How to Pick an Identity Vendor Without an Identity Team

Guilliano Molaire Guilliano Molaire 7 min read

To pick an identity vendor without an identity team, name one accountable owner before you look at any product, write down five or six criteria that reflect your next two years rather than today’s feature list, and run a two-week evaluation that gives each vendor a pass or fail on each criterion. Most of the real differences between vendors show up in how the price changes as you grow, what happens when a large customer wants its own login connection, who is on call when login breaks, and how hard it is to leave. A one-page decision record at the end lets a CEO or CFO see why the choice was made.

This post is a process for a B2B SaaS company of roughly 30 to 300 people that has to choose or replace an identity provider this quarter. It doesn’t recommend a specific vendor, because the right answer depends on your customers and your pricing exposure. It covers who should own the decision, the questions that separate vendors, a two-week plan, and how to write the decision down and plan the exit before you sign.

Why does choosing an identity vendor feel harder than it should?

Identity touches every part of the product at once. It decides how every customer signs in, what your support team can do when someone is locked out, which enterprise deals you can close, and what your auditors look at. A wrong choice is expensive to undo because user records, sessions and integrations all sit on top of it.

Most teams also make this decision without a specialist in the room. The people choosing are usually a CTO, a senior engineer and someone from finance, and they are comparing products that each describe themselves in different vocabulary. A process helps by turning each vendor’s marketing language into the same set of questions, each with a pass or fail answer.

Who should own the choice?

Settle these three roles before anyone looks at vendor pricing, so the evaluation has a driver from day one:

  • One accountable owner. This person runs the evaluation, collects the evidence and writes the decision record. It is usually the CTO or a staff engineer, and it should not be shared between two people who each assume the other is driving.
  • One technical reviewer. Someone who will integrate the product and can say whether a claimed capability works in your stack.
  • One budget approver. Whoever will sign, usually the CEO or CFO, who agrees at the start what a reasonable range looks like so the evaluation does not end with a surprise.

How much engineering time does a fair evaluation take?

Expect the owner to spend a few hours a week on coordination and writing, and the technical reviewer to spend most of one week on hands-on testing. If that looks like more than you can spare, cut the short list to two vendors or cut the criteria to the ones that would change the decision.

Which questions separate identity vendors in practice?

Feature checklists look similar across vendors, because nearly all of them offer sign-in, MFA and social login, and most offer some form of SSO, though often only on higher tiers. The differences are in the questions below.

How does the price change as you grow?

Identity vendors charge per monthly active user, per enterprise connection, or per cluster of infrastructure, and each model rewards a different kind of business. We cover how the three common pricing models behave as you grow in a separate post, so we only add two things here.

First, watch for feature tiers. The base price can look low while enterprise SSO, SCIM provisioning or audit logs only arrive on a higher tier, so the first enterprise deal can force an upgrade. Second, list prices on their own are misleading, so model your own numbers at today’s size, at three times today’s size and at ten times, for each vendor, with the features you will need at that point. Skycloak is priced by plan and by the clusters you run, so the bill changes when you add an environment or a region rather than when you add users, and our pricing page has the details. The procurement and contract guide covers terms to check before signing.

What happens when a large customer asks for its own login connection?

Ask each vendor to walk you through connecting a customer who uses Okta or Microsoft Entra ID: who configures it, how long it takes, whether the customer can self-serve, and whether it costs extra per connection. Then ask what happens when that customer wants automatic user provisioning and deprovisioning (SCIM, standardized in RFC 7644). Enterprise prospects often raise this during a deal, and vendors handle it in very different ways, so a vendor that makes it painful is a real risk.

What will the vendor do for you in the first 90 days?

Find out whether onboarding is documentation only, a shared channel with engineers, or a paid services engagement. Ask what a migration from your current system looks like, including how existing users are brought over: whether your current provider will export password hashes at all, and if it will not, whether the new vendor can migrate users the first time they sign in. Teams often discover too late that every user would need to reset a password.

Who is on call when login breaks, and on which plan?

Read the support and SLA terms for the plan you would actually buy, not the top tier. Ask what the response time is for an outage, whether you get a named contact, and what remedy the SLA offers. A login outage is visible to your customers straight away, so test the response time on your actual plan against what your customers would tolerate.

How do you run a two-week evaluation?

  1. Days 1 to 2. Write the criteria and the pass or fail test for each. Pick two or three vendors.
  2. Days 3 to 7. Build the same small integration with each vendor: sign-up and login for one app, one MFA method, one enterprise connection with a test identity provider, and one token check in your API.
  3. Days 8 to 10. Ask the pricing, support, security and exit questions in writing, and ask for the vendor’s security documentation.
  4. Days 11 to 14. Talk to references and write the decision record.

Score each criterion as pass, partial or fail with a short note, so the result rests on evidence rather than on how each demo went.

What should you ask references and your own customers?

Ask references what surprised them after launch, what they would negotiate differently, and how support behaved during an incident. Also ask two or three of your own larger customers which identity providers they run and what they require from a vendor’s login, since their answers should shape your criteria.

How do you decide and write it down?

Write a one-page record that a CEO or CFO can read in five minutes: the options considered, the criteria, a pass, partial or fail for each, the cost at today’s size and at three and ten times, the risks you accept, and the reason for the choice. The vendor risk brief for CTOs shows the sort of questions a reviewer will ask, which are worth answering in the record.

How do you plan the exit before you sign?

Ask how you export users, credentials and configuration, in what format, and what it costs. Standards-based systems make this easier, and open-source Keycloak is the one we run and know best: realms, including users and their password hashes, can be exported in Keycloak’s standard format, and on Skycloak that export is available from the Launch plan up. Ask every vendor, including us, which plan the export is on. Whatever you choose, an identity provider exit plan is cheaper to write while you are choosing than after you are committed.

What should you do this week?

Name the owner, the technical reviewer and the budget approver. Write the criteria and the pass or fail test for each, pick two or three vendors, and book the kickoff for day one of the evaluation. If you are weighing building login yourself first, read the build versus buy guide.

Frequently asked questions

How long should an identity vendor evaluation take?

Two weeks is a reasonable target for two or three vendors if you fix the criteria first and test the same scenarios with each. A longer evaluation is worth it only if it answers a question the two weeks could not.

Should we build our own authentication instead?

Building login is manageable at first and gets more expensive as customers ask for enterprise SSO, provisioning, audit logs and compliance evidence. Our guide to build versus buy for identity covers what to check.

Who should own an identity vendor decision at a small company?

One accountable person, usually the CTO or a staff engineer, supported by a technical reviewer and a budget approver. When ownership is split, each person tends to assume the other is driving, and the evaluation stalls.

What is the most important question to ask every vendor?

How the price and the workload change when a large customer asks for its own login connection, because enterprise prospects often raise it mid-deal and vendors differ a lot in the effort and cost involved.

Sources

  • IETF, RFC 7644, “System for Cross-domain Identity Management: Protocol”, https://datatracker.ietf.org/doc/html/rfc7644

Identity management as a service, on open source

Skycloak does what Auth0 and Okta do, SSO, MFA, SCIM, audit logs and enterprise federation, on an open source core. Unlimited users and applications on every plan, no charge per monthly active user, and you can export and self-host whenever you want.

Guilliano Molaire
Written by
Founder

Guilliano is the founder of Skycloak and a cloud infrastructure specialist with deep expertise in product development and scaling SaaS products. He discovered Keycloak while consulting on enterprise IAM and built Skycloak to make managed Keycloak accessible to teams of every size.

Start Free Trial Talk to Sales
© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman