\",children:n(a.a,{className:\"heading-anchor\",href:\"#where-ping-identity-hurts\",children:\"Where Ping Identity hurts\"})}),\"\\n\",n(a.p,{children:\"Pricing opacity is the lasting friction. No public pricing, five-figure annual minimums typical, professional-services-heavy onboarding. For mid-market or startup buyers, the vendor selection process alone consumes weeks before pricing is even visible.\"}),\"\\n\",i(a.p,{children:[\"DX trails the developer-first tier substantially. The admin tooling reflects a generation of enterprise IAM design rather than a developer-product mindset; SDK ergonomics are functional but not modern; iteration loops are slower than Auth0 / \",n(a.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" / Clerk by a noticeable margin.\"]}),\"\\n\",i(a.p,{children:[\"The product family is fragmented post-\",n(a.a,{href:\"/ciam-compass/vendors/forgerock/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"ForgeRock\"}),\" acquisition. PingOne, PingFederate, PingAccess, DaVinci, and ForgeRock Identity Cloud are still distinct platforms in 2026, with naming overlap that confuses new buyers. Cross-product integration is in progress but not yet seamless.\"]}),\"\\n\",n(a.p,{children:\"Migration in or out of Ping is a multi-quarter project in either direction. DaVinci flows in particular do not port cleanly to other vendors' orchestration models.\"}),\"\\n\",n(a.h2,{id:\"how-ping-identity-compares\",children:n(a.a,{className:\"heading-anchor\",href:\"#how-ping-identity-compares\",children:\"How Ping Identity compares\"})}),\"\\n\",i(a.p,{children:[\"The closest comparisons are \",n(a.a,{href:\"/ciam-compass/compare/auth0-vs-ping-identity/\",children:\"Auth0 vs Ping Identity\"}),\" for the modernization-vs-enterprise call and \",n(a.a,{href:\"/ciam-compass/compare/ping-identity-vs-forgerock/\",children:\"Ping Identity vs ForgeRock\"}),\" for the within-Ping-portfolio decision. For modern visual orchestration at lower cost, \",n(a.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"}),\" covers a similar use case for mid-market buyers. For deep federation at lower cost, \",n(a.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" and \",n(a.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" are the developer-first alternatives.\"]})]})}return{default:function(e={}){const{wrapper:i}=e.components||{};return i?n(i,{...e,children:n(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/ping-identity/",
    "edit_path": "content/vendors/ping-identity.mdx"
  },
  {
    "type": "vendor",
    "slug": "propelauth",
    "name": "PropelAuth",
    "legal_name": "PropelAuth, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.propelauth.com",
    "docs_url": "https://docs.propelauth.com",
    "pricing_url": "https://www.propelauth.com/pricing",
    "github_url": "https://github.com/PropelAuth",
    "hq": "San Francisco, California, USA",
    "founded": 2021,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 3090000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 2590000,
        "year": 2022,
        "lead": "Tiger Global"
      },
      "investors": [
        "Tiger Global",
        "Y Combinator",
        "8-Bit Capital",
        "Soma Capital"
      ],
      "profitable": null,
      "notes": "B2B auth (YC W22); $2.59M seed led by Tiger Global.",
      "source": "https://www.propelauth.com/post/propelauth-raises-2-59m-seed-round"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go",
          "rust",
          "dotnet",
          "java"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + JWT customization"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 150,
      "enterprise_quote_required_above": "Enterprise SSO connections and dedicated tenancy",
      "notable_costs": [
        "B2B-first pricing, Pro tier at $150/month covers most B2B SaaS at low scale",
        "Enterprise SSO connections billed per-connection",
        "Self-service Org admin UI included at all tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 600,
      "tco_at_500k_mau_estimate_usd_per_month": 2200,
      "tco_at_1m_mau_estimate_usd_per_month": 4200,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "B2B-first product surface with first-class Organizations, role hierarchies, and self-service Org admin UI.",
      "Strong React / Next.js DX with idiomatic hooks and component primitives.",
      "Includes a hosted self-service Org admin portal that end-customer admins use directly, similar to Frontegg's model at lower price.",
      "HIPAA-eligible, uncommon at this tier and price point."
    ],
    "limitations": [
      "Smaller community and ecosystem than Auth0 / Clerk.",
      "Compliance footprint outside HIPAA is narrow, no FedRAMP, ISO 27001, PCI DSS.",
      "No native FGA or adaptive MFA.",
      "Not optimized for B2C consumer flows; the product surface is B2B-shaped."
    ],
    "best_for": [
      "B2B SaaS startups that need Organizations + role hierarchies + self-service Org admin UI",
      "HIPAA-required B2B SaaS at startup or mid-market scale",
      "Teams comparing Frontegg and Clerk for B2B-first projects"
    ],
    "not_for": [
      "B2C consumer apps",
      "Workloads requiring FedRAMP, ISO 27001, or PCI DSS",
      "Authorization-heavy use cases requiring FGA"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-05-21",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "PropelAuth Pricing",
        "url": "https://www.propelauth.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "PropelAuth Documentation",
        "url": "https://docs.propelauth.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "PropelAuth is a B2B-first developer-CIAM with a hosted self-service Org admin portal at the level of Frontegg's, at materially lower price for startup-and-mid-market scale. HIPAA-eligibility is uncommon at this price tier. For B2B SaaS startups whose customers need role hierarchies and Org-admin UX, PropelAuth shortlists with Frontegg, Kinde, and Clerk.",
    "faqs": [
      {
        "q": "How does PropelAuth compare to Frontegg?",
        "a": "Both ship a self-service Admin Portal that end-customer admins use directly. Frontegg has the more mature product and broader feature surface; PropelAuth is materially cheaper for B2B SaaS at startup scale and includes HIPAA-eligibility at lower tiers. For startup-stage B2B SaaS, PropelAuth often wins on cost; for larger deployments, Frontegg's depth is the differentiator."
      },
      {
        "q": "Does PropelAuth support B2C apps?",
        "a": "Not optimized for it. The product surface assumes Organizations are the core data primitive; for B2C without organizations, look at Auth0, Stytch, Clerk, or MojoAuth."
      },
      {
        "q": "Is PropelAuth HIPAA-eligible?",
        "a": "Yes, with a signed BAA at qualifying tiers. Among developer-first B2B CIAM at this price, HIPAA support is the differentiator over Kinde and Clerk."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-21",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:a}=arguments[0];function _createMdxContent(o){const n={a:\"a\",h2:\"h2\",p:\"p\",...o.components};return a(e,{children:[r(n.h2,{id:\"what-propelauth-is\",children:r(n.a,{className:\"heading-anchor\",href:\"#what-propelauth-is\",children:\"What PropelAuth is\"})}),\"\\n\",a(n.p,{children:[r(n.a,{href:\"/ciam-compass/vendors/propelauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"PropelAuth\"}),\" launched in 2021 from San Francisco with a B2B-first thesis: ship a CIAM where Organizations, role hierarchies, and self-service Org admin tooling are first-class concepts rather than bolt-ons. The product line targets B2B SaaS startups that need to ship role-based access control and per-Org admin features without building an Admin Portal v1 in-house.\"]}),\"\\n\",r(n.h2,{id:\"where-propelauth-wins\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-propelauth-wins\",children:\"Where PropelAuth wins\"})}),\"\\n\",a(n.p,{children:[\"The hosted self-service Org admin UI is the differentiator at this price tier. End-customer admins log in directly to manage their own users, role assignments, and SSO connections, similar to \",r(n.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\"'s Admin Portal model but at a materially lower entry price. Strong React / Next.js DX with idiomatic hooks. HIPAA-eligibility is the compliance differentiator at this tier.\"]}),\"\\n\",r(n.h2,{id:\"where-propelauth-hurts\",children:r(n.a,{className:\"heading-anchor\",href:\"#where-propelauth-hurts\",children:\"Where PropelAuth hurts\"})}),\"\\n\",a(n.p,{children:[\"Smaller community than \",r(n.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" / Clerk; compliance footprint outside HIPAA is narrow; no native FGA or adaptive MFA; B2C-light by design. For consumer apps or for workloads requiring FedRAMP / ISO 27001 / PCI DSS, look elsewhere.\"]}),\"\\n\",r(n.h2,{id:\"how-propelauth-compares\",children:r(n.a,{className:\"heading-anchor\",href:\"#how-propelauth-compares\",children:\"How PropelAuth compares\"})}),\"\\n\",a(n.p,{children:[\"The closest comparisons are \",r(n.a,{href:\"/ciam-compass/compare/frontegg-vs-propelauth/\",children:\"Frontegg vs PropelAuth\"}),\", \",r(n.a,{href:\"/ciam-compass/compare/clerk-vs-propelauth/\",children:\"Clerk vs PropelAuth\"}),\", and \",r(n.a,{href:\"/ciam-compass/compare/auth0-vs-propelauth/\",children:\"Auth0 vs PropelAuth\"}),\". For modern B2B \",r(n.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" with even tighter scope, \",r(n.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" and \",r(n.a,{href:\"/ciam-compass/vendors/ssojet/\",children:\"SSOJet\"}),\" are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?r(a,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/propelauth/",
    "edit_path": "content/vendors/propelauth.mdx"
  },
  {
    "type": "vendor",
    "slug": "rownd",
    "name": "Rownd",
    "legal_name": "Rownd, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://rownd.io",
    "docs_url": "https://docs.rownd.io",
    "pricing_url": "https://rownd.io/pricing",
    "github_url": "https://github.com/rownd",
    "hq": "Atlanta, Georgia, USA",
    "founded": 2021,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 3790000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 2200000,
        "year": 2022,
        "lead": "Uncorrelated Ventures"
      },
      "investors": [
        "Uncorrelated Ventures",
        "Y Combinator",
        "Alumni Ventures",
        "Asymmetry Ventures"
      ],
      "profitable": null,
      "notes": "Adaptive sign-in / progressive auth; ~$3.8M raised across pre-seed and seed.",
      "source": "https://www.av.vc/blog/alumni-ventures-invests-in-rownd-a-game-changer-in-user-authentication"
    },
    "categories": [
      "developer-first-ciam",
      "b2c-ciam",
      "passwordless-specialist"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": false,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": "partial",
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "ios",
          "swift",
          "android",
          "kotlin",
          "flutter"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + custom UI components"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 1000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Volume + custom branding",
      "notable_costs": [
        "B2C consumer-app focus with embedded auth widgets",
        "Per-MAU pricing with consent management included",
        "Pre-built UI Hub component drops in across major frameworks"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 49,
      "tco_at_100k_mau_estimate_usd_per_month": 350,
      "tco_at_500k_mau_estimate_usd_per_month": 1400,
      "tco_at_1m_mau_estimate_usd_per_month": 2700,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Embedded auth widget (Hub) ships a complete user-account UX as a single component, fastest B2C drop-in in the index.",
      "First-class consent management and preference center for B2C consumer apps.",
      "Passwordless-first with native passkey support.",
      "HIPAA-eligible at qualifying tiers."
    ],
    "limitations": [
      "Very B2C-focused, no first-class B2B Organizations or Enterprise SSO.",
      "Compliance footprint outside HIPAA is narrow, no FedRAMP, ISO 27001, or PCI DSS.",
      "Smaller customer base and ecosystem than developer-first incumbents.",
      "No native FGA, no adaptive MFA, no managed bot defense."
    ],
    "best_for": [
      "B2C consumer apps that want a polished embedded auth UX with low integration effort",
      "Apps with serious GDPR consent management requirements",
      "Developer-tools and small-scale consumer apps"
    ],
    "not_for": [
      "B2B SaaS needing Organizations / SCIM / Enterprise SSO",
      "Workloads requiring FedRAMP or PCI DSS",
      "Multi-tenant complex authorization scenarios"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-04-01",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Rownd Pricing",
        "url": "https://rownd.io/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Rownd Documentation",
        "url": "https://docs.rownd.io",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Rownd is the embedded-B2C-auth-widget specialist in 2026, drop-in Hub component delivers a complete user-account UX with passwordless, consent management, and preference center in one. The product is intentionally B2C-narrow; for B2B SaaS or enterprise workloads, look elsewhere. For consumer apps that want polished out-of-box UX with serious GDPR consent capabilities, Rownd is a credible pick at lower cost than Auth0 with comparable B2C feature depth.",
    "faqs": [
      {
        "q": "What is the Rownd Hub?",
        "a": "An embedded UI component that drops into a B2C app and provides a complete user-account experience, login, registration, profile management, consent settings, preference center, without requiring the team to build the UX. Drop-in is faster than configuring the equivalent on Auth0 or Stytch's hosted login pages."
      },
      {
        "q": "Does Rownd handle B2B SaaS?",
        "a": "Not really, Rownd is B2C-focused. B2B Organizations and Enterprise SSO are partial; for B2B SaaS look at Auth0, WorkOS, MojoAuth, or Frontegg."
      },
      {
        "q": "Is Rownd HIPAA-eligible?",
        "a": "Yes at qualifying tiers with signed BAA. For HIPAA-required B2C consumer apps (healthcare patient portals, etc.), Rownd is one of the more affordable HIPAA-eligible options in the developer-first tier."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-01",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:n,jsxs:r}=arguments[0];function _createMdxContent(a){const s={a:\"a\",h2:\"h2\",p:\"p\",...a.components};return r(e,{children:[n(s.h2,{id:\"what-rownd-is\",children:n(s.a,{className:\"heading-anchor\",href:\"#what-rownd-is\",children:\"What Rownd is\"})}),\"\\n\",r(s.p,{children:[n(s.a,{href:\"/ciam-compass/vendors/rownd/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Rownd\"}),\" launched in 2021 in Atlanta with a B2C-embedded-widget-first thesis: most CIAM products require teams to build the user-account UX themselves on top of the auth APIs, which is unrelated work for B2C apps that just want login plus profile plus consent settings to work. Rownd's Hub component is a drop-in widget that ships the complete UX, login, profile, consent, preferences, as one component.\"]}),\"\\n\",n(s.h2,{id:\"where-rownd-wins\",children:n(s.a,{className:\"heading-anchor\",href:\"#where-rownd-wins\",children:\"Where Rownd wins\"})}),\"\\n\",r(s.p,{children:[\"Drop-in Hub UX is the fastest B2C auth integration in the index. First-class \",n(s.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\" and preference center suit GDPR-heavy consumer apps. Passwordless-first with native passkeys. HIPAA-eligibility is uncommon at this price tier.\"]}),\"\\n\",n(s.h2,{id:\"where-rownd-hurts\",children:n(s.a,{className:\"heading-anchor\",href:\"#where-rownd-hurts\",children:\"Where Rownd hurts\"})}),\"\\n\",r(s.p,{children:[\"B2C-narrow by design, there is no first-class B2B Organizations support, no SCIM Directory Sync, and Enterprise SAML is partial. Compliance footprint outside HIPAA is narrow with no FedRAMP, ISO 27001, or PCI DSS \",n(s.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\". The customer base and ecosystem are smaller than developer-first incumbents like Auth0 and Clerk; partner integrations and Stack Overflow coverage are correspondingly thinner. No native FGA, no adaptive MFA, and no managed bot defense.\"]}),\"\\n\",n(s.h2,{id:\"how-rownd-compares\",children:n(s.a,{className:\"heading-anchor\",href:\"#how-rownd-compares\",children:\"How Rownd compares\"})}),\"\\n\",r(s.p,{children:[\"The closest comparisons are \",n(s.a,{href:\"/ciam-compass/compare/auth0-vs-rownd/\",children:\"Auth0 vs Rownd\"}),\", \",n(s.a,{href:\"/ciam-compass/compare/stytch-vs-rownd/\",children:\"Stytch vs Rownd\"}),\", and \",n(s.a,{href:\"/ciam-compass/compare/clerk-vs-rownd/\",children:\"Clerk vs Rownd\"}),\" for the B2C-developer-first call. For B2B SaaS, look at \",n(s.a,{href:\"/ciam-compass/vendors/clerk/\",children:\"Clerk\"}),\", \",n(s.a,{href:\"/ciam-compass/vendors/frontegg/\",children:\"Frontegg\"}),\", or \",n(s.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" instead.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?n(r,{...e,children:n(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/rownd/",
    "edit_path": "content/vendors/rownd.mdx"
  },
  {
    "type": "vendor",
    "slug": "sap-customer-data-cloud",
    "name": "SAP Customer Data Cloud",
    "legal_name": "SAP Customer Data Cloud (SAP SE, formerly Gigya)",
    "parent_company": "SAP SE",
    "acquired_by": "SAP (Gigya acquisition closed 2017, $350M)",
    "website": "https://pages.community.sap.com/topics/customer-data-solutions",
    "docs_url": "https://help.sap.com/docs/SAP_CUSTOMER_DATA_CLOUD",
    "pricing_url": null,
    "github_url": null,
    "hq": "Walldorf, Germany / Mountain View, California, USA",
    "founded": 2006,
    "status": "active",
    "funding": {
      "model": "division",
      "total_raised_usd": null,
      "last_round": {
        "stage": "acquired",
        "amount_usd": 350000000,
        "year": 2017,
        "lead": "SAP"
      },
      "investors": [],
      "profitable": null,
      "notes": "Built on Gigya, which SAP (NYSE: SAP) acquired for ~$350M in 2017.",
      "source": "https://techcrunch.com/2017/09/24/sap-is-buying-identity-management-firm-gigya-for-350m/"
    },
    "categories": [
      "enterprise-ciam",
      "b2c-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": "partial",
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "ios",
          "swift",
          "android",
          "kotlin",
          "dotnet",
          "java"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "WebSDK + Site Extensions (proprietary JS) + Webhooks"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": "partial",
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust",
          "TrustArc"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": true,
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based via SAP sales",
      "notable_costs": [
        "SAP enterprise sales engagement; quote-based pricing",
        "Strong fit for existing SAP Commerce Cloud / SAP Customer Experience deployments",
        "Pricing typically among the highest in the index, six-figure annual minimums standard"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 8500,
      "tco_at_500k_mau_estimate_usd_per_month": 26000,
      "tco_at_1m_mau_estimate_usd_per_month": 45000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 3,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Twenty years of B2C CIAM experience (Gigya since 2006) with deep consent management, preference center, and progressive profiling.",
      "Tight integration with SAP Commerce Cloud and broader SAP Customer Experience portfolio.",
      "Comprehensive consent and privacy capabilities, purpose-specific consent, audit trails, regulatory alignment.",
      "Strong B2C customer data unification, the former Gigya CDP heritage shows."
    ],
    "limitations": [
      "Enterprise-only commercial structure with very high entry pricing.",
      "DX is dated; the SAP integration overlay adds complexity for non-SAP teams.",
      "Outside SAP ecosystem the integration story does not justify the cost.",
      "Sprawling SAP product naming creates evaluation complexity."
    ],
    "best_for": [
      "Existing SAP Commerce Cloud or SAP Customer Experience customers",
      "Large-enterprise B2C deployments with deep consent management requirements",
      "Regulated industries needing customer data unification plus CIAM"
    ],
    "not_for": [
      "Mid-market or startup deployments",
      "Greenfield projects without SAP ecosystem context",
      "Teams prioritizing developer velocity over SAP integration depth"
    ],
    "migration_difficulty": {
      "inbound": 5,
      "outbound": 5
    },
    "last_verified": "2026-04-07",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "SAP Customer Data Cloud product page",
        "url": "https://pages.community.sap.com/topics/customer-data-solutions",
        "accessed": "2026-04-22"
      },
      {
        "title": "SAP Customer Data Cloud documentation",
        "url": "https://help.sap.com/docs/SAP_CUSTOMER_DATA_CLOUD",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "SAP Customer Data Cloud (formerly Gigya) is the right CIAM choice for existing SAP Commerce Cloud or SAP Customer Experience customers, where the customer-data-unification heritage and SAP integration depth justify the platform. Twenty years of B2C consent management and preference center expertise are uncommon outside this product. Outside SAP shops, the DX gap and very high pricing make it the wrong choice for greenfield evaluation.",
    "faqs": [
      {
        "q": "What was Gigya?",
        "a": "Gigya was a B2C CIAM and customer data platform founded in 2006, acquired by SAP in 2017 for $350M, and rebranded as SAP Customer Data Cloud. The original product had strong social login, registration-as-a-service, and consent management; SAP retained the engineering and integrated it into the SAP Customer Experience portfolio."
      },
      {
        "q": "Does SAP Customer Data Cloud work outside SAP ecosystems?",
        "a": "Yes technically, protocols are standard. But the integration story and value proposition are materially stronger for existing SAP Commerce Cloud / SAP CX customers. Greenfield non-SAP projects evaluating against Auth0 or Stytch will usually find those alternatives more practical."
      },
      {
        "q": "What does SAP Customer Data Cloud cost?",
        "a": "Enterprise quote-based via SAP sales; typically among the highest pricing in the CIAM index, with six-figure annual minimums standard. For mid-market evaluation, the entry threshold is disqualifying."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-07",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(n){const t={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return r(e,{children:[a(t.h2,{id:\"what-sap-customer-data-cloud-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-sap-customer-data-cloud-is\",children:\"What SAP Customer Data Cloud is\"})}),\"\\n\",r(t.p,{children:[a(t.a,{href:\"/ciam-compass/vendors/sap-customer-data-cloud/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"SAP Customer Data Cloud\"}),\" is the customer identity platform within SAP's Customer Experience portfolio, originating as Gigya (founded 2006, acquired by SAP in 2017 for $350M). The product covers B2C CIAM, customer data unification (the former Gigya CDP heritage), consent management, preference center, and progressive profiling, sold primarily into existing SAP Commerce Cloud and SAP CX customers.\"]}),\"\\n\",a(t.h2,{id:\"where-sap-customer-data-cloud-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-sap-customer-data-cloud-wins\",children:\"Where SAP Customer Data Cloud wins\"})}),\"\\n\",r(t.p,{children:[\"Twenty years of B2C CIAM experience, uncommon depth on \",a(t.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", preference center, and customer data unification. Tight integration with SAP Commerce Cloud and the broader SAP Customer Experience portfolio. Comprehensive consent capabilities including purpose-specific consent and audit trails align with regulated-industry compliance.\"]}),\"\\n\",a(t.h2,{id:\"where-sap-customer-data-cloud-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-sap-customer-data-cloud-hurts\",children:\"Where SAP Customer Data Cloud hurts\"})}),\"\\n\",a(t.p,{children:\"Enterprise-only commercial structure with very high entry pricing. DX is dated and the SAP integration overlay adds complexity for non-SAP teams. Outside SAP ecosystem the integration story does not justify the cost.\"}),\"\\n\",a(t.h2,{id:\"how-sap-customer-data-cloud-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-sap-customer-data-cloud-compares\",children:\"How SAP Customer Data Cloud compares\"})}),\"\\n\",r(t.p,{children:[\"The closest comparisons are \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-sap-customer-data-cloud/\",children:\"Auth0 vs SAP Customer Data Cloud\"}),\" for the modernization-vs-legacy-enterprise call. For other legacy enterprise CIAM, \",a(t.a,{href:\"/ciam-compass/vendors/ping-identity/\",children:\"Ping Identity\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/forgerock/\",children:\"ForgeRock\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/oracle-idcs/\",children:\"Oracle IDCS\"}),\", and \",a(t.a,{href:\"/ciam-compass/vendors/akamai-identity-cloud/\",children:\"Akamai Identity Cloud\"}),\" are peers.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/sap-customer-data-cloud/",
    "edit_path": "content/vendors/sap-customer-data-cloud.mdx"
  },
  {
    "type": "vendor",
    "slug": "scalekit",
    "name": "Scalekit",
    "legal_name": "Scalekit Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.scalekit.com",
    "docs_url": "https://docs.scalekit.com",
    "pricing_url": "https://www.scalekit.com/pricing",
    "github_url": "https://github.com/scalekit-inc",
    "hq": "Bengaluru, India",
    "founded": 2023,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 5500000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 5500000,
        "year": 2024,
        "lead": "Together Fund"
      },
      "investors": [
        "Together Fund",
        "Z47"
      ],
      "profitable": null,
      "notes": "Auth stack for AI agents and B2B SaaS, founded by ex-Freshworks engineers; $5.5M seed (2024).",
      "source": "https://www.securityweek.com/scalekit-raises-5-5-million-to-secure-ai-agent-authentication/"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + JWT customization"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "per-organization",
      "free_tier": {
        "available": true,
        "mau_limit": 1000000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Volume B2B SSO connections",
      "notable_costs": [
        "Free auth tier at high MAU; pay primarily for Enterprise SSO connections per-organization",
        "Designed to compete with WorkOS and SSOJet on per-org pricing",
        "SCIM Directory Sync available at standard B2B tier"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 99,
      "tco_at_500k_mau_estimate_usd_per_month": 1100,
      "tco_at_1m_mau_estimate_usd_per_month": 2400,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "B2B SSO + SCIM at WorkOS-like pricing structure but with developer-first DX positioning.",
      "Generous free auth tier (large MAU allowance) with paid features billed per organization.",
      "Modern SDKs and idiomatic developer experience across major JS frameworks.",
      "Tightly scoped product surface, does not try to cover B2C consumer flows that aren't core."
    ],
    "limitations": [
      "Very young product (founded 2023), small customer base and limited battle-tested coverage.",
      "Compliance footprint is narrow, SOC 2 Type II only.",
      "Adaptive MFA, bot defense, and risk decisioning are weaker than incumbents.",
      "B2C-grade features intentionally absent, pure B2B-first scope."
    ],
    "best_for": [
      "Early-stage B2B SaaS that needs Enterprise SSO + SCIM at predictable per-org pricing",
      "Teams comparing WorkOS and SSOJet on price",
      "Apps where the buyer is the IT admin, not the consumer"
    ],
    "not_for": [
      "B2C consumer apps",
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Mid-to-large enterprise with complex federation requirements"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-05-20",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Scalekit Pricing",
        "url": "https://www.scalekit.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Scalekit Documentation",
        "url": "https://docs.scalekit.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Scalekit is a 2023-vintage entrant in the B2B-SSO-as-a-product segment, sitting alongside WorkOS and SSOJet but with even tighter focus on per-organization pricing for early-stage B2B SaaS. The product is young and the customer base is small, which limits battle-test coverage; pricing and DX are competitive with incumbents in the segment. Worth shortlisting alongside WorkOS and SSOJet for B2B-only SaaS at the early-stage tier.",
    "faqs": [
      {
        "q": "How does Scalekit compare to WorkOS and SSOJet?",
        "a": "All three target the same B2B-SSO segment. WorkOS is the most mature; SSOJet is mid-maturity with strong DX; Scalekit is the youngest entrant with the most aggressive pricing for early-stage SaaS. For teams choosing in 2026, WorkOS is the lower-risk pick; Scalekit and SSOJet compete on price and DX."
      },
      {
        "q": "Does Scalekit support B2C consumer auth?",
        "a": "Not really, Scalekit is B2B-first by design. For consumer apps, look at Auth0, Stytch, MojoAuth, or Descope."
      },
      {
        "q": "What does Scalekit cost at 100 enterprise customers?",
        "a": "Roughly $1,000–$2,000 per month at standard B2B tier with 100 organizations. Always confirm with a custom quote, volume discounts apply at this scale."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-20",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(n){const s={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return r(e,{children:[a(s.h2,{id:\"what-scalekit-is\",children:a(s.a,{className:\"heading-anchor\",href:\"#what-scalekit-is\",children:\"What Scalekit is\"})}),\"\\n\",r(s.p,{children:[a(s.a,{href:\"/ciam-compass/vendors/scalekit/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Scalekit\"}),\" launched in 2023 with a tight scope: ship Enterprise SSO and SCIM Directory Sync for B2B SaaS, with per-organization pricing and developer-first DX. The pitch is direct competition with WorkOS and SSOJet at slightly more aggressive entry pricing for early-stage SaaS that has just landed its first enterprise customer asking for SAML.\"]}),\"\\n\",a(s.h2,{id:\"where-scalekit-wins\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-scalekit-wins\",children:\"Where Scalekit wins\"})}),\"\\n\",r(s.p,{children:[\"Per-organization pricing structure with a generous free auth tier, early-stage B2B SaaS pays primarily for the Enterprise \",a(s.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" connections themselves, not the underlying user pool. Modern SDKs and a tightly-scoped product surface that does not try to cover unrelated B2C concerns.\"]}),\"\\n\",a(s.h2,{id:\"where-scalekit-hurts\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-scalekit-hurts\",children:\"Where Scalekit hurts\"})}),\"\\n\",r(s.p,{children:[\"Very young (2023 founding); small customer base; narrow compliance footprint (SOC 2 Type II only); intentionally B2C-light. For larger enterprise with complex \",a(s.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\" requirements or for B2C consumer apps, look elsewhere.\"]}),\"\\n\",a(s.h2,{id:\"how-scalekit-compares\",children:a(s.a,{className:\"heading-anchor\",href:\"#how-scalekit-compares\",children:\"How Scalekit compares\"})}),\"\\n\",r(s.p,{children:[\"The most relevant comparisons are \",a(s.a,{href:\"/ciam-compass/compare/scalekit-vs-workos/\",children:\"Scalekit vs WorkOS\"}),\", \",a(s.a,{href:\"/ciam-compass/compare/scalekit-vs-ssojet/\",children:\"Scalekit vs SSOJet\"}),\", and \",a(s.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" vs Scalekit. For B2C plus B2B from one platform, \",a(s.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" or \",a(s.a,{href:\"/ciam-compass/vendors/mojoauth/\",children:\"MojoAuth\"}),\" cover both segments.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/scalekit/",
    "edit_path": "content/vendors/scalekit.mdx"
  },
  {
    "type": "vendor",
    "slug": "slashid",
    "name": "SlashID",
    "legal_name": "SlashID, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://www.slashid.dev",
    "docs_url": "https://developer.slashid.dev",
    "pricing_url": "https://www.slashid.dev/",
    "github_url": "https://github.com/slashid",
    "hq": "London, United Kingdom",
    "founded": 2022,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 8830000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 8830000,
        "year": 2022,
        "lead": "Alven"
      },
      "investors": [
        "Alven",
        "DG Daiwa Ventures",
        "Headline",
        "Musha Ventures",
        "TQ Ventures"
      ],
      "profitable": null,
      "notes": "Composable identity/token platform founded by ex-offensive-security engineers; $8.83M seed (2022).",
      "source": "https://app.dealroom.co/companies/slashid"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam",
      "passwordless-specialist"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "b2c",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": false,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + custom auth flows"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": false,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 5000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Volume + dedicated tenancy",
      "notable_costs": [
        "Passwordless-first design, no passwords by default",
        "Per-MAU pricing with B2B Organizations included",
        "API-first product surface"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 49,
      "tco_at_100k_mau_estimate_usd_per_month": 350,
      "tco_at_500k_mau_estimate_usd_per_month": 1400,
      "tco_at_1m_mau_estimate_usd_per_month": 2700,
      "pricing_transparency_score": 4
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Passwordless-by-default, passwords are not part of the default flow, removing a class of legacy auth concerns.",
      "API-first design with idiomatic SDKs across major languages.",
      "EU-headquartered with EU data residency.",
      "Per-MAU pricing model favorable for early-stage SaaS."
    ],
    "limitations": [
      "Very young (2022), small customer base, limited battle-test coverage.",
      "Compliance footprint is narrow, SOC 2 only.",
      "No native FGA, no adaptive MFA, no managed bot defense.",
      "Smaller community than developer-first incumbents."
    ],
    "best_for": [
      "Greenfield apps committed to passwordless from day one",
      "Early-stage B2B SaaS that wants modern API-first auth",
      "EU-based products needing GDPR-first design"
    ],
    "not_for": [
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Apps requiring password fallback for legacy compatibility",
      "Mid-large enterprise federation needs"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-04-24",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "SlashID Pricing",
        "url": "https://www.slashid.dev/",
        "accessed": "2026-04-22"
      },
      {
        "title": "SlashID Developer Documentation",
        "url": "https://developer.slashid.dev",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "SlashID is a 2022-vintage passwordless-first developer CIAM with API-first design and EU-sovereign positioning. Smaller and younger than incumbents, with narrower compliance, but the passwordless-by-default thesis and clean API surface are competitive for greenfield projects committed to the model. Worth shortlisting alongside Stytch and Hanko for passwordless-first B2C and B2B SaaS at startup scale.",
    "faqs": [
      {
        "q": "What does SlashID's passwordless-by-default mean?",
        "a": "Passwords are not part of the default registration or login flow. Users authenticate via magic links, OTP, social login, or passkeys. Teams can opt into passwords if needed for legacy compatibility, but the design center assumes passwordless. This contrasts with most CIAM where passwords are the default and passkeys are added on top."
      },
      {
        "q": "How does SlashID compare to Stytch?",
        "a": "Both are passwordless-first developer CIAM. Stytch is more mature (2020 launch, Twilio-backed since 2025) with broader features and customer base; SlashID is younger, EU-headquartered, and more aggressively scoped to API-first design. For US-based customers, Stytch wins on maturity; for EU-sovereign or smaller-deployment use cases, SlashID is a credible pick."
      },
      {
        "q": "Is SlashID a fit for B2C consumer apps?",
        "a": "Yes for greenfield consumer apps committed to passwordless. The B2C feature set is more limited than Auth0 or Stytch on progressive profiling and fraud signals; for high-fraud-pressure consumer apps, look at Auth0 with Authsignal or Transmit Security."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-24",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:a,jsx:s,jsxs:e}=arguments[0];function _createMdxContent(r){const n={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return e(a,{children:[s(n.h2,{id:\"what-slashid-is\",children:s(n.a,{className:\"heading-anchor\",href:\"#what-slashid-is\",children:\"What SlashID is\"})}),\"\\n\",e(n.p,{children:[s(n.a,{href:\"/ciam-compass/vendors/slashid/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"SlashID\"}),\" launched in 2022 in London with a passwordless-by-default thesis: most CIAM ships passwords as the default and passkeys / passwordless on top, which preserves legacy attack surface. SlashID inverts this, the default flow is passwordless, with passwords available as opt-in for legacy compatibility. The product is API-first with clean SDK ergonomics and EU data residency.\"]}),\"\\n\",s(n.h2,{id:\"where-slashid-wins\",children:s(n.a,{className:\"heading-anchor\",href:\"#where-slashid-wins\",children:\"Where SlashID wins\"})}),\"\\n\",e(n.p,{children:[\"Passwordless-by-default removes a category of attack surface and aligns with the 2026 industry direction toward \",s(n.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-first auth. API-first design with idiomatic SDKs. EU-headquartered with EU data residency. Per-MAU pricing favorable for early-stage SaaS.\"]}),\"\\n\",s(n.h2,{id:\"where-slashid-hurts\",children:s(n.a,{className:\"heading-anchor\",href:\"#where-slashid-hurts\",children:\"Where SlashID hurts\"})}),\"\\n\",e(n.p,{children:[\"Very young, small customer base, narrow compliance (SOC 2 only). No native \",s(n.a,{href:\"/ciam-compass/glossary/fga/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"FGA\"}),\", no adaptive MFA, no managed bot defense. Smaller community than incumbents.\"]}),\"\\n\",s(n.h2,{id:\"how-slashid-compares\",children:s(n.a,{className:\"heading-anchor\",href:\"#how-slashid-compares\",children:\"How SlashID compares\"})}),\"\\n\",e(n.p,{children:[\"SlashID positions itself between \",s(n.a,{href:\"/ciam-compass/vendors/stytch/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stytch\"}),\" (more mature, US-headquartered, broader feature set) and Hanko (open-source, passkey-orchestration-first) on the passwordless-first spectrum. The differentiators are EU-sovereign data residency by default and a strict passwordless-by-default product design that Stytch and Hanko both opt into rather than enforce. The closest direct comparisons are \",s(n.a,{href:\"/ciam-compass/compare/stytch-vs-slashid/\",children:\"Stytch vs SlashID\"}),\", \",s(n.a,{href:\"/ciam-compass/compare/auth0-vs-slashid/\",children:\"Auth0 vs SlashID\"}),\", and \",s(n.a,{href:\"/ciam-compass/compare/hanko-vs-slashid/\",children:\"Hanko vs SlashID\"}),\". For broader OSS-leaning passwordless, \",s(n.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" is the alternative.\"]})]})}return{default:function(a={}){const{wrapper:e}=a.components||{};return e?s(e,{...a,children:s(_createMdxContent,{...a})}):_createMdxContent(a)}};",
    "permalink": "/vendors/slashid/",
    "edit_path": "content/vendors/slashid.mdx"
  },
  {
    "type": "vendor",
    "slug": "ssojet",
    "name": "SSOJet",
    "legal_name": "SSOJet, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://ssojet.com",
    "docs_url": "https://docs.ssojet.com",
    "pricing_url": "https://ssojet.com/pricing",
    "github_url": "https://github.com/ssojet",
    "hq": "Boston, Massachusetts, USA",
    "founded": 2025,
    "status": "active",
    "funding": {
      "model": "bootstrapped",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Early-stage enterprise-SSO startup (founded 2025); no disclosed institutional funding.",
      "source": "https://ssojet.com/"
    },
    "categories": [
      "developer-first-ciam",
      "enterprise-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": "partial",
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go",
          "ruby",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks + JWT customization + custom branding"
      },
      "security": {
        "bot_detection": "partial",
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "per-organization",
      "free_tier": {
        "available": true,
        "mau_limit": 100000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Volume B2B SSO connections and dedicated tenancy",
      "notable_costs": [
        "B2B SSO connections billed per-organization per-month at standard tier",
        "SCIM Directory Sync included in standard B2B tier",
        "Custom branding, audit logs, and webhook delivery included at all paid tiers"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 99,
      "tco_at_500k_mau_estimate_usd_per_month": 1200,
      "tco_at_1m_mau_estimate_usd_per_month": 2800,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "B2B SSO product surface that competes directly with WorkOS at materially lower price points for mid-market SaaS.",
      "Modern API design and idiomatic SDKs across major languages, strong DX without enterprise-vendor friction.",
      "Generous free tier (100k MAU on the auth product) plus per-organization billing keeps costs predictable through scale.",
      "Pre-integrated SAML / OIDC / SCIM for the major IdPs (Okta, Entra, Google Workspace, OneLogin, JumpCloud)."
    ],
    "limitations": [
      "Younger product than WorkOS or Auth0, smaller customer base, fewer Stack Overflow answers, less battle-tested at very large enterprise scale.",
      "B2C-grade features are limited, no first-class progressive profiling, weaker adaptive risk decisioning, no native bot detection at the level of Auth0 or Cognito.",
      "No FGA / Zanzibar-style fine-grained authorization.",
      "Compliance footprint is solid for B2B SaaS but lacks FedRAMP and direct PCI DSS attestation."
    ],
    "best_for": [
      "Mid-market B2B SaaS that needs Enterprise SSO + SCIM at predictable per-org pricing",
      "Teams comparing WorkOS but seeking a lower price point or different commercial structure",
      "Apps where the buyer is the IT admin and the customer is the organization",
      "B2B SaaS that wants the SSO + SCIM checklist without paying enterprise CIAM prices"
    ],
    "not_for": [
      "Pure B2C consumer apps with progressive profiling, bot defense, and adaptive MFA needs",
      "Workloads requiring FedRAMP or PCI DSS direct attestation",
      "Authorization-heavy apps requiring Zanzibar-style FGA at scale"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "SSOJet Pricing",
        "url": "https://ssojet.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "SSOJet Documentation",
        "url": "https://docs.ssojet.com",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "SSOJet is a 2026 enterprise-SSO pick for fast-growing B2B SaaS. Public pricing is connection-based and transparent (from $99/month on the public page, no MAU tax). That commercial shape is stronger for companies adding logos quickly than Auth0's MAU curve or a quote-only enterprise IdP. WorkOS remains the more mature Admin Portal. SSOJet is the pricing-transparency alternative. Not a B2C suite.",
    "faqs": [
      {
        "q": "How does SSOJet compare to WorkOS?",
        "a": "Similar product scope (B2B SSO, SCIM Directory Sync, audit logs, Organizations) at materially lower price points for mid-market SaaS. WorkOS has the larger customer base and more mature compliance footprint; SSOJet competes on pricing, DX, and per-organization billing structure. The two are the closest direct comparison in 2026."
      },
      {
        "q": "Does SSOJet support B2C consumer auth?",
        "a": "Yes for basic flows (magic links, social, OTP, passkeys), but the product is B2B-first and lacks the progressive profiling, advanced fraud signals, and adaptive risk decisioning that mature B2C platforms ship. For pure consumer apps, look at Auth0, Stytch, MojoAuth, or Descope."
      },
      {
        "q": "What does SSOJet cost at 100 enterprise customers?",
        "a": "At 100 B2B customers each with their own SSO connection, expect roughly $1,000–$2,000 per month at standard tier, materially less than WorkOS or Auth0 at the same scale. Always confirm with a custom quote at this tier; volume discounts apply."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified public pricing page. Editorial: enterprise-SSO pick for fast-growing B2B with transparent connection-based list price."
      },
      {
        "date": "2026-04-17",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(s){const t={a:\"a\",h2:\"h2\",p:\"p\",...s.components};return r(e,{children:[a(t.h2,{id:\"what-ssojet-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-ssojet-is\",children:\"What SSOJet is\"})}),\"\\n\",r(t.p,{children:[a(t.a,{href:\"/ciam-compass/vendors/ssojet/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"SSOJet\"}),\" is a 2025 entrant with a precise scope: ship Enterprise SSO and SCIM Directory Sync for B2B SaaS, fast, with modern DX and predictable per-organization pricing. Its product surface spans Organizations, audit logs, custom branding, JWT customization, and broad auth methods including passkeys, positioning it as a credible modern alternative to WorkOS for mid-market B2B SaaS that needs the enterprise checklist without enterprise-vendor pricing.\"]}),\"\\n\",a(t.h2,{id:\"where-ssojet-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-ssojet-wins\",children:\"Where SSOJet wins\"})}),\"\\n\",r(t.p,{children:[\"The B2B SSO economics are the headline. \",a(t.a,{href:\"/ciam-compass/vendors/workos/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"WorkOS\"}),\" prices SSO connections per-organization per-month; SSOJet's equivalent tier is materially lower at comparable feature footprint, with a 100k MAU free tier on the underlying auth product. For a B2B SaaS shipping enterprise customers, this changes the unit economics meaningfully, especially in the 20-to-200-customer range where Enterprise SSO is the gating sales requirement.\"]}),\"\\n\",r(t.p,{children:[\"The DX is modern in a way that matters. Idiomatic SDKs across major languages, a real CLI, Terraform provider, webhook delivery, JWT customization, none of the legacy enterprise CIAM friction. Pre-integrated SAML / \",a(t.a,{href:\"/ciam-compass/glossary/oidc/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"OIDC\"}),\" / SCIM for the major identity providers (Okta, Entra, Google Workspace, OneLogin, JumpCloud) means most customer onboarding is configuration, not engineering.\"]}),\"\\n\",r(t.p,{children:[\"For B2B-first SaaS the product surface aligns cleanly with what IT admins ask for in security questionnaires, Enterprise SSO yes, \",a(t.a,{href:\"/ciam-compass/glossary/scim/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SCIM\"}),\" yes, audit logs yes, SOC 2 yes, without the surrounding scope that B2C-broad CIAM vendors include and charge for.\"]}),\"\\n\",a(t.h2,{id:\"where-ssojet-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-ssojet-hurts\",children:\"Where SSOJet hurts\"})}),\"\\n\",r(t.p,{children:[\"Maturity is the lasting trade-off. SSOJet is a younger product than WorkOS, Auth0, or Frontegg, with a smaller customer base and less battle-tested behavior at very large enterprise scale. For mid-market SaaS this rarely matters; for buyers selling to Fortune 500 customers with hard compliance and \",a(t.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\" requirements, the longer track record of incumbents weighs.\"]}),\"\\n\",r(t.p,{children:[\"B2C-grade features are limited. No first-class \",a(t.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"progressive profiling\"}),\", weaker adaptive risk decisioning, and bot defense at the level of Auth0 or Cognito. SSOJet supports the consumer auth methods (magic links, social login, OTP, passkeys) but the product is not designed to be the primary CIAM for a high-volume consumer app.\"]}),\"\\n\",r(t.p,{children:[\"There's no Zanzibar-style FGA, no first-class \",a(t.a,{href:\"/ciam-compass/glossary/agentic-identity/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"agentic identity\"}),\" / MCP support, and no FedRAMP or PCI DSS direct attestation. For workloads requiring any of these, look elsewhere.\"]}),\"\\n\",a(t.h2,{id:\"how-ssojet-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-ssojet-compares\",children:\"How SSOJet compares\"})}),\"\\n\",r(t.p,{children:[\"The most direct comparison is \",a(t.a,{href:\"/ciam-compass/compare/ssojet-vs-workos/\",children:\"SSOJet vs WorkOS\"}),\" for the modern-B2B-CIAM call. For broader B2C + B2B coverage from a single platform, \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/mojoauth/\",children:\"MojoAuth\"}),\", and \",a(t.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\" are alternatives. For B2B with deeper enterprise federation breadth, \",a(t.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/frontegg/\",children:\"Frontegg\"}),\", and \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0 B2B\"}),\" remain the established choices.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/ssojet/",
    "edit_path": "content/vendors/ssojet.mdx"
  },
  {
    "type": "vendor",
    "slug": "stack-auth",
    "name": "Stack Auth",
    "legal_name": "Stack Auth, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://stack-auth.com",
    "docs_url": "https://docs.stack-auth.com",
    "pricing_url": "https://stack-auth.com/pricing",
    "github_url": "https://github.com/stack-auth/stack",
    "hq": "San Francisco, California, USA",
    "founded": 2023,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 500000,
      "last_round": {
        "stage": "pre-seed",
        "amount_usd": 500000,
        "year": 2024,
        "lead": "Y Combinator"
      },
      "investors": [
        "Y Combinator"
      ],
      "profitable": null,
      "notes": "Open-source Clerk alternative (Zurich); YC-backed pre-seed.",
      "source": "https://www.crunchbase.com/organization/stack-auth"
    },
    "categories": [
      "developer-first-ciam",
      "open-source-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2b-saas",
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Server functions + webhooks"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": "partial",
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Enterprise SSO and dedicated tenancy",
      "notable_costs": [
        "Generous free tier; paid plans start at $49/month",
        "Self-hosted Community edition is fully open source under MIT",
        "Pre-built Next.js components included in SDK"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 290,
      "tco_at_500k_mau_estimate_usd_per_month": 1300,
      "tco_at_1m_mau_estimate_usd_per_month": 2600,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Next.js-first DX with pre-built components that drop in faster than any other CIAM in 2026.",
      "MIT-licensed self-hostable Community edition, strict OSS without commercial-use clauses.",
      "Modern API design with idiomatic React server-component support.",
      "Built-in B2B Organizations and team management included from the free tier."
    ],
    "limitations": [
      "Very young (2023), small customer base, narrow battle-test coverage.",
      "Compliance footprint is minimal, SOC 2 Type II in progress, no other attestations.",
      "Smaller SDK breadth than Clerk, heavily focused on Next.js / React.",
      "Enterprise federation is partial; not yet at Auth0 / WorkOS level."
    ],
    "best_for": [
      "Next.js teams that want strict-OSS self-hostable CIAM with Clerk-grade DX",
      "Open-source projects requiring MIT-licensed auth",
      "Greenfield startups under 50k MAU"
    ],
    "not_for": [
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Teams not committed to Next.js / React",
      "Mid-to-large enterprise federation requirements"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-05-05",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Stack Auth Pricing",
        "url": "https://stack-auth.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Stack Auth Documentation",
        "url": "https://docs.stack-auth.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Stack Auth GitHub",
        "url": "https://github.com/stack-auth/stack",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Stack Auth is a 2023-vintage open-source alternative to Clerk for Next.js teams who want strict MIT licensing and self-host as an option. The DX is at the developer-first tier; the breadth of compliance, SDK coverage, and enterprise federation is not. For Next.js startups under 50k MAU prioritizing OSS guarantees, Stack Auth is a credible pick alongside Clerk and Kinde.",
    "faqs": [
      {
        "q": "How does Stack Auth compare to Clerk?",
        "a": "Both target Next.js / React DX excellence at the developer-first tier. Clerk is more mature, has broader features, and a larger customer base; Stack Auth is open-source under MIT with a self-host option Clerk does not offer. For OSS-mandated environments, Stack Auth wins; for production maturity, Clerk wins."
      },
      {
        "q": "Is Stack Auth fully open source?",
        "a": "Yes, MIT licensed across the codebase. Self-hosted Community edition is unrestricted at any scale. Stack Auth Cloud is the managed offering with paid tiers."
      },
      {
        "q": "Should I pick Stack Auth or Hanko?",
        "a": "Both are OSS-leaning developer-first CIAM. Hanko is passkey-first and EU-headquartered with strict GDPR posture; Stack Auth is Next.js-first and US-headquartered with broader auth method support. The pick depends on whether your binding constraint is passkey orchestration (Hanko) or Next.js DX with B2B Organizations (Stack Auth)."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-05",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:t}=arguments[0];function _createMdxContent(s){const r={a:\"a\",h2:\"h2\",p:\"p\",...s.components};return t(e,{children:[a(r.h2,{id:\"what-stack-auth-is\",children:a(r.a,{className:\"heading-anchor\",href:\"#what-stack-auth-is\",children:\"What Stack Auth is\"})}),\"\\n\",t(r.p,{children:[a(r.a,{href:\"/ciam-compass/vendors/stack-auth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Stack Auth\"}),' launched in 2023 with a focused thesis: open-source the Clerk-style developer experience under MIT. The product surface is Next.js-first, with pre-built React server components that deliver the fastest \"npm install to working login\" path among the OSS CIAM in this index. Both managed (Stack Auth Cloud) and self-hosted (MIT Community edition) deployments are available from the same codebase.']}),\"\\n\",a(r.h2,{id:\"where-stack-auth-wins\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-stack-auth-wins\",children:\"Where Stack Auth wins\"})}),\"\\n\",t(r.p,{children:[\"Next.js DX is at the level of \",a(r.a,{href:\"/ciam-compass/vendors/clerk/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Clerk\"}),\"'s, with strict MIT licensing, no commercial-use clauses or contributor licensing surprises. Self-hosting is unrestricted. Pre-built React server components and idiomatic hooks make first-login under 30 minutes for Next.js teams.\"]}),\"\\n\",a(r.h2,{id:\"where-stack-auth-hurts\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-stack-auth-hurts\",children:\"Where Stack Auth hurts\"})}),\"\\n\",t(r.p,{children:[\"Very young, small customer base, narrow battle-test coverage. Compliance is in progress only. SDK breadth is heavily Next.js / React focused; teams not on that stack should look elsewhere. Enterprise \",a(r.a,{href:\"/ciam-compass/glossary/federation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"federation\"}),\" is partial; for serious B2B SAML edge cases, look at Auth0 or WorkOS.\"]}),\"\\n\",a(r.h2,{id:\"how-stack-auth-compares\",children:a(r.a,{className:\"heading-anchor\",href:\"#how-stack-auth-compares\",children:\"How Stack Auth compares\"})}),\"\\n\",t(r.p,{children:[\"The closest comparisons are \",a(r.a,{href:\"/ciam-compass/compare/clerk-vs-stack-auth/\",children:\"Clerk vs Stack Auth\"}),\", \",a(r.a,{href:\"/ciam-compass/compare/hanko-vs-stack-auth/\",children:\"Hanko vs Stack Auth\"}),\", and \",a(r.a,{href:\"/ciam-compass/compare/stack-auth-vs-betterauth/\",children:\"Stack Auth vs BetterAuth\"}),\" for the OSS-Next.js-first decision. For broader OSS CIAM, \",a(r.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\", \",a(r.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\", and \",a(r.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?a(t,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/stack-auth/",
    "edit_path": "content/vendors/stack-auth.mdx"
  },
  {
    "type": "vendor",
    "slug": "strivacity",
    "name": "Strivacity",
    "legal_name": "Strivacity, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://strivacity.com",
    "docs_url": "https://docs.strivacity.com",
    "pricing_url": null,
    "github_url": "https://github.com/strivacity",
    "hq": "Reston, Virginia, USA",
    "founded": 2019,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 31300000,
      "last_round": {
        "stage": "series-b",
        "amount_usd": 20000000,
        "year": 2023,
        "lead": "SignalFire"
      },
      "investors": [
        "Ten Eleven Ventures",
        "SignalFire",
        "Toba Capital"
      ],
      "profitable": null,
      "notes": "CIAM founded by ex-Janrain/SailPoint leaders; $9.3M Series A (2021) and a $20M round led by SignalFire (2023).",
      "source": "https://www.strivacity.com/press/strivacity-announces-20-million-in-new-funding-to-modernize-customer-sign-in-experiences-and-security"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration",
      "b2c-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2c",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "python",
          "go",
          "dotnet",
          "java"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Journey Builder visual orchestration + custom hooks"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust"
        ]
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": true,
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Enterprise quote-based",
      "notable_costs": [
        "Per-MAU enterprise pricing typical for the segment",
        "Journey Builder visual orchestration included at standard tier",
        "Founded by ForgeRock and Microsoft alumni, enterprise-pedigree positioning"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 4500,
      "tco_at_500k_mau_estimate_usd_per_month": 14000,
      "tco_at_1m_mau_estimate_usd_per_month": 24000,
      "pricing_transparency_score": 1
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "Modern enterprise CIAM positioned between developer-first DX and traditional enterprise platforms (Ping, ForgeRock).",
      "Journey Builder visual orchestration is genuinely capable and easier to onboard than DaVinci or Authentication Trees.",
      "Strong consent management and preference center, uncommon outside the largest enterprise incumbents.",
      "Founded by ForgeRock and Microsoft identity alumni, credibility in enterprise security buying."
    ],
    "limitations": [
      "Enterprise-only commercial structure with no public pricing.",
      "Smaller customer base than incumbent enterprise CIAM.",
      "No FedRAMP authorization.",
      "Newer than the legacy enterprise tier with corresponding maturity gap on edge-case federation."
    ],
    "best_for": [
      "Mid-large enterprise wanting modern CIAM with orchestration but not Ping / ForgeRock pricing",
      "Regulated B2C deployments needing consent management plus passkey orchestration",
      "Enterprises modernizing from legacy identity stacks"
    ],
    "not_for": [
      "Mid-market SaaS or startups without enterprise-quote tolerance",
      "Workloads requiring FedRAMP authorization",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-05-11",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Strivacity overview",
        "url": "https://strivacity.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Strivacity documentation",
        "url": "https://docs.strivacity.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Strivacity is a modern enterprise CIAM that sits between developer-first products and the legacy enterprise tier, Journey Builder visual orchestration, consent management depth, and modern API surface, with founders carrying ForgeRock and Microsoft credibility. For mid-large enterprises that find Ping / ForgeRock pricing and complexity excessive but Auth0 insufficient on consent and orchestration, Strivacity is a credible alternative. The trade-offs are smaller customer base and no FedRAMP.",
    "faqs": [
      {
        "q": "How is Strivacity different from Ping or ForgeRock?",
        "a": "Strivacity is materially newer (2019), with a more modern API surface and DX, simpler Journey Builder orchestration, and faster onboarding. The legacy incumbents have deeper federation breadth and longer track records; Strivacity wins on velocity and onboarding cost for mid-large enterprise that doesn't need legacy IdP edge cases."
      },
      {
        "q": "What does Strivacity cost?",
        "a": "Enterprise quote-based with no public pricing. Expected positioning is below Ping / ForgeRock and above Auth0 for comparable enterprise scale. Mid-market teams should look at Auth0, Descope, or MojoAuth instead."
      },
      {
        "q": "Does Strivacity support B2C consumer flows?",
        "a": "Yes, strong B2C support with progressive profiling, consent management, and preference center. Among the more B2C-mature platforms in the enterprise tier."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-11",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(t){const i={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return r(e,{children:[a(i.h2,{id:\"what-strivacity-is\",children:a(i.a,{className:\"heading-anchor\",href:\"#what-strivacity-is\",children:\"What Strivacity is\"})}),\"\\n\",r(i.p,{children:[\"Strivacity launched in 2019 with founders from ForgeRock and Microsoft and a thesis that the enterprise CIAM tier needed a modern alternative, one that delivered enterprise depth (\",a(i.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", orchestration, federation) with developer-first DX and onboarding velocity. The product is cloud-only SaaS with Journey Builder as the central orchestration surface.\"]}),\"\\n\",a(i.h2,{id:\"where-strivacity-wins\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-strivacity-wins\",children:\"Where Strivacity wins\"})}),\"\\n\",r(i.p,{children:[\"Modern API surface and DX positioned between developer-first and legacy enterprise. Journey Builder visual orchestration is genuinely capable and faster to onboard than DaVinci or \",a(i.a,{href:\"/ciam-compass/glossary/authentication/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authentication\"}),\" Trees. Consent management and preference center depth is uncommon outside the largest enterprise incumbents. Founder credibility from ForgeRock / Microsoft eases enterprise sales conversations.\"]}),\"\\n\",a(i.h2,{id:\"where-strivacity-hurts\",children:a(i.a,{className:\"heading-anchor\",href:\"#where-strivacity-hurts\",children:\"Where Strivacity hurts\"})}),\"\\n\",r(i.p,{children:[\"Enterprise-only commercial structure with opaque pricing. Smaller customer base than incumbent enterprise CIAM. No FedRAMP \",a(i.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\". Newer than the legacy tier with corresponding gaps on edge-case federation.\"]}),\"\\n\",a(i.h2,{id:\"how-strivacity-compares\",children:a(i.a,{className:\"heading-anchor\",href:\"#how-strivacity-compares\",children:\"How Strivacity compares\"})}),\"\\n\",r(i.p,{children:[\"The closest comparisons are \",a(i.a,{href:\"/ciam-compass/compare/auth0-vs-strivacity/\",children:\"Auth0 vs Strivacity\"}),\", \",a(i.a,{href:\"/ciam-compass/compare/ping-identity-vs-strivacity/\",children:\"Ping Identity vs Strivacity\"}),\", and \",a(i.a,{href:\"/ciam-compass/compare/strivacity-vs-descope/\",children:\"Strivacity vs Descope\"}),\" for the modern-orchestration call. For self-hosted alternatives in the same space, \",a(i.a,{href:\"/ciam-compass/vendors/wso2-is/\",children:\"WSO2 IS\"}),\" is the legacy OSS option.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/strivacity/",
    "edit_path": "content/vendors/strivacity.mdx"
  },
  {
    "type": "vendor",
    "slug": "stytch",
    "name": "Stytch",
    "legal_name": "Stytch, Inc.",
    "parent_company": "Twilio",
    "acquired_by": "Twilio (announced 30 October 2025, closed 14 November 2025)",
    "website": "https://stytch.com",
    "docs_url": "https://stytch.com/docs",
    "pricing_url": "https://stytch.com/pricing",
    "github_url": "https://github.com/stytchauth",
    "hq": "San Francisco, California, USA",
    "founded": 2020,
    "status": "acquired",
    "funding": {
      "model": "public",
      "total_raised_usd": 146000000,
      "last_round": {
        "stage": "series-b",
        "amount_usd": 90000000,
        "year": 2021,
        "lead": "Coatue"
      },
      "investors": [
        "Coatue",
        "Benchmark",
        "Thrive Capital",
        "Index Ventures"
      ],
      "profitable": null,
      "notes": "Raised $146M as an independent passwordless startup at a $1B valuation; acquired by Twilio in October 2025 (terms undisclosed).",
      "source": "https://stytch.com/blog/announcing-series-b/"
    },
    "categories": [
      "developer-first-ciam",
      "passwordless-specialist",
      "b2c-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "ruby"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + JWT customization"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 99,
      "enterprise_quote_required_above": "Enterprise SSO and B2B Organizations",
      "notable_costs": [
        "Consumer (B2C) and B2B products are priced separately",
        "Enhanced fraud / device fingerprinting gated to higher tiers",
        "Enterprise SSO connections billed per-connection"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 99,
      "tco_at_100k_mau_estimate_usd_per_month": 950,
      "tco_at_500k_mau_estimate_usd_per_month": 3200,
      "tco_at_1m_mau_estimate_usd_per_month": 6200,
      "pricing_transparency_score": 4
    },
    "dx_score": 5,
    "docs_quality": 5,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Best-in-class passkey orchestration in 2026, conditional UI default, device-aware prompting, recovery flow design baked in.",
      "Distinct B2C and B2B products with appropriate models for each (B2B Organizations, B2C consumer flows).",
      "Modern API surface with strong TypeScript typing across SDKs.",
      "Acquired by Twilio in 2025, which expanded the product into Twilio's communications stack while keeping the developer-first DX."
    ],
    "limitations": [
      "No first-class FGA / Zanzibar-style fine-grained authorization, pair with OpenFGA, Authzed, or Permify for complex authz.",
      "Compliance footprint is narrower than Auth0, no FedRAMP, PCI DSS not directly available.",
      "Smaller SDK breadth than Auth0 (ecosystem effect, not technical limitation).",
      "Adaptive MFA decisioning is less mature than Auth0 or Descope's orchestration layer."
    ],
    "best_for": [
      "Consumer apps prioritizing high passkey adoption out of the box",
      "B2B SaaS teams wanting B2B Organizations + Enterprise SSO without paying enterprise prices below 100k MAU",
      "Teams switching off Auth0 for cost reasons under 500k MAU"
    ],
    "not_for": [
      "Workloads requiring FedRAMP or extensive compliance attestations",
      "Authorization-heavy use cases needing Zanzibar-style FGA",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Stytch Pricing",
        "url": "https://stytch.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "Stytch Documentation",
        "url": "https://stytch.com/docs",
        "accessed": "2026-08-19"
      },
      {
        "title": "Twilio acquires Stytch (October 30, 2025), Deepak Gupta's analysis",
        "url": "https://guptadeepak.com/twilio-stytch-developer-ciam-auth0-alternatives-2025/",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "Stytch is the strongest passkey-first CIAM in 2026 by orchestration quality, not raw feature count. Twilio acquired it on October 30, 2025; the product runs as a Twilio subsidiary with its own API surface, SDK family, and pricing, distinct from Twilio Verify. Post-acquisition the platform combines Stytch's modern auth with Twilio's communications infrastructure, repositioning it as a credible Auth0 alternative for developer-focused teams. Below 500k MAU the case is strong for both B2C and B2B SaaS; beyond that, gaps on FedRAMP, FGA, and adaptive MFA depth narrow it.",
    "faqs": [
      {
        "q": "Was Stytch acquired by Twilio?",
        "a": "Yes, Twilio announced the acquisition on October 30, 2025. Stytch operates as a Twilio subsidiary; the product line, DX, and pricing model remain separate from Twilio Verify, with no codebase or API merge. See Deepak Gupta's analysis at guptadeepak.com/twilio-stytch-developer-ciam-auth0-alternatives-2025/ for the post-acquisition positioning."
      },
      {
        "q": "How does Stytch's passkey adoption compare to other vendors?",
        "a": "Stytch customers consistently report 30–50%+ passkey adoption within six months of launch, materially above the 5–10% baseline seen on vendors without device-aware prompting. The orchestration layer is the differentiator, see the passwordless guide for what \"orchestration quality\" means."
      },
      {
        "q": "Does Stytch have B2B Organizations like Auth0?",
        "a": "Yes. Stytch B2B is a separate product surface with first-class Organizations, Enterprise SSO connections, and SCIM. Feature parity with Auth0 Organizations for most B2B SaaS use cases under 100k MAU."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-05-08",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      },
      {
        "date": "2026-05-08",
        "summary": "Updated to reflect Twilio acquisition (October 30, 2025). Status changed to 'acquired'; verdict and FAQ rewritten with post-acquisition positioning. Sources updated with link to Deepak Gupta's analysis of the deal."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(t){const r={a:\"a\",em:\"em\",h2:\"h2\",p:\"p\",...t.components};return s(e,{children:[a(r.h2,{id:\"what-stytch-is\",children:a(r.a,{className:\"heading-anchor\",href:\"#what-stytch-is\",children:\"What Stytch is\"})}),\"\\n\",s(r.p,{children:[\"Stytch launched in 2020 as a passwordless-first CIAM API, and shipped its B2B product line in 2022. Twilio acquired it in 2025; the product remains a separate API surface from Twilio Verify, with its own SDK family, docs, and pricing. The buyer is typically an engineering team that wants modern \",a(r.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"passkey\"}),\"-first auth without building the orchestration layer themselves.\"]}),\"\\n\",a(r.h2,{id:\"where-stytch-wins\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-stytch-wins\",children:\"Where Stytch wins\"})}),\"\\n\",s(r.p,{children:[\"The passkey orchestration story is the differentiator. Most CIAM vendors have shipped \",a(r.a,{href:\"/ciam-compass/glossary/webauthn/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"WebAuthn\"}),\" support; few have shipped the \",a(r.em,{children:\"prompting\"}),\" layer that decides when to ask, what to do when a user has no passkey on this device, and how to handle recovery. Stytch's defaults are aggressive in the right direction, \",a(r.a,{href:\"/ciam-compass/glossary/conditional-ui/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"conditional UI\"}),\" on by default, device-aware prompting, recovery flows that don't backdoor MFA, and customers consistently land at 30–50% passkey adoption inside six months.\"]}),\"\\n\",s(r.p,{children:[\"The B2C / B2B split is also more honest than competitors who try to serve both segments with one model. B2C customers get \",a(r.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"progressive profiling\"}),\", magic links, and consumer-grade fraud signals; B2B customers get Organizations, Enterprise SSO with SAML / OIDC, and SCIM provisioning. Pricing the two product lines separately reflects that the buyer journey is different.\"]}),\"\\n\",a(r.h2,{id:\"where-stytch-hurts\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-stytch-hurts\",children:\"Where Stytch hurts\"})}),\"\\n\",s(r.p,{children:[a(r.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authorization\"}),\" is the weakest leg. There's no native Zanzibar-style FGA engine, and ABAC support is partial. Teams with serious authorization needs end up running OpenFGA, Authzed, or Permify alongside, which is fine but adds a vendor.\"]}),\"\\n\",s(r.p,{children:[\"Compliance breadth is narrower than \",a(r.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\", no FedRAMP, PCI DSS not directly attested, ISO 27001 yes. For consumer apps and most B2B SaaS this is fine; for federal workloads it isn't.\"]}),\"\\n\",s(r.p,{children:[\"Adaptive MFA decisioning is less mature than \",a(r.a,{href:\"/ciam-compass/vendors/descope/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Descope\"}),\"'s no-code flow editor or Auth0's Actions-driven adaptive policies. Stytch's adaptive layer is improving but in 2026 it's still primarily rule-based rather than learned.\"]}),\"\\n\",a(r.h2,{id:\"how-stytch-compares\",children:a(r.a,{className:\"heading-anchor\",href:\"#how-stytch-compares\",children:\"How Stytch compares\"})}),\"\\n\",s(r.p,{children:[\"For B2C passkey-first apps, \",a(r.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" and \",a(r.a,{href:\"/ciam-compass/vendors/corbado/\",children:\"Corbado\"}),\" are the closest competitors on adoption quality. For B2B \",a(r.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" breadth, \",a(r.a,{href:\"/ciam-compass/vendors/workos/\",children:\"WorkOS\"}),\" and \",a(r.a,{href:\"/ciam-compass/vendors/frontegg/\",children:\"Frontegg\"}),\" are alternatives. For broader compliance footprint, \",a(r.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" remains ahead. The most common direct comparison is \",a(r.a,{href:\"/ciam-compass/compare/auth0-vs-stytch/\",children:\"Auth0 vs Stytch\"}),\" and \",a(r.a,{href:\"/ciam-compass/compare/stytch-vs-descope/\",children:\"Stytch vs Descope\"}),\".\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/stytch/",
    "edit_path": "content/vendors/stytch.mdx"
  },
  {
    "type": "vendor",
    "slug": "supabase-auth",
    "name": "Supabase Auth",
    "legal_name": "Supabase Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://supabase.com/auth",
    "docs_url": "https://supabase.com/docs/guides/auth",
    "pricing_url": "https://supabase.com/pricing",
    "github_url": "https://github.com/supabase/auth",
    "hq": "San Francisco, California, USA / Singapore",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 544000000,
      "last_round": {
        "stage": "growth",
        "amount_usd": 100000000,
        "year": 2025,
        "lead": "Accel"
      },
      "investors": [
        "Coatue",
        "Accel",
        "Peak XV Partners",
        "Craft Ventures",
        "Y Combinator",
        "Felicis"
      ],
      "profitable": null,
      "notes": "Auth is one module of the open-source Postgres platform Supabase, which raised $100M at a $5B valuation in Oct 2025.",
      "source": "https://techcrunch.com/2025/10/03/supabase-nabs-5b-valuation-four-months-after-hitting-2b/"
    },
    "categories": [
      "cloud-native-ciam",
      "open-source-ciam",
      "developer-first-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2c",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": "partial",
        "sso_oidc": "partial",
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": "partial",
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": false,
        "multi_tenancy": "partial",
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "svelte",
          "flutter",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "dart"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "PostgreSQL Row-Level Security + Edge Functions for Auth Hooks"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 50000
      },
      "paid_starts_at_usd": 25,
      "enterprise_quote_required_above": "Team / Enterprise plans for advanced features and SLAs",
      "notable_costs": [
        "Auth is bundled with Supabase platform, Postgres + Auth + Realtime + Storage in one",
        "Free tier covers 50k MAU on Auth",
        "Self-hosted GoTrue (the Auth service) is Apache 2.0, free at any scale",
        "Auth is part of broader Supabase platform pricing rather than separately metered"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 25,
      "tco_at_100k_mau_estimate_usd_per_month": 100,
      "tco_at_500k_mau_estimate_usd_per_month": 600,
      "tco_at_1m_mau_estimate_usd_per_month": 1500,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 5,
    "community_size": "huge",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Bundled with PostgreSQL platform, Auth integrates with Row-Level Security policies for fine-grained data access without a separate authz vendor.",
      "Apache 2.0 self-hosted GoTrue (the underlying Auth service), full OSS optionality.",
      "Generous free tier and predictable platform pricing across the bundle.",
      "Excellent docs and a rapidly-growing community across the broader Supabase ecosystem."
    ],
    "limitations": [
      "B2C-first, no first-class Organizations, weak SAML / OIDC, no SCIM.",
      "Tied to PostgreSQL, Auth on Supabase requires Supabase's Postgres, not arbitrary databases.",
      "No native FGA, no adaptive MFA, no managed bot defense.",
      "Compliance footprint is solid for B2B SaaS but lacks FedRAMP and PCI DSS direct attestation."
    ],
    "best_for": [
      "Apps already on Supabase platform that benefit from PostgreSQL + Auth + RLS integration",
      "B2C consumer apps and developer-tools at the 10k–500k MAU range",
      "Teams that want OSS GoTrue self-host with Postgres-native authz patterns"
    ],
    "not_for": [
      "B2B SaaS needing Organizations / SCIM / Enterprise SSO",
      "Workloads requiring FedRAMP or PCI DSS",
      "Apps with complex authorization needing FGA at scale"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-04-06",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Supabase Auth documentation",
        "url": "https://supabase.com/docs/guides/auth",
        "accessed": "2026-04-22"
      },
      {
        "title": "Supabase pricing",
        "url": "https://supabase.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "GoTrue (Supabase Auth) GitHub",
        "url": "https://github.com/supabase/auth",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Supabase Auth is the right CIAM choice for B2C apps and developer-tools already on the Supabase platform, Auth integrates with PostgreSQL Row-Level Security in a way that no other CIAM matches, removing the need for a separate authz vendor for many use cases. The trade-off is a B2C-first product without first-class B2B Organizations or SAML; for B2B SaaS, look elsewhere. For greenfield Supabase-native apps, Supabase Auth is one of the strongest picks at low cost.",
    "faqs": [
      {
        "q": "What is GoTrue?",
        "a": "GoTrue is the underlying Apache 2.0-licensed Auth service that powers Supabase Auth. It's a Go-based JWT-issuing server that originated as a Netlify project, forked and developed further by Supabase. Self-hosting GoTrue is unrestricted; Supabase Cloud runs it as part of the platform."
      },
      {
        "q": "How does Supabase Auth integrate with PostgreSQL Row-Level Security?",
        "a": "JWT claims issued by Supabase Auth are accessible inside PostgreSQL RLS policies (via auth.uid() and auth.jwt()), which means data access can be authorized at the database level using the authenticated user's identity. This composes auth and authz in a way that no other CIAM in this index matches as natively."
      },
      {
        "q": "Can I use Supabase Auth without the rest of Supabase?",
        "a": "Yes via self-hosted GoTrue, but you lose the PostgreSQL RLS integration that is the main differentiator. Most teams that pick Supabase Auth do so as part of choosing the broader Supabase platform."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-06",
        "summary": "Editorial review: capability matrix and TCO bands confirmed against the latest vendor documentation."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(r){const t={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return s(e,{children:[a(t.h2,{id:\"what-supabase-auth-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-supabase-auth-is\",children:\"What Supabase Auth is\"})}),\"\\n\",s(t.p,{children:[\"Supabase Auth (originally GoTrue, forked from Netlify) is the auth component of the Supabase platform, a PostgreSQL-centric backend-as-a-service launched in 2020. The differentiator is integration with PostgreSQL Row-Level Security: JWT claims issued by Auth are accessible inside database policies, which means \",a(t.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" decisions can happen at the database layer using the authenticated user's identity. This composition is unique in the index.\"]}),\"\\n\",a(t.h2,{id:\"where-supabase-auth-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-supabase-auth-wins\",children:\"Where Supabase Auth wins\"})}),\"\\n\",a(t.p,{children:\"PostgreSQL RLS integration removes the need for a separate authz layer for many use cases. Apache 2.0 self-hostable GoTrue. Generous free tier as part of the broader platform. Excellent docs and a large community across the Supabase ecosystem.\"}),\"\\n\",a(t.h2,{id:\"where-supabase-auth-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-supabase-auth-hurts\",children:\"Where Supabase Auth hurts\"})}),\"\\n\",s(t.p,{children:[\"B2C-first by design, no first-class Organizations, weak SAML, no SCIM. Tied to PostgreSQL, \",a(t.a,{href:\"/ciam-compass/vendors/supabase-auth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Supabase Auth\"}),\" assumes Postgres. Compliance footprint lacks FedRAMP and PCI DSS. For B2B SaaS or for enterprise federation, look elsewhere.\"]}),\"\\n\",a(t.h2,{id:\"how-supabase-auth-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-supabase-auth-compares\",children:\"How Supabase Auth compares\"})}),\"\\n\",s(t.p,{children:[\"The closest comparisons are \",a(t.a,{href:\"/ciam-compass/compare/firebase-auth-vs-supabase-auth/\",children:\"Firebase Auth vs Supabase Auth\"}),\", \",a(t.a,{href:\"/ciam-compass/compare/auth0-vs-supabase-auth/\",children:\"Auth0 vs Supabase Auth\"}),\", and \",a(t.a,{href:\"/ciam-compass/compare/supabase-auth-vs-clerk/\",children:\"Supabase Auth vs Clerk\"}),\". For OSS without the Postgres requirement, \",a(t.a,{href:\"/ciam-compass/vendors/supertokens/\",children:\"SuperTokens\"}),\", \",a(t.a,{href:\"/ciam-compass/vendors/betterauth/\",children:\"BetterAuth\"}),\", and \",a(t.a,{href:\"/ciam-compass/vendors/hanko/\",children:\"Hanko\"}),\" are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/supabase-auth/",
    "edit_path": "content/vendors/supabase-auth.mdx"
  },
  {
    "type": "vendor",
    "slug": "supertokens",
    "name": "SuperTokens",
    "legal_name": "SuperTokens, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://supertokens.com",
    "docs_url": "https://supertokens.com/docs",
    "pricing_url": "https://supertokens.com/pricing",
    "github_url": "https://github.com/supertokens",
    "hq": "San Francisco, California, USA",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 4950000,
      "last_round": {
        "stage": "seed",
        "amount_usd": null,
        "year": 2020,
        "lead": "Y Combinator"
      },
      "investors": [
        "Y Combinator",
        "Root Ventures",
        "WestWave Capital",
        "Irregular Expressions"
      ],
      "profitable": null,
      "notes": "Open-source Auth0 alternative; YC S20, ~$5M raised across seed rounds.",
      "source": "https://www.ycombinator.com/companies/supertokens"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "self-hosted",
      "cloud-saas"
    ],
    "target_segments": [
      "b2c",
      "b2b-saas",
      "developer-tools"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "vue",
          "angular",
          "python",
          "go",
          "php"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Pluggable recipes (auth methods as composable modules) + override APIs"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": 0,
      "enterprise_quote_required_above": "Self-hosted Community is free; SaaS Managed Service priced per-MAU",
      "notable_costs": [
        "Self-hosted Core service is Apache 2.0, free at any scale",
        "Managed Service (SaaS) priced per-MAU with included MAU allowance at low cost",
        "Pluggable recipe model, pay only for the auth methods you actually deploy"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 200,
      "tco_at_500k_mau_estimate_usd_per_month": 900,
      "tco_at_1m_mau_estimate_usd_per_month": 1800,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Pluggable Recipe architecture, auth methods are composable modules, pay only for what you use.",
      "Apache 2.0 self-hosted Core under the most permissive OSS license among full CIAM platforms.",
      "Strong session management primitives, refresh token rotation, anti-CSRF, and revocation are first-class.",
      "Clean SDK ergonomics across major JS frameworks plus Python / Go / PHP."
    ],
    "limitations": [
      "Smaller community than Keycloak; larger than newer entrants but still mid-tier.",
      "Compliance footprint on managed product is narrow, SOC 2 Type II only.",
      "B2B Organizations exists but is less mature than dedicated B2B vendors.",
      "No native FGA, no adaptive MFA, no bot defense."
    ],
    "best_for": [
      "Teams that want OSS-licensed auth library with self-host as the primary deployment",
      "Apps that compose auth methods incrementally rather than buying the full stack",
      "B2C consumer apps or B2B SaaS at mid-market scale"
    ],
    "not_for": [
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Mid-large enterprise federation requirements",
      "Authorization-heavy use cases requiring FGA"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 2
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "SuperTokens Pricing",
        "url": "https://supertokens.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "SuperTokens Documentation",
        "url": "https://supertokens.com/docs",
        "accessed": "2026-08-19"
      },
      {
        "title": "SuperTokens GitHub",
        "url": "https://github.com/supertokens",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "SuperTokens is the modern OSS auth library with the cleanest pluggable architecture in 2026, Apache 2.0 self-hosted Core, Recipe-based composition (each auth method is a module), and strong session management primitives. For teams that want OSS auth as a library with optional managed offering, SuperTokens shortlists alongside FusionAuth and Zitadel. The trade-off is narrower compliance and weaker B2B Organizations than dedicated B2B platforms.",
    "faqs": [
      {
        "q": "What is the SuperTokens Recipe architecture?",
        "a": "Each auth method (passwords, passwordless, social login, multi-tenancy, MFA, dashboard) is a separate Recipe, a composable module that can be added or removed independently. This is more flexible than monolithic CIAM where you pay for and operate everything regardless of usage."
      },
      {
        "q": "Is SuperTokens self-hosted only?",
        "a": "No, both self-hosted Core (Apache 2.0, free at any scale) and SuperTokens Managed Service (SaaS) are available. The Managed Service runs the Core for you with included MAU allowances."
      },
      {
        "q": "How does SuperTokens compare to Auth.js / NextAuth?",
        "a": "SuperTokens is a hosted backend service with SDKs, while Auth.js is a library that runs entirely inside the application. SuperTokens has stronger session management, multi-tenant primitives, and admin tooling; Auth.js has zero-deployment simplicity. For projects beyond a single Next.js app, SuperTokens is usually the right model."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-05-28",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(n){const r={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return s(e,{children:[a(r.h2,{id:\"what-supertokens-is\",children:a(r.a,{className:\"heading-anchor\",href:\"#what-supertokens-is\",children:\"What SuperTokens is\"})}),\"\\n\",s(r.p,{children:[a(r.a,{href:\"/ciam-compass/vendors/supertokens/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"SuperTokens\"}),\" launched in 2020 as an open-source auth library with a focus on session management, with the codebase split between the Core (Apache 2.0 backend service) and SDK Recipes (pluggable auth method modules). Both self-hosted and managed offerings share the same Core, and the Recipe architecture is the design center: each auth method (passwords, passwordless, social, multi-tenancy, MFA) is a composable module.\"]}),\"\\n\",a(r.h2,{id:\"where-supertokens-wins\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-supertokens-wins\",children:\"Where SuperTokens wins\"})}),\"\\n\",s(r.p,{children:[\"The pluggable Recipe model is the differentiator, teams pay for and operate only the auth methods they actually use, which keeps both the bundle and the operational surface small. Apache 2.0 licensing across the Core is the most permissive in the OSS CIAM tier. Session management primitives (\",a(r.a,{href:\"/ciam-compass/glossary/refresh-token-rotation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"refresh token rotation\"}),\", anti-CSRF, revocation) are strong.\"]}),\"\\n\",a(r.h2,{id:\"where-supertokens-hurts\",children:a(r.a,{className:\"heading-anchor\",href:\"#where-supertokens-hurts\",children:\"Where SuperTokens hurts\"})}),\"\\n\",s(r.p,{children:[\"Compliance footprint on the managed product is narrow (SOC 2 only). B2B Organizations exists but is less mature than WorkOS or \",a(r.a,{href:\"/ciam-compass/vendors/frontegg/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Frontegg\"}),\". No native FGA, no adaptive MFA, no bot defense.\"]}),\"\\n\",a(r.h2,{id:\"how-supertokens-compares\",children:a(r.a,{className:\"heading-anchor\",href:\"#how-supertokens-compares\",children:\"How SuperTokens compares\"})}),\"\\n\",s(r.p,{children:[\"SuperTokens sits in a useful middle of the OSS CIAM tier, heavier than a code-first library like \",a(r.a,{href:\"/ciam-compass/vendors/betterauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"BetterAuth\"}),\", lighter than full enterprise platforms like Keycloak or WSO2 IS. The Recipe-based composition is its most distinctive design choice and the main reason teams pick it over Keycloak. The closest direct comparisons are \",a(r.a,{href:\"/ciam-compass/compare/supertokens-vs-keycloak/\",children:\"SuperTokens vs Keycloak\"}),\", \",a(r.a,{href:\"/ciam-compass/compare/supertokens-vs-fusionauth/\",children:\"SuperTokens vs FusionAuth\"}),\", and \",a(r.a,{href:\"/ciam-compass/compare/auth0-vs-supertokens/\",children:\"Auth0 vs SuperTokens\"}),\". For modern OSS with B2B-first focus, \",a(r.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\" is the alternative.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/supertokens/",
    "edit_path": "content/vendors/supertokens.mdx"
  },
  {
    "type": "vendor",
    "slug": "tesseral",
    "name": "Tesseral",
    "legal_name": "Tesseral, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://tesseral.com",
    "docs_url": "https://tesseral.com/docs",
    "pricing_url": "https://tesseral.com/pricing",
    "github_url": "https://github.com/tesseral-labs",
    "hq": "San Francisco, California, USA",
    "founded": 2024,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 3300000,
      "last_round": {
        "stage": "seed",
        "amount_usd": 3300000,
        "year": 2025,
        "lead": "Y Combinator"
      },
      "investors": [
        "Y Combinator",
        "Paul Graham",
        "Jessica Livingston"
      ],
      "profitable": null,
      "notes": "Open-source B2B auth infrastructure; $3.3M seed at launch (2025).",
      "source": "https://www.finsmes.com/2025/05/tesseral-raises-3-3m-in-seed-funding.html"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam",
      "open-source-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": "partial",
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": "partial"
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "go",
          "python"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": true,
        "extension_model": "Webhooks + custom claims"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 10000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Volume + dedicated tenancy",
      "notable_costs": [
        "Open-source self-hosted edition available",
        "Managed Cloud priced per-MAU with B2B Organizations included",
        "Pre-built UI components in Next.js + React SDKs"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 290,
      "tco_at_500k_mau_estimate_usd_per_month": 1300,
      "tco_at_1m_mau_estimate_usd_per_month": 2500,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "B2B SaaS focus with both managed cloud and open-source self-hosted deployments from one product.",
      "Modern Go-based architecture with idiomatic React/Next.js SDKs.",
      "Apache 2.0 licensed self-hosted edition, strict OSS compliance.",
      "Built B2B Organizations and tenant-aware login URLs into the core data model."
    ],
    "limitations": [
      "Very young (2024), small customer base, limited battle-test coverage.",
      "Compliance footprint is narrow, SOC 2 Type II only on the managed product.",
      "B2C consumer features are minimal.",
      "Smaller ecosystem than WorkOS or Frontegg."
    ],
    "best_for": [
      "B2B SaaS startups that want OSS self-host as an option without taking on Keycloak operational weight",
      "Teams comparing modern OSS B2B CIAM",
      "Apps that may need to switch between managed and self-hosted later"
    ],
    "not_for": [
      "B2C consumer apps",
      "Workloads requiring HIPAA, FedRAMP, ISO 27001, or PCI DSS",
      "Mid-large enterprise federation needs"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 2
    },
    "last_verified": "2026-05-15",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Tesseral Pricing",
        "url": "https://tesseral.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Tesseral Documentation",
        "url": "https://tesseral.com/docs",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Tesseral is a 2024-vintage entrant in B2B-SaaS-OSS CIAM, with both managed cloud and self-hosted Apache 2.0 deployments. Smaller and younger than incumbents, but the pricing model and OSS option are competitive for early-stage B2B SaaS that wants the optionality. Worth shortlisting alongside Zitadel and SSOJet for B2B-only SaaS that values OSS self-host.",
    "faqs": [
      {
        "q": "How does Tesseral compare to Zitadel?",
        "a": "Both are modern OSS B2B CIAM with managed and self-hosted options. Zitadel is more mature and has a larger feature surface; Tesseral is younger with tighter B2B-SaaS scope. For 2026 evaluations, Zitadel is the lower-risk pick; Tesseral is worth watching."
      },
      {
        "q": "Is Tesseral fully open source?",
        "a": "Yes, Apache 2.0 self-hosted Community edition. Tesseral Cloud is the managed offering; both share the same codebase."
      },
      {
        "q": "Should I pick Tesseral over WorkOS?",
        "a": "WorkOS is more mature and battle-tested. Tesseral's differentiator is the OSS self-host option WorkOS does not offer. For teams that want managed-only with maximum maturity, WorkOS; for OSS optionality, Tesseral."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-15",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(r){const n={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return s(e,{children:[a(n.h2,{id:\"what-tesseral-is\",children:a(n.a,{className:\"heading-anchor\",href:\"#what-tesseral-is\",children:\"What Tesseral is\"})}),\"\\n\",s(n.p,{children:[a(n.a,{href:\"/ciam-compass/vendors/tesseral/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Tesseral\"}),\" launched in 2024 as a B2B-SaaS-focused CIAM with both managed (Tesseral Cloud) and Apache 2.0 self-hosted Community editions sharing the same codebase. The thesis is similar to Zitadel's, modern OSS plus managed offering, but with tighter B2B-SaaS scope and Next.js / React-first DX.\"]}),\"\\n\",a(n.h2,{id:\"where-tesseral-wins\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-tesseral-wins\",children:\"Where Tesseral wins\"})}),\"\\n\",a(n.p,{children:\"Both deployment options from one product. Strict Apache 2.0 OSS licensing on the self-hosted edition. Modern Go-based architecture. Built B2B Organizations and tenant-aware login URLs into the core.\"}),\"\\n\",a(n.h2,{id:\"where-tesseral-hurts\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-tesseral-hurts\",children:\"Where Tesseral hurts\"})}),\"\\n\",s(n.p,{children:[\"Very young, 2024 founding means a small customer base and limited battle-test coverage compared to incumbents. Compliance footprint is narrow with SOC 2 Type II only on the managed product, no ISO 27001 / HIPAA / FedRAMP / PCI DSS attestations. B2C consumer features are minimal; the product is intentionally B2B-multi-tenant-shaped. For mid-large enterprise federation or for B2C consumer apps with serious \",a(n.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"progressive profiling\"}),\" and fraud needs, look elsewhere.\"]}),\"\\n\",a(n.h2,{id:\"how-tesseral-compares\",children:a(n.a,{className:\"heading-anchor\",href:\"#how-tesseral-compares\",children:\"How Tesseral compares\"})}),\"\\n\",s(n.p,{children:[\"The closest comparisons are \",a(n.a,{href:\"/ciam-compass/compare/tesseral-vs-zitadel/\",children:\"Tesseral vs Zitadel\"}),\", \",a(n.a,{href:\"/ciam-compass/compare/tesseral-vs-workos/\",children:\"Tesseral vs WorkOS\"}),\", and \",a(n.a,{href:\"/ciam-compass/compare/tesseral-vs-ssojet/\",children:\"Tesseral vs SSOJet\"}),\" for the modern-B2B-CIAM call. For broader OSS without managed-cloud, \",a(n.a,{href:\"/ciam-compass/vendors/keycloak/\",children:\"Keycloak\"}),\" and \",a(n.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory\"}),\" are the alternatives.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/tesseral/",
    "edit_path": "content/vendors/tesseral.mdx"
  },
  {
    "type": "vendor",
    "slug": "transmit-security",
    "name": "Transmit Security",
    "legal_name": "Transmit Security Ltd.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://transmitsecurity.com",
    "docs_url": "https://developer.transmitsecurity.com",
    "pricing_url": null,
    "github_url": "https://github.com/TransmitSecurity",
    "hq": "Boston, Massachusetts, USA / Tel Aviv, Israel",
    "founded": 2014,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 543000000,
      "last_round": {
        "stage": "series-a",
        "amount_usd": 543000000,
        "year": 2021,
        "lead": "Insight Partners"
      },
      "investors": [
        "Insight Partners",
        "General Atlantic",
        "Cyberstarts",
        "Geodesic",
        "SYN Ventures"
      ],
      "profitable": null,
      "notes": "The largest Series A in cybersecurity history ($543M, 2021) at a $2.2B valuation; bootstrapped for its first seven years.",
      "source": "https://techcrunch.com/2021/06/22/transmit-security-raises-543m-series-a-to-kill-off-the-password/"
    },
    "categories": [
      "enterprise-ciam",
      "identity-orchestration",
      "idv-and-fraud",
      "passwordless-specialist"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "enterprise",
      "b2c"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "ios",
          "swift",
          "android",
          "kotlin",
          "python",
          "go",
          "java",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Mosaic platform, composable journey orchestration"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": "partial"
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": true,
        "hipaa": true,
        "pci_dss": "Level 1",
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": true,
        "purpose_specific_consent": true,
        "integrates_with_cmps": [
          "OneTrust"
        ]
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": true,
        "high_scale_proven": true
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": true,
        "account_linking": true,
        "custom_domains_per_brand": true,
        "per_brand_theming": true,
        "consent_partitioning": "partial",
        "deletion_webhooks": true,
        "event_streaming": true,
        "rate_limit_transparency": true
      }
    },
    "pricing": {
      "model": "enterprise-quote",
      "free_tier": {
        "available": false,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "All deployments enterprise quote-based",
      "notable_costs": [
        "Mosaic platform combines CIAM, fraud, and orchestration in one commercial bundle",
        "Per-MAU + per-fraud-decision pricing typical",
        "Strong fit for fintech and high-fraud-pressure consumer use cases"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": null,
      "tco_at_100k_mau_estimate_usd_per_month": 6500,
      "tco_at_500k_mau_estimate_usd_per_month": 20000,
      "tco_at_1m_mau_estimate_usd_per_month": 35000,
      "pricing_transparency_score": 1
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 5,
    "strengths": [
      "Mosaic platform unifies CIAM, fraud detection, and identity orchestration in one product, uncommon in the index.",
      "Strong fintech and banking focus, built for high-fraud-pressure B2C scenarios with adaptive risk + behavioral biometrics.",
      "Best-in-class passkey orchestration paired with risk decisioning at the same layer.",
      "PCI DSS Level 1 with HIPAA, appropriate for fintech and healthcare workloads."
    ],
    "limitations": [
      "Enterprise-only commercial structure with opaque pricing and high entry threshold.",
      "DX trails developer-first tier; the platform is positioned for buying-committee evaluation, not engineering self-service.",
      "Smaller customer base than large enterprise incumbents (Auth0, Ping, ForgeRock).",
      "FedRAMP not yet attested as of 2026."
    ],
    "best_for": [
      "Fintech, banking, and insurance with high fraud pressure and need for risk decisioning at the auth layer",
      "Enterprise B2C deployments requiring unified CIAM + fraud + orchestration",
      "Regulated industries comfortable with enterprise-quote pricing"
    ],
    "not_for": [
      "Mid-market SaaS or startups",
      "Workloads requiring FedRAMP authorization",
      "Teams prioritizing developer self-service over enterprise sales engagement"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-05-27",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Transmit Security Mosaic platform",
        "url": "https://transmitsecurity.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Transmit Security Developer documentation",
        "url": "https://developer.transmitsecurity.com",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Transmit Security is the right CIAM choice for fintech, banking, and high-fraud-pressure B2C deployments where unified CIAM plus fraud detection plus orchestration removes the typical three-vendor stack. The Mosaic platform's combination of risk decisioning, behavioral biometrics, and passkey orchestration is among the most capable in the enterprise tier. Enterprise-only pricing and opaque commercial structure exclude mid-market evaluation; for teams below that threshold, look at Auth0 plus Authsignal or Descope.",
    "faqs": [
      {
        "q": "What is the Mosaic platform?",
        "a": "Transmit Security's unified product offering, CIAM (auth, MFA, passkeys), fraud detection (account opening, account takeover, transaction fraud), and orchestration (composable journey design). The thesis is that fragmenting these across separate vendors costs more in integration and creates blind spots between CIAM signals and fraud signals."
      },
      {
        "q": "Is Transmit Security only for fintech?",
        "a": "Strongest fit for fintech and banking, but used across high-fraud-pressure verticals including insurance, healthcare, and high-stakes consumer commerce. For workloads without significant fraud pressure, the platform's broader capability is hard to justify against simpler CIAM."
      },
      {
        "q": "What does Transmit Security cost?",
        "a": "Enterprise quote-based with per-MAU plus per-fraud-decision pricing. Six-figure annual minimums are typical. For mid-market evaluation, the entry threshold is disqualifying."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-27",
        "summary": "Capability matrix and pricing bands re-verified against the vendor's latest documentation and changelog."
      }
    ],
    "body": "const{Fragment:e,jsx:r,jsxs:a}=arguments[0];function _createMdxContent(t){const i={a:\"a\",h2:\"h2\",p:\"p\",...t.components};return a(e,{children:[r(i.h2,{id:\"what-transmit-security-is\",children:r(i.a,{className:\"heading-anchor\",href:\"#what-transmit-security-is\",children:\"What Transmit Security is\"})}),\"\\n\",a(i.p,{children:[r(i.a,{href:\"/ciam-compass/vendors/transmit-security/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Transmit Security\"}),\" launched in 2014 in Tel Aviv with a fintech-and-banking-first thesis: high-fraud-pressure consumer scenarios need CIAM, fraud detection, and orchestration designed together rather than stitched across three separate vendors. The Mosaic platform unifies these into one product surface, with adaptive risk decisioning, behavioral biometrics, and passkey orchestration at the same layer.\"]}),\"\\n\",r(i.h2,{id:\"where-transmit-security-wins\",children:r(i.a,{className:\"heading-anchor\",href:\"#where-transmit-security-wins\",children:\"Where Transmit Security wins\"})}),\"\\n\",a(i.p,{children:[\"Unified CIAM plus fraud plus orchestration is uncommon in the index. The depth in fraud detection, account opening fraud, account takeover, transaction fraud, exceeds what stock CIAM ships and removes the integration cost of running a separate fraud vendor. \",r(i.a,{href:\"/ciam-compass/glossary/passkey/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Passkey\"}),\" orchestration paired with risk decisioning at the same layer is differentiating for high-stakes scenarios.\"]}),\"\\n\",r(i.h2,{id:\"where-transmit-security-hurts\",children:r(i.a,{className:\"heading-anchor\",href:\"#where-transmit-security-hurts\",children:\"Where Transmit Security hurts\"})}),\"\\n\",r(i.p,{children:\"Enterprise-only commercial structure with opaque pricing and six-figure annual minimums. DX is positioned for buying-committee evaluation rather than engineering self-service. FedRAMP is not yet attested. Smaller customer base than the largest enterprise CIAM incumbents.\"}),\"\\n\",r(i.h2,{id:\"how-transmit-security-compares\",children:r(i.a,{className:\"heading-anchor\",href:\"#how-transmit-security-compares\",children:\"How Transmit Security compares\"})}),\"\\n\",a(i.p,{children:[\"The closest comparisons are \",r(i.a,{href:\"/ciam-compass/compare/auth0-vs-transmit-security/\",children:\"Auth0 vs Transmit Security\"}),\" for the enterprise-CIAM-with-fraud call and \",r(i.a,{href:\"/ciam-compass/compare/ping-identity-vs-transmit-security/\",children:\"Ping Identity vs Transmit Security\"}),\". For mid-market alternatives that compose CIAM plus fraud separately, \",r(i.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" plus \",r(i.a,{href:\"/ciam-compass/vendors/authsignal/\",children:\"Authsignal\"}),\" or \",r(i.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"}),\" cover similar ground at lower cost.\"]})]})}return{default:function(e={}){const{wrapper:a}=e.components||{};return a?r(a,{...e,children:r(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/transmit-security/",
    "edit_path": "content/vendors/transmit-security.mdx"
  },
  {
    "type": "vendor",
    "slug": "workos",
    "name": "WorkOS",
    "legal_name": "WorkOS, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://workos.com",
    "docs_url": "https://workos.com/docs",
    "pricing_url": "https://workos.com/pricing",
    "github_url": "https://github.com/workos",
    "hq": "San Francisco, California, USA",
    "founded": 2019,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 100000000,
      "last_round": {
        "stage": "series-b",
        "amount_usd": 80000000,
        "year": 2022,
        "lead": "Greenoaks"
      },
      "investors": [
        "Greenoaks",
        "Lightspeed Venture Partners",
        "Lachy Groom",
        "Abstract Ventures"
      ],
      "profitable": null,
      "notes": "Enterprise-readiness APIs (SSO, SCIM, audit logs); $80M Series B in 2022 alongside the Modulz acquisition.",
      "source": "https://workos.com/blog/series-b"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas",
      "enterprise"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": true,
        "fga_engine": true,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go",
          "ruby",
          "php",
          "java",
          "dotnet",
          "kotlin"
        ],
        "cli": false,
        "terraform_provider": true,
        "local_emulator": false,
        "extension_model": "Webhooks"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": "partial",
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": true,
        "data_residency_control": "partial",
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": true,
        "custom_domains_per_brand": "partial",
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "per-organization",
      "free_tier": {
        "available": true,
        "mau_limit": 1000000
      },
      "paid_starts_at_usd": 125,
      "enterprise_quote_required_above": "Custom volume pricing for larger orgs",
      "notable_costs": [
        "Free up to 1M MAU on AuthKit (the auth product), pricing kicks in for advanced features",
        "Enterprise SSO connections billed per-org per-month at standard rate",
        "Audit Log API and Directory Sync (SCIM) priced separately"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 0,
      "tco_at_500k_mau_estimate_usd_per_month": 1500,
      "tco_at_1m_mau_estimate_usd_per_month": 3500,
      "pricing_transparency_score": 5
    },
    "dx_score": 5,
    "docs_quality": 5,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 4,
    "strengths": [
      "B2B-first by design, Organizations, Enterprise SSO with SAML/OIDC, SCIM Directory Sync, and audit logs are first-class, not bolt-ons.",
      "AuthKit free up to 1M MAU is the most generous free tier in the developer-first tier and a credible Auth0 alternative for B2B SaaS.",
      "FGA (Zanzibar-style fine-grained authorization) shipped in 2024, competitive with Auth0 FGA for new B2B SaaS authz.",
      "Strong DX with idiomatic SDKs across major languages and a Terraform provider."
    ],
    "limitations": [
      "B2C-grade features are weaker, no progressive profiling, no native bot detection, no adaptive MFA.",
      "Compliance breadth narrower than Auth0, no FedRAMP, no PCI DSS direct attestation.",
      "Adaptive / risk-based MFA decisioning is rudimentary compared to Descope or Auth0.",
      "MCP / agentic identity is partial, no first-class agent token model in 2026."
    ],
    "best_for": [
      "B2B SaaS that wants Enterprise SSO, SCIM, and audit logs without paying enterprise prices",
      "Teams switching off Auth0 below 1M MAU specifically for cost",
      "Apps where the buyer is the IT admin, not the end user"
    ],
    "not_for": [
      "Consumer (B2C) apps with progressive profiling, bot defense, and adaptive risk needs",
      "Workloads requiring FedRAMP or PCI DSS",
      "Self-hosted deployments"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-08-19",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "WorkOS Pricing",
        "url": "https://workos.com/pricing",
        "accessed": "2026-08-19"
      },
      {
        "title": "WorkOS Documentation",
        "url": "https://workos.com/docs",
        "accessed": "2026-08-19"
      }
    ],
    "editorial_verdict": "WorkOS is the strongest B2B-first CIAM in 2026 by deliberate scope choice: every product surface assumes the buyer is selling to enterprise IT, not to consumers. AuthKit's 1M MAU free tier makes it a credible Auth0 alternative for B2B SaaS that does not need adaptive risk or B2C consumer flows. In 2026 the company is also documenting MCP step-up patterns for agents; that is still a tutorial surface, not a packaged agent-identity product like Auth0 for AI Agents. For pure B2B SSO, SCIM, and audit logs, WorkOS is hard to beat at any price point.",
    "faqs": [
      {
        "q": "How is WorkOS different from Auth0?",
        "a": "WorkOS is built B2B-first; Auth0 is broader. WorkOS Organizations, Enterprise SSO, SCIM Directory Sync, and audit logs are first-class products, not bolt-ons. Auth0 covers more ground (B2C consumer flows, broader compliance, adaptive MFA) but at materially higher cost for B2B-only use cases below 1M MAU."
      },
      {
        "q": "What does WorkOS cost?",
        "a": "AuthKit (the auth product) is free up to 1M MAU. Pricing kicks in for advanced features, Enterprise SSO connections, Directory Sync (SCIM), Audit Logs, FGA, billed per-org or per-call. For a B2B SaaS at 100k MAU with 20 enterprise customers, expect $500–$1,500 per month."
      },
      {
        "q": "Does WorkOS support B2C consumer auth?",
        "a": "Technically yes, but the product is not designed for it. Missing pieces: progressive profiling, native bot detection, adaptive risk MFA, and B2C-grade fraud signals. For consumer apps, look at Auth0, Stytch, Descope, or MojoAuth."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-08-19",
        "summary": "Re-verified against public docs and pricing pages. Agentic identity, passkeys, and acquisition status checked as of 19 August 2026."
      },
      {
        "date": "2026-04-22",
        "summary": "Profile reviewed: capabilities, pricing, and verdict checked against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:s}=arguments[0];function _createMdxContent(r){const o={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return s(e,{children:[a(o.h2,{id:\"what-workos-is\",children:a(o.a,{className:\"heading-anchor\",href:\"#what-workos-is\",children:\"What WorkOS is\"})}),\"\\n\",s(o.p,{children:[a(o.a,{href:\"/ciam-compass/vendors/workos/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"WorkOS\"}),\" launched in 2019 with a tight scope: make it easy for SaaS apps to support enterprise customers. The product line maps to the SOC 2 / IT-admin checklist, Single Sign-On, Directory Sync (SCIM), Audit Logs, MFA, sold as a coherent set of APIs. AuthKit, the user-facing auth product, was added in 2024 and sits on top of the same Organizations model. The buyer is the engineering team at a B2B SaaS that needs to ship enterprise features without building them.\"]}),\"\\n\",a(o.h2,{id:\"where-workos-wins\",children:a(o.a,{className:\"heading-anchor\",href:\"#where-workos-wins\",children:\"Where WorkOS wins\"})}),\"\\n\",s(o.p,{children:[\"The B2B-first stance is the differentiator. Every feature assumes the customer is an organization, not a consumer, Organizations are first-class objects, SSO connections live per-organization, audit logs are queryable per-organization. The model maps cleanly to how B2B SaaS actually sells, and the docs are written for the engineer who has just been told by sales that a $50k contract requires \",a(o.a,{href:\"/ciam-compass/glossary/saml/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SAML\"}),\" SSO by Friday.\"]}),\"\\n\",s(o.p,{children:[\"AuthKit's free tier, 1M MAU, is the most generous in the developer-first segment and changes the math on \",a(o.a,{href:\"/ciam-compass/vendors/auth0/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Auth0\"}),\" alternatives. For a B2B SaaS under 1M MAU that doesn't need consumer flows, the underlying auth is effectively free; only the enterprise add-ons (SSO, Directory Sync, Audit Logs, FGA) are billed.\"]}),\"\\n\",s(o.p,{children:[\"WorkOS FGA, shipped in 2024, brings Zanzibar-style fine-grained \",a(o.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"authorization\"}),\" to the platform. For B2B SaaS designing role-based and resource-based permissions, this removes the need for a separate authz vendor.\"]}),\"\\n\",a(o.h2,{id:\"where-workos-hurts\",children:a(o.a,{className:\"heading-anchor\",href:\"#where-workos-hurts\",children:\"Where WorkOS hurts\"})}),\"\\n\",s(o.p,{children:[\"The flip side of B2B-first is that B2C-grade features are weaker or missing. There's no \",a(o.a,{href:\"/ciam-compass/glossary/progressive-profiling/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"progressive profiling\"}),\", no native bot detection, no adaptive risk-based MFA. For a consumer app at scale, these gaps matter; for B2B SaaS where the IT admin enforces MFA centrally, they don't.\"]}),\"\\n\",s(o.p,{children:[\"Compliance breadth is narrower than Auth0, no FedRAMP, no PCI DSS direct \",a(o.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\". ISO 27001 and SOC 2 Type II yes. Most B2B SaaS sales cycles don't ask for FedRAMP, but federal or fintech buyers do.\"]}),\"\\n\",s(o.p,{children:[a(o.a,{href:\"/ciam-compass/glossary/agentic-identity/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Agentic identity\"}),\" / MCP is not yet first-class. OAuth 2.1 and Dynamic Client Registration yes, but no scoped agent token model or web bot auth.\"]}),\"\\n\",a(o.h2,{id:\"how-workos-compares\",children:a(o.a,{className:\"heading-anchor\",href:\"#how-workos-compares\",children:\"How WorkOS compares\"})}),\"\\n\",s(o.p,{children:[\"The most direct comparisons are \",a(o.a,{href:\"/ciam-compass/compare/workos-vs-frontegg/\",children:\"WorkOS vs Frontegg\"}),\" and \",a(o.a,{href:\"/ciam-compass/compare/auth0-vs-workos/\",children:\"Auth0 vs WorkOS\"}),\". For broader B2C + B2B coverage, \",a(o.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\", \",a(o.a,{href:\"/ciam-compass/vendors/stytch/\",children:\"Stytch\"}),\", and \",a(o.a,{href:\"/ciam-compass/vendors/descope/\",children:\"Descope\"}),\" are the credible alternatives. For modern enterprise CIAM with strong B2B \",a(o.a,{href:\"/ciam-compass/glossary/sso/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"SSO\"}),\" at lower price points, \",a(o.a,{href:\"/ciam-compass/vendors/ssojet/\",children:\"SSOJet\"}),\" and \",a(o.a,{href:\"/ciam-compass/vendors/mojoauth/\",children:\"MojoAuth\"}),\" deserve evaluation.\"]})]})}return{default:function(e={}){const{wrapper:s}=e.components||{};return s?a(s,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/workos/",
    "edit_path": "content/vendors/workos.mdx"
  },
  {
    "type": "vendor",
    "slug": "wristband",
    "name": "Wristband",
    "legal_name": "Wristband, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://wristband.dev",
    "docs_url": "https://docs.wristband.dev",
    "pricing_url": "https://wristband.dev/pricing",
    "github_url": "https://github.com/wristband-dev",
    "hq": "New York, New York, USA",
    "founded": 2022,
    "status": "active",
    "funding": {
      "model": "bootstrapped",
      "total_raised_usd": null,
      "last_round": null,
      "investors": [],
      "profitable": null,
      "notes": "Bootstrapped by its founders; multi-tenant B2B auth, no institutional funding disclosed.",
      "source": "https://www.wristband.dev/the-team"
    },
    "categories": [
      "developer-first-ciam",
      "b2b-saas-ciam"
    ],
    "deployment": [
      "cloud-saas"
    ],
    "target_segments": [
      "b2b-saas"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": false,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": false,
        "step_up_auth": "partial"
      },
      "authorization": {
        "rbac": true,
        "abac": false,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": false,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": false
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "react",
          "next",
          "python",
          "go",
          "dotnet"
        ],
        "cli": false,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Webhooks + custom claims"
      },
      "security": {
        "bot_detection": false,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": false,
        "log_streams": "partial",
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": "partial",
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": false,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": false,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": false,
        "preference_center": false,
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": "partial",
        "high_scale_proven": false
      },
      "enterprise_ops": {
        "migration_hash_import": "partial",
        "lazy_migration": false,
        "account_linking": "partial",
        "custom_domains_per_brand": false,
        "per_brand_theming": false,
        "consent_partitioning": false,
        "deletion_webhooks": false,
        "event_streaming": "partial",
        "rate_limit_transparency": false
      }
    },
    "pricing": {
      "model": "per-organization",
      "free_tier": {
        "available": true,
        "mau_limit": 25000
      },
      "paid_starts_at_usd": 49,
      "enterprise_quote_required_above": "Volume B2B SSO connections",
      "notable_costs": [
        "Per-tenant pricing model, predictable as B2B customer base grows",
        "Free tier covers most early-stage B2B SaaS",
        "Enterprise SSO connections billed per-tenant per-month"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 0,
      "tco_at_100k_mau_estimate_usd_per_month": 250,
      "tco_at_500k_mau_estimate_usd_per_month": 1100,
      "tco_at_1m_mau_estimate_usd_per_month": 2200,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "small",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "B2B multi-tenant CIAM with per-tenant data isolation as a first-class design choice.",
      "Predictable per-tenant pricing favorable to B2B SaaS with growing customer count.",
      "Strong default tenant resolution flow with subdomain-aware login URLs.",
      "Modern API surface and SDKs across major languages."
    ],
    "limitations": [
      "Very young, small customer base and ecosystem.",
      "Compliance footprint is narrow, SOC 2 only.",
      "B2C consumer features are not the focus; basic at best.",
      "No native FGA, no adaptive MFA, no managed bot detection."
    ],
    "best_for": [
      "B2B SaaS prioritizing strict tenant isolation by design",
      "Multi-tenant SaaS at startup-to-mid-market scale",
      "Teams comparing per-tenant pricing models against per-MAU"
    ],
    "not_for": [
      "B2C consumer apps",
      "Workloads requiring HIPAA, FedRAMP, or PCI DSS",
      "Mid-large enterprise federation requirements"
    ],
    "migration_difficulty": {
      "inbound": 2,
      "outbound": 3
    },
    "last_verified": "2026-04-28",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Wristband Pricing",
        "url": "https://wristband.dev/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Wristband Documentation",
        "url": "https://docs.wristband.dev",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Wristband is a B2B-multi-tenant-CIAM with predictable per-tenant pricing, designed for SaaS apps where tenant isolation is the architectural anchor. Smaller and younger than WorkOS or Frontegg, with narrower compliance, but the pricing model is genuinely friendly for SaaS with growing customer counts. Worth evaluating alongside SSOJet and Scalekit for early-to-mid-stage B2B SaaS.",
    "faqs": [
      {
        "q": "What does Wristband mean by per-tenant data isolation?",
        "a": "Each B2B customer (tenant) gets logically isolated user data and configuration; cross-tenant queries are not possible by default. This is a stronger architectural posture than 'add a tenant_id claim and trust the application,' which is how many CIAM achieve multi-tenancy."
      },
      {
        "q": "How does Wristband compare to WorkOS?",
        "a": "Both are B2B-focused. WorkOS is more mature, has a broader feature set, and a larger customer base; Wristband is younger with tighter scope on multi-tenancy and per-tenant pricing. For early-stage SaaS prioritizing predictable pricing per customer, Wristband is competitive."
      },
      {
        "q": "Does Wristband handle B2C apps?",
        "a": "Not really. Wristband is B2B-multi-tenant-first; for consumer apps, look at Auth0, Stytch, MojoAuth, or Clerk."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-28",
        "summary": "Full profile review: capability matrix, TCO bands, and editorial verdict re-verified against current public sources."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:n}=arguments[0];function _createMdxContent(r){const t={a:\"a\",h2:\"h2\",p:\"p\",...r.components};return n(e,{children:[a(t.h2,{id:\"what-wristband-is\",children:a(t.a,{className:\"heading-anchor\",href:\"#what-wristband-is\",children:\"What Wristband is\"})}),\"\\n\",n(t.p,{children:[a(t.a,{href:\"/ciam-compass/vendors/wristband/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Wristband\"}),\" launched in 2022 in New York with a B2B-multi-tenant-first thesis: ship a CIAM where per-tenant isolation is an architectural primitive rather than a tenant_id claim convention. The product surface assumes B2B SaaS with multiple end-customer organizations, each with their own subdomain, branding, and isolated user pool, and delivers the auth + tenant-resolution + admin tooling for that pattern.\"]}),\"\\n\",a(t.h2,{id:\"where-wristband-wins\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-wristband-wins\",children:\"Where Wristband wins\"})}),\"\\n\",a(t.p,{children:\"Per-tenant data isolation by design, not as a configuration option. Predictable per-tenant pricing that aligns with how B2B SaaS economics actually work (you bill per customer, you pay per tenant). Subdomain-aware tenant resolution that reduces the engineering effort to ship per-customer branded login flows.\"}),\"\\n\",a(t.h2,{id:\"where-wristband-hurts\",children:a(t.a,{className:\"heading-anchor\",href:\"#where-wristband-hurts\",children:\"Where Wristband hurts\"})}),\"\\n\",n(t.p,{children:[\"Young, small ecosystem, narrow compliance (SOC 2 only). B2C-light by design. No native FGA, no adaptive MFA, no managed \",a(t.a,{href:\"/ciam-compass/glossary/bot-detection/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"bot detection\"}),\". For consumer apps or for mid-large enterprise federation, look elsewhere.\"]}),\"\\n\",a(t.h2,{id:\"how-wristband-compares\",children:a(t.a,{className:\"heading-anchor\",href:\"#how-wristband-compares\",children:\"How Wristband compares\"})}),\"\\n\",n(t.p,{children:[\"The closest comparisons are \",a(t.a,{href:\"/ciam-compass/compare/wristband-vs-workos/\",children:\"Wristband vs WorkOS\"}),\", \",a(t.a,{href:\"/ciam-compass/compare/wristband-vs-frontegg/\",children:\"Wristband vs Frontegg\"}),\", and \",a(t.a,{href:\"/ciam-compass/compare/wristband-vs-ssojet/\",children:\"Wristband vs SSOJet\"}),\" for the B2B-multi-tenant-CIAM choice. For B2C plus B2B coverage, \",a(t.a,{href:\"/ciam-compass/vendors/auth0/\",children:\"Auth0\"}),\" and \",a(t.a,{href:\"/ciam-compass/vendors/mojoauth/\",children:\"MojoAuth\"}),\" are alternatives.\"]})]})}return{default:function(e={}){const{wrapper:n}=e.components||{};return n?a(n,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/wristband/",
    "edit_path": "content/vendors/wristband.mdx"
  },
  {
    "type": "vendor",
    "slug": "wso2-is",
    "name": "WSO2 Identity Server",
    "legal_name": "WSO2, Inc.",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://wso2.com/identity-server",
    "docs_url": "https://is.docs.wso2.com",
    "pricing_url": null,
    "github_url": "https://github.com/wso2/product-is",
    "hq": "Mountain View, California, USA / Colombo, Sri Lanka",
    "founded": 2005,
    "status": "active",
    "funding": {
      "model": "pe-owned",
      "total_raised_usd": 130000000,
      "last_round": {
        "stage": "acquired",
        "amount_usd": 600000000,
        "year": 2024,
        "lead": "EQT Private Capital Asia"
      },
      "investors": [
        "EQT Private Capital Asia",
        "Intel Capital",
        "Toba Capital",
        "Pacific Controls"
      ],
      "profitable": null,
      "notes": "Open-source middleware/identity vendor; raised ~$130M of VC, acquired by EQT for ~$600M in 2024.",
      "source": "https://en.wikipedia.org/wiki/WSO2"
    },
    "categories": [
      "open-source-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "self-hosted",
      "cloud-saas",
      "on-prem",
      "hybrid"
    ],
    "target_segments": [
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": true,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": true,
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": true,
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": true
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": false,
        "sdks": [
          "js",
          "node",
          "java",
          "python",
          "dotnet"
        ],
        "cli": true,
        "terraform_provider": false,
        "local_emulator": false,
        "extension_model": "Authentication Scripts (JavaScript) + custom Java extensions"
      },
      "security": {
        "bot_detection": true,
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": true,
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": true,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": true,
        "preference_center": "partial",
        "purpose_specific_consent": true,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "free-open-source",
      "free_tier": {
        "available": true,
        "mau_limit": null
      },
      "paid_starts_at_usd": null,
      "enterprise_quote_required_above": "Asgardeo (managed cloud) and self-managed Enterprise subscription",
      "notable_costs": [
        "Self-hosted Identity Server is Apache 2.0, free at any scale",
        "Asgardeo is the managed cloud (per-MAU tiered pricing) by WSO2",
        "Enterprise subscription provides production support, SLAs, security patches",
        "Operational profile: stateful Java service, broadly similar to Keycloak"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 300,
      "tco_at_100k_mau_estimate_usd_per_month": 900,
      "tco_at_500k_mau_estimate_usd_per_month": 3000,
      "tco_at_1m_mau_estimate_usd_per_month": 6000,
      "pricing_transparency_score": 3
    },
    "dx_score": 3,
    "docs_quality": 4,
    "community_size": "large",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Most enterprise-feature-complete OSS CIAM in 2026, adaptive MFA, consent management, governance integration, identity federation depth that Keycloak lacks.",
      "Twenty years of enterprise federation expertise, public-sector and large-enterprise install base across telecoms, banks, governments.",
      "Asgardeo is a credible managed cloud option with WSO2's enterprise pedigree behind it.",
      "Active OSS community plus commercial enterprise support tier."
    ],
    "limitations": [
      "Operational profile is heavy, stateful Java service similar to Keycloak's footprint.",
      "DX trails developer-first tier substantially; admin UI and APIs reflect enterprise-IT design choices.",
      "Pricing for Asgardeo and self-managed enterprise subscription is opaque, quote-based for serious deployments.",
      "Sprawling product family (Identity Server + Asgardeo + Choreo + API Manager) creates evaluation complexity."
    ],
    "best_for": [
      "Large enterprise and public-sector with deep federation requirements and on-prem mandates",
      "Organizations with existing WSO2 footprint (API Manager, Enterprise Integrator)",
      "Regulated industries needing consent management plus CIAM"
    ],
    "not_for": [
      "Mid-market SaaS or startups prioritizing developer velocity",
      "Teams without Java operational competence",
      "Greenfield projects without enterprise-IT context"
    ],
    "migration_difficulty": {
      "inbound": 4,
      "outbound": 4
    },
    "last_verified": "2026-04-16",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "WSO2 Identity Server Documentation",
        "url": "https://is.docs.wso2.com",
        "accessed": "2026-04-22"
      },
      {
        "title": "Asgardeo (managed cloud)",
        "url": "https://wso2.com/asgardeo",
        "accessed": "2026-04-22"
      },
      {
        "title": "WSO2 Identity Server GitHub",
        "url": "https://github.com/wso2/product-is",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "WSO2 Identity Server is the most feature-complete enterprise OSS CIAM in 2026, twenty years of federation depth, native consent management, adaptive MFA, and identity governance integration that Keycloak does not match. Asgardeo (the managed cloud) is a credible option with WSO2's enterprise pedigree. The trade-offs are heavy operational profile, dated DX, and opaque enterprise pricing. For large enterprise and public-sector with serious federation requirements, WSO2 IS is a top OSS pick alongside Keycloak.",
    "faqs": [
      {
        "q": "What is Asgardeo?",
        "a": "Asgardeo is WSO2's managed cloud CIAM, built on Identity Server. Sold per-MAU with included MAU allowances at the free tier. Offers WSO2's enterprise-grade auth without the operational burden of self-hosting Identity Server."
      },
      {
        "q": "How does WSO2 IS compare to Keycloak?",
        "a": "Both are mature self-hosted Java-based OSS CIAM with Apache 2.0 licensing. WSO2 IS ships more enterprise features out of the box, consent management, adaptive MFA, deeper governance integration. Keycloak has the larger community and broader theme/extension ecosystem. For enterprise federation depth, WSO2; for largest community, Keycloak."
      },
      {
        "q": "Is WSO2 IS enterprise-only?",
        "a": "No, the Identity Server is fully open-source under Apache 2.0 with no feature-gating between Community and Enterprise. The Enterprise subscription provides commercial support, SLAs, and security patches; the underlying product is the same."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-04-16",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:r}=arguments[0];function _createMdxContent(n){const s={a:\"a\",h2:\"h2\",p:\"p\",...n.components};return r(e,{children:[a(s.h2,{id:\"what-wso2-identity-server-is\",children:a(s.a,{className:\"heading-anchor\",href:\"#what-wso2-identity-server-is\",children:\"What WSO2 Identity Server is\"})}),\"\\n\",r(s.p,{children:[a(s.a,{href:\"/ciam-compass/vendors/wso2-is/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"WSO2 Identity Server\"}),\" (WSO2 IS) launched in 2007 as part of WSO2's broader open-source middleware platform. By 2026 it sits as one of the longest-running and most feature-complete enterprise OSS CIAM platforms, Apache 2.0 licensed, with twenty years of enterprise federation expertise and a substantial install base across telecoms, banks, government, and large enterprise. Asgardeo is the managed cloud offering, built on the same Identity Server codebase.\"]}),\"\\n\",a(s.h2,{id:\"where-wso2-is-wins\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-wso2-is-wins\",children:\"Where WSO2 IS wins\"})}),\"\\n\",r(s.p,{children:[\"Enterprise feature depth above the OSS median. Adaptive MFA, \",a(s.a,{href:\"/ciam-compass/glossary/consent-management/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"consent management\"}),\", preference center, identity governance integration, and federation breadth that Keycloak does not match out of the box. Asgardeo provides a managed-cloud path with WSO2's enterprise pedigree behind it, uncommon in the OSS CIAM tier.\"]}),\"\\n\",a(s.h2,{id:\"where-wso2-is-hurts\",children:a(s.a,{className:\"heading-anchor\",href:\"#where-wso2-is-hurts\",children:\"Where WSO2 IS hurts\"})}),\"\\n\",a(s.p,{children:\"Heavy operational profile (Java + stateful service), DX trails developer-first tier substantially, opaque pricing for Asgardeo and Enterprise subscription, and a sprawling product family that complicates evaluation. For mid-market or developer-velocity-focused teams, simpler alternatives exist.\"}),\"\\n\",a(s.h2,{id:\"how-wso2-is-compares\",children:a(s.a,{className:\"heading-anchor\",href:\"#how-wso2-is-compares\",children:\"How WSO2 IS compares\"})}),\"\\n\",r(s.p,{children:[\"The closest comparisons are \",a(s.a,{href:\"/ciam-compass/compare/keycloak-vs-wso2-is/\",children:\"Keycloak vs WSO2 IS\"}),\", \",a(s.a,{href:\"/ciam-compass/compare/wso2-is-vs-auth0/\",children:\"WSO2 IS vs Auth0\"}),\", and \",a(s.a,{href:\"/ciam-compass/compare/wso2-is-vs-ping-identity/\",children:\"WSO2 IS vs Ping Identity\"}),\" for the enterprise-OSS choice. For modern OSS at lower operational weight, \",a(s.a,{href:\"/ciam-compass/vendors/fusionauth/\",children:\"FusionAuth\"}),\", \",a(s.a,{href:\"/ciam-compass/vendors/zitadel/\",children:\"Zitadel\"}),\", and \",a(s.a,{href:\"/ciam-compass/vendors/authentik/\",children:\"Authentik\"}),\" are the alternatives.\"]})]})}return{default:function(e={}){const{wrapper:r}=e.components||{};return r?a(r,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/wso2-is/",
    "edit_path": "content/vendors/wso2-is.mdx"
  },
  {
    "type": "vendor",
    "slug": "zitadel",
    "name": "Zitadel",
    "legal_name": "Zitadel AG",
    "parent_company": null,
    "acquired_by": null,
    "website": "https://zitadel.com",
    "docs_url": "https://zitadel.com/docs",
    "pricing_url": "https://zitadel.com/pricing",
    "github_url": "https://github.com/zitadel/zitadel",
    "hq": "Schaffhausen, Switzerland",
    "founded": 2020,
    "status": "active",
    "funding": {
      "model": "venture-backed",
      "total_raised_usd": 11500000,
      "last_round": {
        "stage": "series-a",
        "amount_usd": 9000000,
        "year": 2024,
        "lead": "Nexus Venture Partners"
      },
      "investors": [
        "Nexus Venture Partners",
        "Floodgate"
      ],
      "profitable": null,
      "notes": "Swiss open-source identity platform; $2.5M seed (2022) then a $9M Series A (2024), both led by Nexus.",
      "source": "https://zitadel.com/blog/fundraising-nexus"
    },
    "categories": [
      "open-source-ciam",
      "developer-first-ciam",
      "b2b-saas-ciam",
      "enterprise-ciam"
    ],
    "deployment": [
      "cloud-saas",
      "self-hosted"
    ],
    "target_segments": [
      "b2b-saas",
      "enterprise",
      "public-sector"
    ],
    "capabilities": {
      "authentication": {
        "passwords": true,
        "social_login": true,
        "magic_links": true,
        "sms_otp": true,
        "email_otp": true,
        "totp": true,
        "push_mfa": false,
        "webauthn_passkeys": true,
        "biometric": true,
        "hardware_keys": true,
        "sso_saml": true,
        "sso_oidc": true,
        "sso_oauth2": true,
        "enterprise_federation": true,
        "passwordless_only_flows": true,
        "adaptive_mfa": "partial",
        "step_up_auth": true
      },
      "authorization": {
        "rbac": true,
        "abac": "partial",
        "rebac": false,
        "fga_engine": false,
        "api_authorization": true,
        "fine_grained_permissions": true
      },
      "user_management": {
        "self_service_registration": true,
        "progressive_profiling": true,
        "self_service_account": true,
        "bulk_user_import": true,
        "user_search_admin": true,
        "custom_user_metadata": true,
        "organizations": true,
        "multi_tenancy": true,
        "scim": "partial"
      },
      "developer_experience": {
        "rest_api": true,
        "graphql_api": true,
        "sdks": [
          "js",
          "node",
          "go",
          "python",
          "dotnet",
          "java"
        ],
        "cli": true,
        "terraform_provider": true,
        "local_emulator": true,
        "extension_model": "Actions (custom code) + Event-driven webhooks"
      },
      "security": {
        "bot_detection": "partial",
        "breached_password_detection": true,
        "brute_force_protection": true,
        "anomaly_detection": "partial",
        "log_streams": true,
        "audit_logs": true,
        "gdpr_data_export": true,
        "pii_minimization": true,
        "post_quantum_roadmap": false
      },
      "agentic_identity": {
        "mcp_support": false,
        "oauth_2_1": true,
        "dynamic_client_registration": true,
        "agent_vs_human_token_separation": false,
        "web_bot_auth": false
      },
      "compliance": {
        "soc2_type2": true,
        "iso_27001": true,
        "iso_27018": false,
        "hipaa": false,
        "pci_dss": false,
        "gdpr": true,
        "ccpa": true,
        "fedramp": false,
        "eu_data_residency": true
      },
      "consent_and_privacy": {
        "consent_management": "partial",
        "preference_center": "partial",
        "purpose_specific_consent": false,
        "integrates_with_cmps": []
      },
      "scalability": {
        "multi_region": "partial",
        "data_residency_control": true,
        "high_scale_proven": "partial"
      },
      "enterprise_ops": {
        "migration_hash_import": true,
        "lazy_migration": "partial",
        "account_linking": "partial",
        "custom_domains_per_brand": true,
        "per_brand_theming": "partial",
        "consent_partitioning": false,
        "deletion_webhooks": "partial",
        "event_streaming": "partial",
        "rate_limit_transparency": "partial"
      }
    },
    "pricing": {
      "model": "tiered-mau",
      "free_tier": {
        "available": true,
        "mau_limit": 25000
      },
      "paid_starts_at_usd": 100,
      "enterprise_quote_required_above": "Self-hosted Enterprise license + dedicated tenancy",
      "notable_costs": [
        "Self-hosted Community edition is Apache 2.0, free at any scale; pay only operational cost",
        "Zitadel Cloud (managed) is per-MAU with Swiss data residency by default",
        "Self-hosted Enterprise license adds support SLAs and additional features",
        "Operational profile is lighter than Keycloak, single Go binary plus PostgreSQL"
      ],
      "tco_at_10k_mau_estimate_usd_per_month": 100,
      "tco_at_100k_mau_estimate_usd_per_month": 600,
      "tco_at_500k_mau_estimate_usd_per_month": 2400,
      "tco_at_1m_mau_estimate_usd_per_month": 4500,
      "pricing_transparency_score": 5
    },
    "dx_score": 4,
    "docs_quality": 4,
    "community_size": "medium",
    "github_stars": null,
    "passkey_native": true,
    "passkey_orchestration_quality": 3,
    "strengths": [
      "Modern Go-based architecture with event-sourcing under the hood, cleaner ops profile than Keycloak.",
      "First-class B2B Organizations and multi-tenancy as core data model, not bolt-ons.",
      "Strict Apache 2.0 licensing across the codebase; no commercial-use clauses.",
      "Swiss-headquartered with Swiss data residency on Zitadel Cloud, stronger sovereignty story than EU-only competitors for some buyers."
    ],
    "limitations": [
      "Smaller community than Keycloak or Ory; Stack Overflow coverage is thinner.",
      "Authorization stays at RBAC plus partial ABAC, no Zanzibar-style FGA.",
      "Adaptive MFA and risk decisioning are weaker than Auth0 or Descope; pair with Authsignal for orchestration.",
      "Compliance footprint is solid for B2B SaaS but lacks FedRAMP, HIPAA, and PCI DSS direct attestation on the managed product."
    ],
    "best_for": [
      "B2B SaaS that wants modern OSS with strong Organizations model",
      "Swiss / EU-sovereign deployments wanting managed CIAM with explicit data residency",
      "Self-hosted teams wanting lighter ops than Keycloak with strict OSS licensing"
    ],
    "not_for": [
      "Workloads requiring FedRAMP, HIPAA, or PCI DSS direct attestation",
      "Authorization-heavy use cases requiring Zanzibar-style FGA",
      "B2C consumer apps with serious adaptive risk and bot defense needs"
    ],
    "migration_difficulty": {
      "inbound": 3,
      "outbound": 3
    },
    "last_verified": "2026-05-14",
    "verified_by": "guptadeepak",
    "sources": [
      {
        "title": "Zitadel Pricing",
        "url": "https://zitadel.com/pricing",
        "accessed": "2026-04-22"
      },
      {
        "title": "Zitadel Documentation",
        "url": "https://zitadel.com/docs",
        "accessed": "2026-04-22"
      },
      {
        "title": "Zitadel GitHub",
        "url": "https://github.com/zitadel/zitadel",
        "accessed": "2026-04-22"
      }
    ],
    "editorial_verdict": "Zitadel is the modern open-source CIAM with the strongest B2B Organizations data model in 2026, Go-based, single-binary, event-sourced, and Apache 2.0 licensed throughout. For self-hosted teams that find Keycloak's operational profile too heavy and Ory's component model too complex, Zitadel splits the difference with a single deployment artifact and B2B-native primitives. Swiss data residency on Zitadel Cloud is a meaningful differentiator for sovereignty-conscious buyers.",
    "faqs": [
      {
        "q": "How does Zitadel differ from Keycloak and Ory?",
        "a": "Zitadel is a single Go binary with PostgreSQL, lighter ops than Keycloak's Java stack, simpler topology than Ory's component model. Where Keycloak has the largest community and Ory has the most modern architecture (and native FGA via Keto), Zitadel splits the practical middle: modern Go codebase, single deployment artifact, event-sourcing, and first-class B2B Organizations."
      },
      {
        "q": "Is Zitadel fully open source?",
        "a": "Yes, Apache 2.0 licensed across the codebase with no commercial-use clauses. Self-hosting is unrestricted at any scale. Zitadel Cloud (managed) and the Enterprise license tier add support and managed-service value, but the underlying product is genuinely OSS."
      },
      {
        "q": "What does Swiss data residency mean for Zitadel Cloud?",
        "a": "Zitadel Cloud's primary infrastructure is Swiss-hosted, which places it under Swiss data protection law rather than EU GDPR or US jurisdictions. For organizations subject to FADP (Switzerland's data protection regulation) or wanting jurisdictional separation from US-and-EU surveillance frameworks, this is a meaningful sovereignty signal."
      }
    ],
    "coi_disclosure": null,
    "changelog": [
      {
        "date": "2026-05-14",
        "summary": "Routine profile review: capabilities, pricing, and editorial verdict re-verified."
      }
    ],
    "body": "const{Fragment:e,jsx:a,jsxs:t}=arguments[0];function _createMdxContent(i){const n={a:\"a\",h2:\"h2\",p:\"p\",...i.components};return t(e,{children:[a(n.h2,{id:\"what-zitadel-is\",children:a(n.a,{className:\"heading-anchor\",href:\"#what-zitadel-is\",children:\"What Zitadel is\"})}),\"\\n\",t(n.p,{children:[\"Zitadel launched in 2020 from Schaffhausen, Switzerland with a clear thesis: the OSS CIAM market needed a modern Go-based platform with B2B Organizations as a first-class concept rather than a bolt-on, lighter operationally than \",a(n.a,{href:\"/ciam-compass/vendors/keycloak/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Keycloak\"}),\", and simpler topologically than Ory's component model. The product is a single Go binary backed by PostgreSQL, with an event-sourced data model under the hood. The buyer is typically a B2B SaaS team that wants OSS plus strong multi-tenancy, or an organization in Switzerland or the EU that wants explicit data sovereignty.\"]}),\"\\n\",a(n.h2,{id:\"where-zitadel-wins\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-zitadel-wins\",children:\"Where Zitadel wins\"})}),\"\\n\",a(n.p,{children:'The B2B Organizations model is among the strongest in the index, OSS or otherwise. Multi-tenancy is the core data primitive, not a feature added later, which means Organizations, projects, and applications nest cleanly with predictable behaviors. For B2B SaaS designing around tenant isolation, this avoids the \"we built it on top of user pool groups\" workarounds common to other platforms.'}),\"\\n\",a(n.p,{children:\"The operational profile is genuinely lighter than Keycloak. A single Go binary plus PostgreSQL, with event-sourcing for the audit and replication story, deploys with the patterns teams already use for any other Go service. The contrast with Keycloak's JBoss-style Java stack is meaningful for teams comfortable in modern container ops but uncomfortable with traditional Java-EE operational practices.\"}),\"\\n\",t(n.p,{children:[\"Strict Apache 2.0 licensing avoids the licensing friction that complicates \",a(n.a,{href:\"/ciam-compass/vendors/fusionauth/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"FusionAuth\"}),\" procurement at strict-OSS-only buyers. Swiss headquarters and Swiss data residency on Zitadel Cloud is a sovereignty differentiator that no other vendor in this index ships.\"]}),\"\\n\",a(n.p,{children:\"DX is high for the OSS CIAM tier, modern docs, idiomatic SDKs, GraphQL API alongside REST, real Terraform provider.\"}),\"\\n\",a(n.h2,{id:\"where-zitadel-hurts\",children:a(n.a,{className:\"heading-anchor\",href:\"#where-zitadel-hurts\",children:\"Where Zitadel hurts\"})}),\"\\n\",t(n.p,{children:[\"The community is smaller than Keycloak's and \",a(n.a,{href:\"/ciam-compass/vendors/ory/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Ory\"}),\"'s. Stack Overflow coverage is thinner; partner integrations are fewer. For most teams this is a non-issue; for teams that depend on community answers at production-edge cases, it's real friction.\"]}),\"\\n\",t(n.p,{children:[a(n.a,{href:\"/ciam-compass/glossary/authorization/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"Authorization\"}),\" is bounded. RBAC and partial ABAC are the model; there's no native Zanzibar-style FGA. For applications with fine-grained per-resource permissions, pair with OpenFGA, Authzed, or Permify.\"]}),\"\\n\",t(n.p,{children:[\"Adaptive MFA, risk decisioning, and bot defense are weaker than Auth0 or Descope. For B2C consumer apps facing serious account-takeover pressure, pair with \",a(n.a,{href:\"/ciam-compass/vendors/authsignal/\",className:\"auto-link auto-link-vendor\",\"data-autolink\":\"vendor\",children:\"Authsignal\"}),\" as an orchestration layer.\"]}),\"\\n\",t(n.p,{children:[\"Compliance breadth is good for B2B SaaS (SOC 2 Type II, ISO 27001, GDPR) but does not yet include FedRAMP, HIPAA, or PCI DSS direct \",a(n.a,{href:\"/ciam-compass/glossary/attestation/\",className:\"auto-link auto-link-glossary\",\"data-autolink\":\"glossary\",children:\"attestation\"}),\" on the managed product. For workloads requiring those, look elsewhere.\"]}),\"\\n\",a(n.h2,{id:\"how-zitadel-compares\",children:a(n.a,{className:\"heading-anchor\",href:\"#how-zitadel-compares\",children:\"How Zitadel compares\"})}),\"\\n\",t(n.p,{children:[\"The most relevant comparisons are \",a(n.a,{href:\"/ciam-compass/compare/keycloak-vs-zitadel/\",children:\"Keycloak vs Zitadel\"}),\" for the OSS-CIAM choice and \",a(n.a,{href:\"/ciam-compass/compare/zitadel-vs-ory/\",children:\"Zitadel vs Ory\"}),\" for the modern-OSS pick. For SaaS migrations, \",a(n.a,{href:\"/ciam-compass/compare/auth0-vs-zitadel/\",children:\"Auth0 vs Zitadel\"}),\" covers the SaaS-to-self-host call. For Swiss-and-EU sovereignty alternatives, \",a(n.a,{href:\"/ciam-compass/vendors/ory/\",children:\"Ory Network\"}),\" is the closest commercial peer.\"]})]})}return{default:function(e={}){const{wrapper:t}=e.components||{};return t?a(t,{...e,children:a(_createMdxContent,{...e})}):_createMdxContent(e)}};",
    "permalink": "/vendors/zitadel/",
    "edit_path": "content/vendors/zitadel.mdx"
  }
]