Skip to content
By CIAM

The Identity Tax: What Auth Actually Costs Per Closed Deal

Everyone argues about auth pricing. Almost nobody accounts for what identity actually costs per closed deal, or notices the invoice founders obsess over is the smallest of four identity costs.

The Identity Tax: What Auth Actually Costs Per Closed Deal, by Deepak Gupta on guptadeepak.com

Sit in enough B2B SaaS budget meetings and you notice the same scene repeat. A founder squints at the identity vendor's invoice, a number in the tens of thousands, and asks some version of “why is login so expensive.” It's a fair question with a boring answer, and the whole conversation misses the point.

The invoice is not the identity tax. The invoice is the smallest, most visible slice of it. Authentication costs a B2B SaaS company money in four different places, only one of which shows up as a line item anyone stares at, and the one everyone stares at is usually the cheapest. Founders agonize over a $40,000 vendor bill while a signup flow two clicks away quietly leaks ten times that in conversion, unmeasured, because nobody ever put a dollar figure on it.

I've been on three sides of this. I built a customer identity platform to more than a billion users, so I've been the vendor sending the invoice founders resent. I've watched that same category of bill hit my own P&L as a founder. And I mentor founders through the exact deal math this article lays out. What I want to do here is what almost nobody does: stop treating auth as a pricing question and start accounting for it as a cost per closed deal, because that reframe changes which number you should actually be worried about.

The four costs, not one

Identity shows up on your books in four distinct places. Most teams can see one clearly, sense a second dimly, and have never quantified the other two at all.

Cost one: the vendor invoice. The visible one. Your CIAM or auth platform's monthly bill. This is real money and worth managing, but it's the slice everyone overweights precisely because it's the only one with its own line item. I've written a whole framework for who's actually overpaying here versus who's getting fair value in Auth0 Isn't Overpriced, You're Just the Wrong Buyer. For this piece, hold one fact: for most B2B SaaS companies, this is not the biggest identity cost. It just feels like it because it arrives as a bill.

Cost two: the deal-gating cost, the SSO tax you pay. This is the one that determines whether enterprise revenue exists at all, and it runs in both directions. Every B2B SaaS company hits the same wall at the same moment: a promising deal reaches procurement, the security questionnaire comes back, and one line stops everything. Does your product support SAML SSO and automated provisioning? If the answer is no, the deal doesn't negotiate, it stalls. Enterprises will not manage another standalone password store, so SSO is not a feature request, it's the price of entry.

Cost three: the abandonment cost, the identity tax you're paying without knowing. This is the invisible giant, and I'll spend real time on it below, because it's the one that's usually larger than the vendor invoice and almost never measured.

Cost four: the breach-and-compliance cost, the insurance you're actually buying. What a chunk of your identity spend really purchases is not “login.” It's the SOC 2 evidence, the audit trail, the reduced blast radius that keeps a credential incident from becoming a company-ending event. Priced against the thing it prevents, this cost is almost always trivial, which is exactly why it's miscategorized as an expense rather than insurance.

Four costs. Now the accounting, because the interesting part is how wildly they differ in size, and how backwards most teams have the ranking.

The deal-gating cost: real, but pointing the wrong way

Start with the cost founders do sense: the SSO tax. Two things are true about it at once, and holding both is the whole trick.

First, it's real, and it's often outrageous. The public sso.tax catalog now tracks around 150 vendors, 104 with a computable markup and 44 that simply say “contact sales.” The markups span orders of magnitude. GitHub moves from $4 to $21 per user to add SAML, a 425% jump. At the extreme, some vendors gate SSO behind minimums that work out to thousands of percent over the plan below. Independent tracking puts the median premium across tracked vendors well above the point where CISA calls it a security anti-pattern, and CISA's position is blunt: SSO “should be available by default as part of the base offering,” and customers “should not need to bear an onerous SSO tax.”

Second, and this is the part that reframes it: the SSO tax you resent paying to your vendors is the mirror image of the SSO tax you're deciding whether to charge your customers, and both decisions are usually made on the wrong axis. When you pay it, it feels like extortion. When you charge it, it feels like smart packaging. The honest framing is neither. SSO is the gate to a different tier of customer entirely. SMB contracts might run $5K to $15K a year; enterprise contracts start at $50K and reach into the hundreds of thousands. The single feature that most reliably separates “enterprise-ready” from “not” is SSO. So the deal-gating cost is not really a cost. It's the toll on the bridge to your entire enterprise segment, and pricing it as if it were a cost center is how companies leave that segment unbuilt.

Here's the sharper version, and it's where the accounting gets useful. If adding SSO unblocks a $100K contract, and the identity spend to support that contract runs, generously, a few thousand dollars a month, then identity is on the order of 2 to 4% of the annual contract value it makes possible. State that as a ratio and the “auth is expensive” conversation collapses. You are not spending money on login. You are spending 3% of a deal to make the other 97% collectible. A founder arguing about the per-connection rate while that ratio holds is optimizing the wrong number.

The place the deal-gating cost genuinely bites is in what you gate, not whether you pay. The defensible 2026 move is not to gate SSO itself, which is now a procurement liability and a public-shaming risk, but to include SSO on any paid business plan and reserve premium pricing for SCIM provisioning, audit-log streaming, and session policy, the things with real ongoing cost that enterprises will pay for without feeling taxed. I laid out how to add SSO without either overpaying your vendor or overcharging your customer in the guide to escaping the SSO tax, and the deeper picture of which vendor fits which stage is in the Auth0 vs Okta vs Stytch vs WorkOS buyer-stage framework.

The abandonment cost: the tax you're already paying, blind

Now the invisible giant, and the reason this article exists.

Every identity conversation in B2B SaaS is dominated by the enterprise end of the funnel, the SSO gate, the security questionnaire, the six-figure deal. Almost none of it looks at the top of the funnel, where the same identity system is quietly bleeding conversion on every single signup and login, and where the losses are usually far larger than the vendor invoice everyone's arguing about.

The numbers are not subtle. Roughly 25% of users abandon account creation the moment they're asked to set a password. The Reforge 2025 PLG benchmarks attribute 18 to 24% of B2B SaaS signup-form abandonment specifically to password-creation friction, worse on mobile. On the returning-user side, about 19% of users abandon a login because they forgot their password. Median B2B SaaS signup drop-off runs 60 to 80%, meaning fewer than half who start ever finish, and analyses attribute a large share of that specifically to credential and form friction. Teams that remove password creation from signup consistently see completion improve 20 to 35% and, most importantly, trial-to-paid conversion improve 8 to 15%.

Now put a dollar sign on it, because that's the move nobody makes. Take a modest PLG company: 10,000 signup starts a month, a $15K average contract value, and a trial-to-paid rate you're trying to improve. An 8 to 15 percentage-point lift in trial-to-paid conversion from removing password friction is not a rounding error. Against that ACV and volume, it's the kind of number that, annualized, dwarfs a $40K yearly auth invoice by a wide multiple. The signup leak is a bigger identity cost than the vendor bill, and it's the one line item that has no line item, so it never gets managed.

This is the core inversion of the whole piece. The invoice is loud, itemized, and small. The abandonment cost is silent, unlabeled, and large. Founders spend a quarter negotiating 15% off the vendor bill and never spend an afternoon instrumenting where the signup funnel loses half its users. As the Corbado analysts put it, checkout abandonment gets obsessed over while login failure goes unmeasured and unfixed, even though every failed login is wasted customer-acquisition cost and a customer who may just leave for a competitor with a smoother door.

The reason this cost stays invisible is organizational, not technical. The vendor invoice lands on finance's desk with a number on it. The abandonment cost is smeared across growth, product, and engineering, and shows up only as a conversion rate nobody has decomposed. So it gets treated as “just how funnels work” rather than as an identity cost you can attack. It is an identity cost. It's probably your largest one. And the fix, moving password creation out of the critical path in favor of passwordless or deferred credential creation, is cheap and well understood, which makes leaving it unfixed the most expensive passive decision in your identity budget.

The breach cost: insurance you've miscategorized as expense

The fourth cost is the one that's almost always trivial relative to what it prevents, and gets cut in exactly the budget cycles where it matters most.

A meaningful fraction of your identity spend isn't buying authentication, it's buying the evidence and the containment that keep a bad day from becoming a fatal one: the SOC 2 report that unblocks the deal, the audit trail you'll need mid-incident, the short session lifetimes and phishing-resistant credentials that shrink the blast radius when, not if, a credential gets compromised. Set against average breach costs in the millions, and against the specific failure mode of a regulated deal falling through because you couldn't produce an audit log, this spend rounds to zero. The mistake is filing it under “auth expense” next to the vendor invoice, where it competes with features for budget, instead of under “insurance,” where it would obviously survive. When a team cuts identity spend to hit a margin target, this is usually the cost they're unknowingly cutting, and it's the one they can least afford to.

The accounting, put together

Line the four costs up and the ranking most teams carry in their heads is upside down.

The vendor invoice is the one they manage hardest and it's typically the smallest controllable number. The deal-gating cost feels like a cost and is actually the toll that opens your entire enterprise segment, so cutting it is cutting revenue, not expense. The abandonment cost is the one nobody has quantified and it's usually the largest, a silent multiple of the invoice, sitting in a funnel no one has instrumented. And the breach cost is insurance miscategorized as expense, trivial against what it prevents and cut at exactly the wrong time.

The reframe that fixes all four is to stop asking “what does our auth cost” and start asking “what does identity cost us per closed deal, and where in that number is the real lever.” Answer it and the priorities invert cleanly. Instrument the signup and login funnel before you renegotiate the vendor bill, because the leak is bigger than the invoice. Treat SSO as the toll on the enterprise bridge, include it on paid plans, and price SCIM and audit streaming instead. Keep the breach spend and re-file it mentally as insurance. And by all means manage the vendor invoice, just with the correct knowledge that it's the smallest of the four and the last place your attention pays off.

Auth isn't expensive. It's mis-accounted. The bill you can see is the least of what identity costs you, and the cost that's eating you alive doesn't have a line item at all.

What's your identity cost per closed deal, and have you ever actually added up all four pieces, or just the one that arrives as an invoice?

FAQ

What is the “identity tax” for a B2B SaaS company?

It's the full cost of authentication across four areas, not just the vendor invoice: (1) the CIAM/auth vendor bill, (2) the deal-gating SSO cost that determines whether enterprise revenue is reachable, (3) the conversion lost to signup and login friction, and (4) the breach-and-compliance spend that functions as insurance. Most teams only account for the first, which is usually the smallest.

Is the vendor invoice really the smallest identity cost?

For most B2B SaaS companies, yes. The signup-abandonment cost (conversion lost at the password field) is frequently a multiple of the annual vendor bill but goes unmeasured because it has no line item. Around 25% of users abandon signup when asked to set a password, and removing that friction commonly lifts trial-to-paid conversion 8 to 15%, a number that annualized often dwarfs the auth invoice.

Should I charge my customers for SSO (the “SSO tax”)?

Gating SSO itself is increasingly a procurement liability, and CISA formally recommends SSO be included in base offerings. The defensible approach in 2026 is to include SSO on any paid business plan and reserve premium pricing for SCIM provisioning, audit-log streaming, and session policy, features with genuine ongoing cost that enterprises will pay for without feeling penalized.

How do I calculate authentication cost per closed deal?

Add all four costs (vendor invoice, deal-gating investment, abandonment/conversion loss, and breach/compliance spend) and divide by deals closed, rather than looking at the invoice alone. A useful sanity check: if adding SSO unblocks a $100K contract and identity spend to support it runs a few thousand a month, identity is roughly 2 to 4% of the contract value it makes possible, which reframes “auth is expensive” entirely.

Why is the signup-abandonment cost so hard to see?

It's organizational. The vendor invoice lands on finance's desk as a single number, while the abandonment cost is spread across growth, product, and engineering and appears only as an undecomposed conversion rate. So it gets accepted as “how funnels work” rather than attacked as an identity cost, even though it's usually the largest of the four.


Deepak Gupta is a serial entrepreneur and cybersecurity researcher who founded and scaled a CIAM platform to 1B+ users. He writes about AI, cybersecurity, and B2B growth at guptadeepak.com.

Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:

Get the newsletter

New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.