The Top 11 IDaaS Providers Compared (2026 Edition)

Guilliano Molaire Guilliano Molaire 10 min read
idaas powerhouse

Last updated: July 2026

The top IDaaS providers in 2026 fall into three distinct categories: full CIAM platforms (Auth0, Microsoft Entra External ID, Amazon Cognito, Google Cloud Identity Platform, FusionAuth), developer-auth SDK layers built for B2B SaaS (Clerk, Stytch, Descope, Frontegg, WorkOS), and managed open source (managed Keycloak). The right pick depends on which category matches your product, not on any single ranking. The pricing models differ so much between categories that comparing vendors head to head without this split produces nonsense numbers.

Why this list is grouped into categories

Most IDaaS listicles dump ten logos into a flat list and rank them by brand recognition. That format hides the decision that actually matters: these products are not interchangeable. A team evaluating Clerk against Amazon Cognito is usually asking the wrong question, because the two products solve different problems at different layers of the stack.

So this list is organized the way buyers actually shop:

  1. Full CIAM/IDaaS platforms. Complete customer identity backends: hosted login, user storage, MFA, federation, admin tooling. You integrate via OIDC or SAML and the vendor runs everything.
  2. Developer-auth SDK layers. Products that live inside your frontend and API code, optimized for B2B SaaS: prebuilt components, organization modeling, enterprise SSO as an add-on.
  3. Managed open source. Open source identity servers (in practice, Keycloak) run for you by a hosting provider. The category almost every listicle skips, and the only one with no per-user pricing.

Pick your category first. The vendor shortlist mostly writes itself after that.

Why aren’t Okta and Microsoft Entra ID on this list?

Because workforce IAM is a different product for a different buyer, even though most listicles conflate the two. Okta Workforce Identity and Microsoft Entra ID manage your employees: they connect HR systems, push users into Slack and Salesforce, and enforce IT policy on corporate devices. The buyer is IT and security leadership.

IDaaS in the customer-identity sense (CIAM) is the login box in your product. The buyer is engineering and product. The requirements are different too: millions of self-registered users instead of thousands of provisioned employees, conversion-sensitive signup flows instead of compliance-driven onboarding, and per-MAU economics instead of per-seat licensing.

Okta the company does compete here, through Auth0, which it acquired in 2021. That is why Auth0 is on this list and Okta Workforce is not. If you are shopping for employee SSO and device policy, you want a workforce IAM comparison, not this one.

Category 1: full CIAM and IDaaS platforms

These are complete identity backends. You point your app at them, they handle registration, login, MFA, token issuance, and user storage. Best fit: consumer apps and teams that want identity fully outsourced.

Auth0

Auth0 is still the reference point everyone else prices against. The developer experience is excellent, the docs are the best in the category, and the integration catalog covers almost anything. Pricing is MAU-based: the free tier covers up to 25,000 MAUs, B2C Essentials starts at $35/month, and B2B Essentials starts at $150/month at 500 MAUs (Auth0 pricing, July 2026).

The catch is what happens past the self-service slider. Features like advanced MFA and enterprise connections sit in higher tiers, and six-figure user counts push you into opaque enterprise quotes. We wrote up the detailed cost math in our Keycloak vs Auth0 comparison.

Microsoft Entra External ID

Entra External ID is Microsoft’s current CIAM product and the official successor to Azure AD B2C, which closed to new customers on May 1, 2025 (Microsoft FAQ). The headline is the free tier: your first 50,000 MAUs cost nothing (Microsoft Entra pricing, July 2026). Beyond that, usage is metered per MAU, and add-ons like SMS-based authentication and machine-to-machine tokens are billed separately, so check the Azure pricing page for current meters before you model costs.

It is a strong pick if you are already deep in Azure. It is also a young product: B2C veterans will find gaps, and the migration tooling from B2C is still maturing.

Amazon Cognito

Cognito is the AWS-native option, and its pricing changed meaningfully in November 2024 when AWS re-tiered it into Lite ($0.0055/MAU), Essentials ($0.015/MAU), and Plus ($0.020/MAU), with 10,000 free MAUs on Lite and Essentials (Cognito pricing, July 2026). Essentials is the default for new user pools and costs 2.7x Lite, and features like custom auth flows now require it. Pools created before November 22, 2024 keep the old 50,000 MAU free tier. Machine-to-machine tokens are billed separately at $0.00225 each.

Cognito is cheap and durable if you live in AWS and can tolerate its developer experience, which remains the most common complaint about it.

Google Cloud Identity Platform

Identity Platform is Firebase Authentication’s enterprise-grade sibling: same SDKs, plus SAML/OIDC federation, multi-tenancy, and an SLA. The free tier covers 50,000 MAUs for standard sign-in methods, but SAML and OIDC users are free for only 50 MAUs, with tiered per-MAU pricing beyond that (Firebase pricing, July 2026).

That tiny SAML/OIDC allowance is the number to notice: if your roadmap includes enterprise SSO customers, model that meter before committing. For mobile-first consumer apps already on Firebase, it is a natural and low-friction choice.

FusionAuth

FusionAuth is the hybrid on this list: a downloadable, single-tenant identity server you can self-host free on the Community plan, or have FusionAuth run for you in their cloud starting at $162/month on Starter, with the Essentials plan listed at $2,970/month; both scale with MAU count, which is why the sticker gap between the two tiers looks so wide (FusionAuth pricing, July 2026).

The appeal is control without open source assembly: one deployable app, your infrastructure or theirs, plan-based pricing instead of a MAU meter on the hosting itself. The trade-off is a smaller community and ecosystem than Auth0 or Keycloak, and a steep jump between paid tiers.

Category 2: developer-auth SDKs for B2B SaaS

These products optimize for time-to-first-login and B2B features: organizations, invitations, enterprise SSO, SCIM. They live closer to your frontend than category 1 does.

Clerk

Clerk owns the React and Next.js auth experience: drop-in components for sign-in, user profiles, and organization management that genuinely save weeks. In 2026 Clerk bills on Monthly Retained Users (MRUs) rather than raw MAUs: the free tier covers 50,000 MRUs, Pro is $25/month plus $0.02 per MRU beyond the free allowance, and the B2B feature add-on is $100/month (Clerk pricing, July 2026).

The retained-user model is friendlier than MAU billing for apps with churny signups. The flip side is framework coupling: Clerk is at its best inside React, and thinner elsewhere. We compare the trade-offs in depth in Keycloak vs Clerk.

Stytch

Stytch is API-first where Clerk is component-first, with strong passwordless options and fraud tooling. Pricing is pay-as-you-go: 10,000 MAUs and 5 SSO/SCIM connections free, then $125 per additional connection (Stytch pricing, July 2026).

That per-connection fee is the number B2B buyers should model. Five free enterprise connections is generous for a young SaaS; at fifty enterprise customers, connections become the bill.

Descope

Descope’s differentiator is a visual workflow builder: you design auth flows (passkeys, MFA step-up, fraud checks) on a canvas instead of in code. The free tier covers 7,500 MAUs and 10 tenants; paid plans start at $249/month for Pro and $799/month for Growth (Descope pricing, July 2026).

It is a newer vendor, and the no-code abstraction cuts both ways: fast to change, harder to eject from. Teams that iterate on auth flows frequently tend to like it a lot.

Frontegg

Frontegg leans hardest into B2B multi-tenancy: a self-service admin portal your customers use to manage their own users, SSO, and security policies, out of the box. Pricing is consumption-based pay-as-you-go, with a free tier covering 7,500 MAUs and 5 enterprise connections (Frontegg pricing, July 2026).

The customer-facing admin portal is a real differentiator that would take months to build in-house. The consumption model makes bills less predictable than flat tiers, so watch your meters.

WorkOS

WorkOS started as “enterprise readiness as an API” (SSO, SCIM, audit logs) and added AuthKit, a full hosted auth layer with the most aggressive free tier in the industry: free up to 1,000,000 MAUs, then $2,500/month per additional million (WorkOS pricing, July 2026). Enterprise SSO is billed per connection at $125/month, tiering down to $50 at volume.

Read that pricing carefully: user auth is effectively free, and the business model is the per-connection SSO fees your enterprise customers trigger. For a B2B SaaS with dozens of enterprise logos, connections are the real line item.

Category 3: managed open source (managed Keycloak)

This is the category flat listicles skip, and it changes the economics completely. Keycloak is the dominant open source identity server: Apache 2.0 licensed, OIDC and SAML, single sign-on, LDAP and Active Directory federation, fine-grained authorization, all included with no feature gates and no per-MAU meter.

Honesty first: raw Keycloak is not effortless. The admin console UX trails the polished SaaS options, upgrades and high-availability clustering are real operational work, and the docs are reference-grade rather than tutorial-grade. Self-hosting it well means owning backups, monitoring, and patching.

Managed Keycloak hosting exists to remove exactly that work while keeping the open source economics. Because Keycloak sizing follows login request rate rather than registered user count, the infrastructure cost stays roughly flat as MAUs grow. That is why managed Keycloak pricing (including Skycloak’s) is a flat monthly fee based on cluster size, not a meter that scales with your signup chart. You also keep full data control and an exit path: it is your realm export, portable to any host.

The honest downside: even managed, Keycloak’s time-to-first-login is slower than Clerk or Auth0, and heavy UI customization means theming work rather than flipping SaaS toggles.

IDaaS pricing at a glance (as of July 2026)

All figures below come from each vendor’s public pricing page, checked July 2026. Pricing models shift often (Cognito re-tiered in late 2024, Clerk moved to retained-user billing), so treat vendor pages as the source of truth.

Provider Model Free tier Entry paid pricing
Auth0 Per MAU 25,000 MAUs B2C Essentials $35/mo; B2B Essentials $150/mo at 500 MAUs
Entra External ID Per MAU 50,000 MAUs Metered per MAU beyond free; add-ons (SMS, M2M) billed separately
Amazon Cognito Per MAU 10,000 MAUs (Lite/Essentials) Lite $0.0055, Essentials $0.015, Plus $0.020 per MAU
Google Identity Platform Per MAU 50,000 MAUs (SAML/OIDC: 50) Tiered per-MAU beyond free
FusionAuth Plan-based Community (self-hosted) Cloud from $162/mo Starter; Essentials $2,970/mo
Clerk Per MRU 50,000 MRUs Pro $25/mo + $0.02/MRU overage; B2B add-on $100/mo
Stytch PAYG 10,000 MAUs + 5 SSO/SCIM connections $125 per additional connection
Descope Plan-based 7,500 MAUs, 10 tenants Pro from $249/mo; Growth $799/mo
Frontegg Consumption PAYG 7,500 MAUs + 5 enterprise connections Consumption-based beyond free
WorkOS Free auth + per connection 1,000,000 MAUs (AuthKit) $2,500/mo per additional 1M MAUs; SSO $125/connection/mo (down to $50)
Managed Keycloak Flat infra-based Keycloak itself is free Flat monthly fee by cluster size, see pricing

What does 100,000 MAU actually cost?

Here is where the categories stop being academic. Using only the verified rates above, a hypothetical app with 100,000 monthly active users pays wildly different bills depending on the model:

Provider Monthly cost at 100,000 MAUs The arithmetic
Amazon Cognito (Essentials) $1,350 (100,000 – 10,000 free) x $0.015 = $1,350
Clerk (Pro) $1,025 $25 base + (100,000 – 50,000 free) x $0.02 = $1,025
WorkOS (AuthKit) $0 Under the 1,000,000 MAU free tier; SSO connections billed separately
Auth0 No published price 100k MAUs is enterprise-quote territory; see our Auth0 cost breakdown
FusionAuth Cloud Plan-based Flat plan tiers from $162/mo Starter to $2,970/mo Essentials, not a MAU meter
Managed Keycloak Flat Sized by login rate and cluster, not user count; pricing here

Three things jump out of that table. First, “per MAU” providers diverge by an order of magnitude at identical scale. Second, WorkOS’s $0 is real but incomplete: its revenue model is per-connection SSO, so a B2B app with 40 enterprise connections pays $2,000 to $5,000/month there instead. Third, the flat-price options (FusionAuth Cloud, managed Keycloak) are the only ones where the bill does not move when marketing has a great quarter.

One caveat on Clerk: MRUs are retained users, not raw actives, so real Clerk bills often land below a naive MAU calculation. It is the most user-friendly meter in the per-user camp.

To model your own numbers against a flat-price setup, our pricing calculator does the comparison for your actual MAU and login-rate figures.

How to choose

Match the category to the product first, then compare within it:

  • Consumer app, want zero identity ops: category 1. Auth0 for developer experience, Entra External ID or Cognito if you are already committed to that cloud, Identity Platform if you are Firebase-native.
  • B2B SaaS in React, speed matters most: category 2. Clerk for components, WorkOS if enterprise SSO is the immediate need, Frontegg if customer self-service admin is the differentiator you want.
  • Cost predictability, data control, or six-figure MAUs: category 3, or FusionAuth. Per-MAU meters punish success; flat pricing does not.

And if your requirements sit across categories (say, a B2B SaaS that also needs LDAP federation and full data residency), that overlap zone is exactly where Keycloak tends to win despite its rougher edges.

Frequently asked questions

What is the difference between IDaaS and CIAM?

IDaaS (Identity as a Service) is the umbrella term for any cloud-delivered identity product, covering both workforce IAM (employee logins, like Okta Workforce and Entra ID) and CIAM (customer identity, the login box in your product). CIAM is the subset this list covers: self-registered external users, conversion-sensitive flows, and per-MAU or per-connection pricing.

How much does IDaaS cost per user?

As of July 2026, published per-MAU rates run from $0.0055 (Cognito Lite) to $0.020 (Cognito Plus), with Clerk at $0.02 per retained user past its free tier. But per-user rates only tell part of the story: free tiers range from 7,500 users (Descope, Frontegg) to 1,000,000 (WorkOS AuthKit), and B2B products often bill per enterprise SSO connection ($50 to $125/month each) on top.

Is Auth0 still free for 25,000 users?

Yes. As of July 2026, Auth0’s free plan covers up to 25,000 MAUs (Auth0 pricing). Paid plans start at $35/month for B2C Essentials and $150/month for B2B Essentials at 500 MAUs, with costs scaling on a MAU slider from there. Advanced features and higher user counts move you into enterprise quotes.

What replaced Azure AD B2C?

Microsoft Entra External ID is the official successor. Azure AD B2C stopped accepting new customers on May 1, 2025, though existing tenants remain supported until at least May 2030 (Microsoft FAQ). New CIAM projects on Microsoft’s stack should start on External ID, which includes 50,000 free MAUs.

Is Keycloak a good alternative to Auth0 or Okta?

For customer identity, yes, with caveats. Keycloak matches the core CIAM feature set (OIDC, SAML, MFA, federation, fine-grained authorization) with no per-MAU fees, which makes it strongest at scale or where data control matters. The trade-off is operational work, which managed hosting absorbs. Our Keycloak vs Auth0 guide walks through the decision in detail. As an Okta Workforce replacement for employee IAM, Keycloak can work but requires more assembly.

Tired of running Keycloak yourself?

Skycloak runs real upstream Keycloak for you with a 99.99% SLA. No fork, no lock-in, just managed Keycloak that stays patched and on call so you don't have to.

Guilliano Molaire
Written by
Founder

Guilliano is the founder of Skycloak and a cloud infrastructure specialist with deep expertise in product development and scaling SaaS products. He discovered Keycloak while consulting on enterprise IAM and built Skycloak to make managed Keycloak accessible to teams of every size.

Start Free Trial Talk to Sales
© 2026 Skycloak. All Rights Reserved. Design by Yasser Soliman