The strongest Auth0 alternatives depend on who is signing in. Keycloak and ZITADEL are the open-source picks for developers who want to own the identity layer, and Clerk is the hosted pick for teams that want working sign-in screens quickly. If you are replacing Okta or OneLogin for staff single sign-on, Authentik and Microsoft Entra ID fit better.
Auth0 and FusionAuth are customer identity products, where the people logging in are your app's users. Okta and OneLogin are workforce products, where they are your employees. This guide covers twelve picks across both jobs and says which job each one does.
| Tool | Type | Self-host | Pricing | GitHub |
|---|---|---|---|---|
| SaaS | No | Free plan · from $35/mo | Closed source | |
| SaaS | No | From $6/mo per seat | Closed source | |
| Open source | Yes | Free (open source) | ★ 37k | |
| Open source | Yes | Free · cloud from $100/mo | ★ 15k | |
| Open source | Yes | Free (open source) | ★ 15k | |
| Open source | Yes | Free · cloud from $24/mo | ★ 15k | |
| Open source | Yes | Free · cloud from $770/yr | ★ 14k | |
| Open source | Yes | Free (open source) | ★ 26k | |
| SaaS | No | Free plan | Closed source | |
| SaaS | No | Free plan | Closed source | |
| SaaS | No | Free plan | Closed source | |
| SaaS | No | From $11/mo per seat | Closed source |
Live data from Enlisted: GitHub stats sync daily; pricing comes from each vendor's pricing page.
Why people look for Auth0 alternatives
Auth0 is a hosted authentication and authorization platform with SDKs and quickstarts for adding login, single sign-on and access control to apps. Teams comparing it with other tools usually cite one of these reasons:
- The bill follows your user count. Auth0's pricing page counts monthly active users, defined as non-employee users who authenticate in a given month, and charges the next tier up when usage falls between published tiers. Growth in sign-ins raises the invoice.
- B2B features cost extra. Auth0 prices B2C and B2B plans separately, and enterprise SSO connections beyond the ones included are billed per connection, so selling to larger customers changes the cost.
- It is closed source and hosted only. Enlisted lists no self-hosted version, so user records stay with the vendor.
- Vendor ownership. Okta, the workforce identity vendor, also owns Auth0, so teams that want customer identity from a different vendor, or from open source, have alternatives to compare.
- Data and customisation control. Self-hosted identity servers let you keep user tables in your own database and change the sign-in flow in code.
How we picked
A product made this list if it handles the core job of an identity provider: sign-in, single sign-on and multi-factor authentication through standards such as OpenID Connect and SAML. Open-source tools needed a clear licence and recent GitHub activity, and Enlisted shows whether each can be self-hosted. Hosted products are included for their published pricing model and free plan. None of this is first-hand testing: the descriptions come from Enlisted's catalogue and each vendor's documentation. See how Enlisted ranks tools.
Customer identity or workforce SSO?
Pick the job before the product, because the two categories share a name and little else.
- Customer identity (CIAM): your product's users sign up and log in. You need embeddable screens, SDKs, social login, passkeys, organizations for B2B customers and usually a per-user price. Auth0 and FusionAuth live here, along with most tools below from Keycloak to WorkOS.
- Workforce identity (SSO): employees sign in once to many third-party apps. You need directories, app catalogues, provisioning and policy. Okta and OneLogin live here, with Authentik, Authelia, Microsoft Entra ID and JumpCloud as replacements.
Keycloak and ZITADEL can do both, and Okta covers both by selling workforce suites and, through Auth0, customer identity.
1. Keycloak: best open-source identity server for apps and staff
Keycloak is an open-source identity and access management server, written in Java under the Apache-2.0 licence, that adds single sign-on, user management and authorization to applications. Where Auth0 gives you a hosted tenant, Keycloak is software you run: users and sessions sit in your own database.
It supports OpenID Connect and SAML, federates with external directories, and offers fine-grained authorization policies and several multi-step authentication options. You can run the downloadable distribution or the official Docker image from Quay for containers and Kubernetes. Enlisted lists no vendor cloud for the project itself.
- Best for: teams with platform engineers who want a free, standards-based identity provider for customer apps, internal tools or both.
- Watch out for: you own upgrades, the database, scaling and the look of the sign-in pages, and the admin surface takes time to learn.
2. ZITADEL: best open-source choice for multi-tenant B2B products
ZITADEL is an open-source identity platform with single sign-on, multi-factor authentication, passkeys, OIDC, SAML and SCIM, built API-first around multi-tenancy. Its README sets it against FusionAuth, Keycloak and Auth0 or Okta on points such as self-hosting, native B2B organizations and an event-stream audit trail.
That makes it a natural fit when each of your customers needs its own organization with its own members and login rules. It is licensed under AGPL-3.0 and available self-hosted or as a cloud service, with a free cloud plan and paid plans above it.
- Best for: SaaS companies that sell to businesses and want organizations, SSO and provisioning without building them.
- Watch out for: AGPL-3.0 has network-use obligations, so read it before you modify and host the code, and note that the cloud plans meter daily active users, not monthly ones.
3. SuperTokens: best for login that lives inside your own backend
SuperTokens is an open-source authentication provider, positioned by its project as an alternative to Auth0, Firebase Auth and AWS Cognito, that you wire into your app through SDKs. A frontend SDK handles session tokens and login widgets, a backend SDK exposes the sign-up and sign-in APIs, and a Java core service holds the authentication logic and database operations.
Features include passwordless and social login, session handling with token refresh, MFA, multi-tenant organizations with enterprise SSO, user roles and a user dashboard. Self-hosting is free according to the vendor, and a managed cloud is free up to a user threshold, then billed per active user. Enlisted lists the licence as Other.
- Best for: developers who want login and sessions in their own stack, with a self-host option.
- Watch out for: self-hosting means running the core service and its database, and the licence needs reading before you redistribute anything.
4. Logto: best open-source Auth0-style sign-in for SaaS and AI products
Logto is an open-source identity platform for sign-in, sign-up and access control, built on OpenID Connect and OAuth 2.1 with SAML support. It is licensed under MPL-2.0 and aimed at SaaS products and AI or agent-based platforms.
It includes multi-tenancy with organizations, member invites and role-based access, enterprise SSO, and customisable prebuilt sign-in pages. Sign-in methods cover social login, passwordless, MFA and Google One Tap, and SDKs exist for React, Next.js, Angular, Vue, Flutter, Go, Python and more. A free cloud plan exists, and self-hosting is available.
- Best for: product teams that want hosted-style sign-in screens with open code and a self-host exit.
- Watch out for: check which enterprise SSO and organization features sit on your chosen cloud plan before you commit.
5. Ory Kratos: best headless identity system for custom front ends
Ory Kratos is an API-first identity and user management system written in Go and licensed under Apache-2.0. It handles login, registration, recovery, verification and profile management, so your services call HTTP APIs instead of rebuilding those flows. Its own summary names Auth0 and Firebase as the products it replaces.
Supported methods include MFA, passkeys, social sign-in, OIDC, magic links, SMS and TOTP, with configurable identity schemas. It is headless, so it works with any UI framework. The wider Ory stack adds Ory Hydra for OAuth 2.0 and OpenID Connect, and Ory sells a hosted Ory Network.
- Best for: engineering teams that want full control of the screens and identity data model, often on Kubernetes.
- Watch out for: you build the user interface yourself, and OAuth2 provider duties live in a separate service.
6. Hanko: best open-source option for passkey-first login
Hanko is an open-source authentication and user management service built around passkeys, with passwords, email passcodes, TOTP and security-key MFA, social login, custom OIDC and OAuth connections, and SAML enterprise SSO. Its README presents it as an alternative to Auth0, Clerk, WorkOS and Stytch.
Hanko Elements web components and a JavaScript SDK keep integration short, and you can choose passkey-only setups. It runs self-hosted or on Hanko Cloud, which has a free tier. The catalogue lists the licence as Other.
- Best for: apps that want phishing-resistant, passwordless sign-in without writing it.
- Watch out for: the repository lists organizations, roles, permissions and mobile SDKs as roadmap items, so confirm B2B needs against the current docs.
7. Clerk: best hosted option for React and Next.js apps
Clerk is a hosted authentication and user management service with prebuilt UI components and SDKs for sign-in, sign-up, organizations and billing. It is the closest hosted equivalent to Auth0 for front-end teams, and SDKs are listed for Next.js, React, Expo, Remix, Vue, Nuxt, Express, Go, Python and more.
Components and email templates can be restyled to match your brand, and there is a hosted Account Portal. Clerk's pricing page has a free Hobby plan and bills by monthly retained users, meaning people who come back at least a day after signing up, which differs from Auth0's monthly active users. Extra enterprise SSO connections and B2B features are priced separately.
- Best for: React and Next.js teams that want polished sign-in in an afternoon.
- Watch out for: it is closed source and hosted only, so there is no self-hosted fallback.
8. WorkOS: best for adding enterprise SSO to a B2B product
WorkOS is a hosted set of APIs for enterprise single sign-on, directory sync and user management, aimed at B2B software companies. It targets the moment a larger customer asks for SAML single sign-on and directory sync, so you integrate one provider instead of each customer's identity system.
Its pricing page lists AuthKit for user management, while SSO and directory sync are priced per customer connection. Enlisted records no self-hosted edition. See the WorkOS alternatives page for other routes.
- Best for: B2B SaaS teams whose sales process now includes SSO and directory sync requests.
- Watch out for: per-connection fees grow with the number of enterprise customers, so model that before choosing.
9. Authentik: best self-hosted identity provider to replace Okta
Authentik is an open-source identity provider for single sign-on that supports SAML, OAuth2 and OIDC, LDAP and RADIUS. A reverse-proxy mode lets it protect apps that have no native SSO. The project positions its enterprise edition as a way to replace Okta, Auth0, Entra ID or Ping Identity.
Docker Compose is recommended for small and test setups, a Helm chart suits Kubernetes, and templates exist for AWS CloudFormation and DigitalOcean. The open-source edition is free, and the paid Enterprise edition is charged per user. Enlisted lists the licence as Other and records no hosted version.
- Best for: IT teams and homelabs that want one SSO for internal and self-hosted apps.
- Watch out for: there is no vendor-run cloud in Enlisted's data, so you operate it, and you should read the licence terms for the edition you deploy.
10. Authelia: best lightweight SSO and MFA portal for self-hosted apps
Authelia is an open-source authentication and authorization server, written in Go under Apache-2.0, that adds single sign-on and multi-factor authentication to web apps. It sits in front of your services, usually next to a reverse proxy, so users sign in once at a portal and policies are checked before they reach an app.
It supports TOTP and push verification with LDAP backends, is described as OpenID Certified, and runs as a small container with Docker and Kubernetes documentation. It targets self-hosters who want a consistent login in front of tools with weak or no authentication.
- Best for: homelabs and small teams securing a handful of internal web apps.
- Watch out for: its scope is protecting apps behind a portal, so check the docs before using it for customer sign-up flows.
11. Microsoft Entra ID: best hosted Okta alternative for Microsoft shops
Microsoft Entra ID is Microsoft's cloud identity service, formerly Azure Active Directory, offering single sign-on, multi-factor authentication and conditional access. It handles sign-in for Microsoft 365 and Azure and for thousands of other applications, and it can synchronise with on-premises Active Directory.
Enlisted records a free tier, and Microsoft documents its editions and pricing on its own site.
- Best for: organisations that use Microsoft 365 and want conditional access in one admin console.
- Watch out for: it is closed source and tied to Microsoft's ecosystem, and it is built for workforce sign-in more than customer-facing apps.
12. JumpCloud: best for managing staff logins and laptops together
JumpCloud is a cloud directory platform that combines identity management, device management and single sign-on. It aims to replace or complement on-premises directories for IT teams that do not want to run directory servers.
Pricing is per user per month for each product, such as SSO or device management, so the cost depends on which pieces you buy, and a 30-day trial is offered. There is no free plan in Enlisted's data.
- Best for: small and mid-sized organisations that want users, devices and SSO in one place.
- Watch out for: per-product, per-user pricing stacks as you add modules, and it is a workforce product rather than a customer login service.
Other options worth a look
- Hosted customer identity: Stytch offers passwordless login and B2B SSO as APIs, Descope designs sign-in with drag-and-drop flows, Kinde bundles feature flags with authentication, and Frontegg adds self-service user administration for your customers. All are closed source and hosted only.
- FusionAuth: a customer identity platform with login, MFA and SSO. It can be self-hosted, with a free Community edition, or run as a paid cloud service. See the FusionAuth alternatives page.
- OneLogin: a cloud SSO and MFA service for staff, now from One Identity. See the OneLogin alternatives page.
- More open source: Casdoor is a Go identity platform with SSO, OAuth, OIDC, SAML and MFA, Dex federates LDAP, SAML and social logins behind OIDC, and Pocket ID signs users in with passkeys only.
- Enterprise suites: Ping Identity and IBM Verify cover workforce and customer identity, and Duo Security is Cisco's workforce MFA and SSO service. All three are closed source and hosted.
- Backend platforms: Firebase includes authentication, so read the Firebase alternatives guide if login is part of a wider backend decision.
How monthly-active-user pricing works
Most hosted identity services bill by usage, and the unit differs. Auth0 counts monthly active users, meaning non-employee users who authenticated in a month. Clerk counts retained users who return after sign-up, ZITADEL meters daily active users, WorkOS charges per enterprise connection, and Okta's workforce suites are priced per user per month.
To estimate your bill, count how many distinct customers sign in during a typical month and how many enterprise customers need SSO. Then compare vendors on the same unit. Self-hosting removes the meter but adds database, upgrade and uptime work, so it suits teams that already run production services.
Which Auth0 alternative should you choose?
| If you need | Pick |
|---|---|
| A free, standards-based server for customers and staff | Keycloak |
| Organizations per customer in a B2B product | ZITADEL |
| Login code inside your own backend | SuperTokens or Ory Kratos |
| Auth0-style screens with open code | Logto |
| Passkey-first sign-in | Hanko |
| Drop-in sign-in for React or Next.js | Clerk |
| SAML SSO and directory sync for large customers | WorkOS |
| Okta replacement you host yourself | Authentik, or Keycloak |
| A simple SSO and MFA gate for self-hosted apps | Authelia |
| Staff SSO inside a Microsoft shop | Microsoft Entra ID |
| Staff SSO plus device management | JumpCloud |
Browse every Auth0 alternative and Okta alternative in the catalogue, or the wider auth and identity category.
Self-hosting identity: what you take on
An identity server is the front door to your product, so running it is a bigger commitment than running a blog. You are responsible for patching, backups, high availability and the security of the admin console. Teams with an operations function often accept that in exchange for owning user data and avoiding per-user fees.
If you want open-source code without the operating work, ZITADEL, SuperTokens, Logto, Hanko and Ory all sell a managed cloud. Whichever route you take, treat vendor security statements as claims to check against their documentation and audit reports.
Auth0 alternatives: pricing compared
Plans and list prices from each vendor's pricing page. Prices change, so confirm the current price on the vendor's page before you buy.
| Tool | Free option | Paid plans | Source |
|---|---|---|---|
| Free plan |
| Pricing page Checked 2 Oct 2026 | |
| Free trial |
ProfessionalPrices on the vendor's page | Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable | None listed | ||
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| Free (open source)Self-hostable |
| Pricing page Checked 2 Oct 2026 | |
| Free plan | See the vendor's pricing page | Pricing page | |
| Free plan |
Annual CreditsPrices on the vendor's page | Pricing page Checked 2 Oct 2026 | |
| Free plan | See the vendor's pricing page | Pricing page | |
| Free trial |
| Pricing page Checked 2 Oct 2026 |
List prices from each vendor's public pricing page on the date shown. Annual billing is often cheaper, and taxes, usage and transaction fees aren't included. Open-source tools cost nothing to self-host beyond your own server.
Frequently asked questions
- What is the best open-source alternative to Auth0?
- Keycloak and ZITADEL are the two most complete open-source Auth0 alternatives. Keycloak is the long-established, standards-based identity server that handles both customer logins and staff SSO, and ZITADEL adds native multi-tenancy for B2B products. SuperTokens, Logto and Ory Kratos are lighter options aimed at developers who want login inside their own application.
- What are the best alternatives to Okta?
- For employee single sign-on, Microsoft Entra ID and JumpCloud are hosted alternatives to Okta, and Authentik and Keycloak are open-source ones you run yourself. Okta also owns Auth0, so teams that use Okta for customer identity should look at Clerk, WorkOS or ZITADEL instead. Pick by whether your users are staff or customers.
- Is there a self-hosted alternative to Auth0?
- Yes. Keycloak, ZITADEL, SuperTokens, Logto, Ory Kratos, Hanko and Authentik can all be self-hosted, and several of them also sell a managed cloud. FusionAuth can be self-hosted too, with a free Community edition. Self-hosting removes the per-user meter but means you run the database, upgrades and uptime yourself.
- What are the best OneLogin and FusionAuth alternatives?
- OneLogin is a cloud SSO product for staff, so Microsoft Entra ID, JumpCloud, Okta and Authentik are the natural comparisons. FusionAuth is a customer identity platform, so ZITADEL, Keycloak, SuperTokens and Logto are the closest open-source options, and Clerk and WorkOS are hosted ones.
- How is Auth0 priced compared with its alternatives?
- Auth0 prices by monthly active users, counting non-employee users who sign in during a month, and it has a free plan with a user cap. Clerk counts monthly retained users, ZITADEL meters daily active users, WorkOS charges per enterprise connection, and open-source tools charge nothing per user when you self-host. Compare the unit being metered, not only the headline price.