Top 10 Passwordless CIAM Solutions in 2026
Ten passwordless CIAM platforms compared on verified September 2026 pricing and real passkey depth, plus three vendors to drop from an older shortlist.
If you are replacing passwords in a customer-facing product, the platform you need depends on one question: are you adding passkeys to an identity system you already run, or replacing the identity system itself? For a fast passkey and OTP rollout on a consumer product, MojoAuth or Stytch. For flow orchestration your product team can change without an engineer, Descope. For enterprise breadth and compliance, Auth0, Okta, or Ping Identity. For self-hosting with no per-user fee, FusionAuth or Keycloak. For AWS-native stacks, Amazon Cognito Essentials.
Three vendors that appear on almost every other version of this list are no longer real options, and that alone is a reason to check the date on whatever you are reading. The removals are documented below.
How we evaluated
Every price, plan name, and free-tier limit here was read off the vendor's own pricing page or documentation in September 2026. Acquisition and end-of-sale claims were checked against the acquiring company's own announcement. Where a vendor publishes no list price, this page says so rather than inventing one.
Deepak Gupta founded LoginRadius and scaled it past a billion managed identities, and the axes here come from that vantage. Are passkeys a first-class self-serve registration flow or a bolt-on? How does account recovery work when the device is lost? Can the platform run passwordless and passwords side by side during a rollout? And how does cost behave as monthly active users grow?
Nothing on this page is a hands-on benchmark. It is a documentation, pricing, and changelog review, which is what a vendor shortlist should be built on.
Last verified: September 2026. Checked this pass: vendor pricing pages, product documentation, and acquisition and end-of-sale announcements for all ten platforms plus the three removals.
What changed since the last version of this list
ForgeRock is no longer a separate vendor. ForgeRock joined Ping Identity in August 2023. The platforms are one portfolio now, so evaluating both is evaluating one company. Ping is covered below.
CyberArk's customer identity product is gone. CyberArk closed its acquisition by Palo Alto Networks in February 2026, and the customer identity line did not survive it. CyberArk remains a privileged access management name; it is not a CIAM shortlist entry.
Azure AD B2C is closed to new customers. Microsoft stopped selling it on 1 May 2025. New customer-identity work on Microsoft goes to Entra External ID.
OneLogin is workforce-shaped. One Identity acquired OneLogin in October 2021. It is still a capable access-management product, but it is no longer a distinct customer-identity roadmap, so it is not ranked here.
Stytch is Twilio-owned as of November 2025, which belongs in a procurement review even though it did not change the product.
Quick comparison
| Platform | Pricing (Sept 2026) | Passwordless strength | Best for |
|---|---|---|---|
| Auth0 | Free to 25,000 MAU; B2C Essentials from $35/mo, Professional from $240/mo; B2B from $150/mo | WebAuthn plus the broadest surrounding platform | Mid-market to enterprise needing breadth and compliance |
| Okta | Workforce SSO from $6/user/mo; Customer Identity enterprise base $3,000/mo | Adaptive MFA, FIDO2, enterprise policy depth | Large enterprises standardising on one IAM vendor |
| Microsoft Entra External ID | Usage-based per MAU; quoted | FIDO2 keys, Authenticator, Conditional Access | Microsoft-centric organisations |
| Ping Identity | PingOne for Customers from $35k/yr (Essential), $50k/yr (Plus) | Enterprise federation, fraud signals, regulated industries | Banks, insurers, and other regulated enterprises |
| Stytch | Free to 10,000 MAU and agents; $125 per extra SSO or SCIM connection | Passkey-first by design, device fingerprinting | Consumer and B2B products rebuilding auth around passkeys |
| Descope | Free to 7,500 MAU; Pro from $249/mo; Growth from $799/mo | Drag-and-drop passwordless and step-up flows | Teams that change auth journeys every sprint |
| FusionAuth | Community free and unlimited; Starter from $162/mo annual; Essentials and Enterprise from $2,970/mo | WebAuthn and TOTP, self-hosted, no per-MAU fee | Teams with ops capacity and data-residency needs |
| MojoAuth | Free to 25,000 MAU; Business Pro from $50/mo | Passwordless-first: passkeys, magic links, multi-channel OTP | SaaS and ecommerce optimising login conversion |
| Amazon Cognito | Essentials free to 10,000 MAU then $0.015; Lite $0.0055; Plus $0.020 | Passwordless and passkeys on the Essentials tier | AWS-native applications |
| Keycloak | Free, Apache 2.0; infrastructure and staff only | WebAuthn built in, bare default UI | Data sovereignty and zero licence cost |
Pick by the job you are doing
| If you need | Look at |
|---|---|
| Passkeys and OTP live on a consumer product fast | MojoAuth, Stytch |
| Auth flows non-engineers can change | Descope |
| Developer breadth and a large connector catalog | Auth0 |
| Enterprise governance and lifecycle | Okta |
| Regulated industry federation and fraud signals | Ping Identity |
| Microsoft ecosystem alignment | Entra External ID |
| Self-hosting with full infrastructure control | FusionAuth, Keycloak |
| AWS-native, lowest per-user cost | Amazon Cognito |
1. Auth0: the broadest platform around the passwordless feature
Auth0 supports WebAuthn passkeys, email and SMS one-time codes, magic links, and push, alongside adaptive MFA and anomaly detection. Its real advantage is not the passwordless feature set, which several smaller vendors match, but everything around it: a large federation catalog, B2B Organizations, extensive SDKs, and the compliance evidence enterprise buyers ask for.
Pricing (verified September 2026). The free tier covers 25,000 MAU. B2C Essentials starts at $35 per month and Professional at $240. B2B Essentials starts at $150 per month and Professional at $800. Enterprise is quoted.
Honest weakness. The free tier is generous and the step up to paid is steep, and the curve steepens again past 100,000 MAU. For an organisation whose only requirement is passwordless login, the platform's breadth is complexity you pay for and do not use. Decide whether you need the surrounding platform before you buy it. See the full Auth0 alternatives comparison and Auth0 Isn't Overpriced, You're the Wrong Buyer.
2. Okta: enterprise policy depth and adaptive MFA
Okta's customer identity product covers passwordless sign-in with FIDO2 and biometrics, adaptive MFA that weighs device, location and behaviour, full customer lifecycle management, API access management, and a very large pre-built integration catalog. It is the choice when passwordless is one requirement inside a governance and compliance programme.
Pricing (verified September 2026). Okta publishes Workforce SSO at $6 per user per month on the Starter suite and $17 on Essentials, both billed annually. Customer Identity carries a $3,000 per month enterprise base platform fee billed annually, with usage-based add-ons quoted against total annual MAU. Okta also owns Auth0, so shortlisting both is one vendor relationship.
Watch out. That base platform fee is the floor. For a startup adding passkeys to a consumer app, this is the wrong shelf entirely.
3. Microsoft Entra External ID: passwordless inside the Microsoft tenant
Entra External ID brings customer and partner identity into the Microsoft cloud with FIDO2 security keys, Microsoft Authenticator, Windows Hello, Conditional Access policies that weigh device health and risk, and Identity Protection for leaked-credential and anomalous-sign-in detection.
What to know before shortlisting. Azure AD B2C, the product most older guides name here, has not been sold to new customers since 1 May 2025. New work goes to Entra External ID. B2C's Identity Experience Framework custom policies were powerful and genuinely hard to maintain, and that history matters if you are inheriting an existing deployment rather than starting fresh.
Watch out. It suits organisations already standardising on Microsoft 365 and Azure. Outside that gravity, the configuration model costs more than it returns.
4. Ping Identity: regulated enterprises, and the home of ForgeRock
Ping covers passwordless and FIDO2, adaptive and risk-based authentication, API security, fraud signals, consent management, and hybrid deployment across cloud and on-premises. It is strongest where the requirement is regulatory: financial services, insurance, healthcare, and government.
Pricing (verified September 2026). Unusually for this tier, Ping publishes numbers. PingOne for Customers starts at $35,000 annually for Essential and $50,000 annually for Plus. PingOne for Workforce is $3 per user per month on Essential and $6 on Plus, based on a 5,000-user minimum annual contract.
ForgeRock. ForgeRock joined Ping in August 2023 and is not a separate evaluation. If a comparison still lists both, it predates the merger. For the enterprise detail, see Auth0 vs ForgeRock.
5. Stytch: passkey-first by design
Stytch built its orchestration around passwordless rather than retrofitting it onto a password core. Passkeys, magic links, one-time codes, embedded flows, and device fingerprinting are the primitives, and the developer surface is cleaner than the accreted feature sets of the older platforms. Twilio acquired Stytch in November 2025.
Pricing (verified September 2026). The pay-as-you-go plan includes 10,000 monthly active users and AI agents at no cost, with unlimited organizations, five SSO or SCIM connections, and 1,000 machine-to-machine tokens. Extra SSO or SCIM connections are $125 each. Fraud fingerprinting is $0.005 per fingerprint beyond 10,000 included.
Watch out. The enterprise federation catalog is smaller than Auth0's or Okta's. Demo the identity providers your largest customers actually run. Head to head: Clerk vs Stytch and Stytch vs Descope.
6. Descope: passwordless flows in a visual builder
Descope's differentiator is a drag-and-drop builder for authentication and user journeys, including passkey enrolment, step-up authentication, and progressive profiling. If your passwordless rollout keeps stalling because every flow change needs an engineer and a deploy, this is the direct answer.
Pricing (verified September 2026). Free Forever covers 7,500 MAU with all authentication methods, RBAC, MFA, three SSO connections, and one OIDC federated app. Pro starts at $249 per month for 10,000 MAU, Growth at $799 per month for 25,000 MAU, both billed annually with usage-based overage. The free tier does not permit overages; you upgrade instead.
Watch out. Visual orchestration is a different mental model. Code-first teams often find it indirect rather than faster.
7. FusionAuth: passwordless you host yourself
FusionAuth is a single-binary, API-first CIAM supporting WebAuthn and FIDO2, TOTP authenticator apps, email and SMS codes, magic links, and social login, with per-tenant theming and multi-tenancy. You run it on your own infrastructure or in FusionAuth Cloud, and there is no per-active-user charge on the self-hosted Community edition.
Pricing (verified September 2026, and it has changed). Older comparisons quote "$37 per month cloud, $125 per month self-hosted". Those figures are obsolete. The current pricing page lists Community as free and unlimited with the core authentication features, Starter from $162 per month billed annually, and Essentials and Enterprise from $2,970 per month billed annually. Cloud and self-hosted share the same four tiers.
Watch out. Self-hosting moves the cost from an invoice to an on-call rota, and the licence is not OSI-approved, which some procurement teams block outright.
8. MojoAuth: the shortest path to passwordless
MojoAuth is passwordless-first rather than passwordless-capable: email, SMS and WhatsApp OTP, magic links, and passkeys via WebAuthn, behind a hosted login page or SDKs. Multi-channel OTP delivery is the differentiator for products with users outside SMS-friendly markets, where WhatsApp delivery lands and SMS does not.
Pricing (verified September 2026). The free tier covers 25,000 MAU permanently with email OTP, magic links, social login, and basic attack protection. Business Pro starts at $50 per month for 5,000 MAU and adds passkeys, phone OTP, custom domain branding, MFA, team management, and SSO. Enterprise private cloud is quoted, with dedicated infrastructure and a 99.99 percent uptime SLA. Startups and non-profits get 50 percent off annual billing.
Watch out. No SCIM provisioning, so it does not satisfy an enterprise directory-sync requirement, and admin analytics are lighter than an enterprise IAM suite. Multi-channel OTP also means your login availability depends on email and messaging deliverability, which is worth a runbook.
9. Amazon Cognito: passwordless on the Essentials tier
Cognito added passwordless sign-in and passkeys to its Essentials tier, alongside user pools, OIDC and SAML federation, Lambda triggers, MFA, and threat protection on the Plus tier. For an AWS-native stack, identity stays inside the same account and IAM model.
Pricing (verified September 2026, and the old numbers are wrong). The 50,000 free MAU tier most comparisons still quote was replaced in November 2024. Current Cognito pricing has three tiers. Lite is free to 10,000 MAU then $0.0055 per MAU. Essentials, the default for new pools and the tier that carries passwordless and passkeys, is free to 10,000 MAU then $0.015. Plus has no free tier at $0.020 per MAU. SAML and OIDC federation bills separately at $0.015 per MAU above 50 MAU. Pools created before 22 November 2024 on Lite can retain the legacy free tier under documented conditions.
Watch out. Passwordless costs you the Essentials tier, which is roughly three times the Lite rate. The hosted UI is constrained and flow customisation runs through Lambda triggers. See the full Cognito alternatives comparison.
10. Keycloak: passwordless with no licence fee
Keycloak supports WebAuthn and FIDO2 natively alongside OIDC, OAuth 2.0 and SAML 2.0, identity brokering, LDAP and Active Directory federation, and SPI extension points, under Apache 2.0 with no per-user charge at any scale.
Release status (verified September 2026). Keycloak 26.7.4 shipped on 16 September 2026. The project maintains no long-term-support line: only the newest release receives security fixes, so continuous upgrades are part of the commitment.
Watch out. The default passkey experience is bare. Adoption stays low unless you invest in theming or put an overlay in front of it, and that work is the hidden cost of the free licence. Budget roughly half to one engineer for the deployment overall.
A note on passkey-specialist overlays
If your identity platform is fine and only the passkey experience is weak, you do not necessarily need to migrate. Specialist vendors such as Corbado and Hanko sit in front of an existing identity provider and own the passkey registration, conditional UI, and fallback experience, which is often where adoption is actually won or lost. The CIAM Compass covers the trade-off in passkey overlays versus CIAM and ranks the specialists in passkey orchestration vendors 2026.
What actually decides a passwordless rollout
Account recovery, not enrolment. Every platform here can register a passkey. The design that matters is what happens when a user loses the device, gets a new phone, or logs in from a shared machine. A weak recovery path either locks users out or reopens the phishing hole you just closed. Start with account recovery design.
Running both methods at once. Real rollouts run passwords and passwordless side by side for months. Check that the platform supports a per-user or per-cohort switch rather than a global one, so you can ramp.
SMS is the weak link. SMS one-time codes are the most widely supported passwordless method and the least secure, vulnerable to SIM swap and interception. Treat SMS as a fallback with a deprecation plan, not a destination. See the SMS OTP deprecation guide and magic links versus OTP.
Measure the right thing. The business case for passwordless is fewer password-reset tickets, lower account-takeover loss, and higher completion at login and checkout. Instrument those three before you migrate, or you will have no way to prove the project worked.
Working artefacts: the passwordless implementation checklist and the solution selection matrix. Technical background: passkeys explained, WebAuthn explained, and passkeys versus passwords.
How to choose
Match the platform to the constraint that is actually binding. Consumer product where login conversion is the metric: MojoAuth or Stytch. Flows that change constantly: Descope. Enterprise breadth, connectors, and compliance: Auth0 or Okta. Regulated industry with hybrid deployment: Ping Identity. Microsoft shop: Entra External ID. AWS-native: Cognito Essentials. Data residency or zero licence cost: FusionAuth or Keycloak.
For the full scored matrix across every vendor on one set of axes, see the CIAM providers directory, the top CIAM solutions ranking, and the complete guide to CIAM.
Frequently Asked Questions
Which CIAM platforms support passwordless and passkeys?
All ten above support passkeys in some form, but the depth varies and that is the whole evaluation. Stytch, Descope, and MojoAuth treat passkeys as a first-class, self-serve registration flow. Auth0, Okta, Entra External ID, and Ping support WebAuthn inside a larger platform, so enrolment and conditional UI need more configuration. Keycloak has WebAuthn built in with a bare default interface. Amazon Cognito requires the Essentials tier for passwordless and passkeys.
Is passwordless CIAM the same as passkey support?
No. Passwordless is the category and covers magic links, one-time codes over email, SMS or WhatsApp, push approval, and device-bound biometrics. Passkeys are one method inside it, and the strongest one, because they are phishing-resistant by design: the credential is bound to the site origin and the private key never leaves the device. A platform can be passwordless without supporting passkeys well, which is why the per-vendor notes above separate the two.
Do I need a dedicated passwordless platform, or can I add passkeys to what I already run?
Usually you can add them. Every major identity provider has shipped passkey support rather than requiring a separate product, so the practical question is whether your current platform's implementation covers your actual users across their real browsers and devices. If the platform is fine and only the passkey experience is weak, a specialist overlay such as Corbado or Hanko is cheaper than a migration. Switch platforms when the limitation is architectural rather than cosmetic.
How much does passwordless CIAM cost compared with passwords?
Most platforms charge per monthly active user regardless of method, so passwordless is rarely a direct cost driver. Two exceptions are worth budgeting. Amazon Cognito puts passwordless and passkeys on the Essentials tier at $0.015 per MAU against Lite at $0.0055, so it roughly triples the per-user rate. Anything using SMS one-time codes pays per message, and at global scale that line can exceed the platform fee. The offsetting savings are fewer password-reset tickets, lower account-takeover losses, and higher login completion.
Can passwordless CIAM handle enterprise-scale deployments?
Yes. Okta, Ping Identity, and Microsoft Entra all run hundreds of millions of identities with global distribution, and Auth0, FusionAuth, and Keycloak scale to enterprise volumes on very different architectures. Scale is rarely the constraint. The constraints that actually bite at enterprise size are account recovery design, per-cohort rollout control, regional data residency, and whether your existing identity providers are in the vendor's federation catalog.
Which vendors should I drop from an older passwordless shortlist?
Three. ForgeRock is not separate from Ping Identity, having joined it in August 2023. CyberArk's customer identity product is gone following the close of the Palo Alto Networks acquisition in February 2026. Azure AD B2C has not been sold to new customers since 1 May 2025, so Microsoft evaluations should be scoped to Entra External ID. OneLogin still exists under One Identity but is workforce-shaped rather than a customer-identity roadmap.
More from Deepak Gupta
Every page on guptadeepak.com is hand-curated by Deepak Gupta. Pick a thread:
- About Deepak Gupta Founder, cybersecurity architect, and writer at guptadeepak.com.
- My journey From LoginRadius (2013, 1B+ users) to GrackerAI, in milestones.
- Publications & patents Books, free e-books, a journal special issue, and five granted patents.
- Research Hub Curated research, buyer's guides, vendor comparisons, and technical deep-dives.
Get the newsletter
New writing on identity, AI security, and building software, delivered when it ships. No tracking pixels, no funnels, unsubscribe with one click.