Hosted identity: sign-in, social and enterprise connections, multi-factor authentication and the rules around them, as a service your application redirects to.
Do not build this if you sell to enterprises. Consider it if you do not. Two things carry the verdict, and they are different in kind. **SAML and enterprise directory connections** are what unlock large customers, and they are genuinely tedious — every provider is subtly different and getting a signature validation wrong is a security hole. **Attack protection** — credential stuffing detection, breached password lists, anomaly signals across many customers — is something a provider sees and you do not. WHEN TO KEEP PAYING - Customers ask for SAML, SCIM provisioning or an audit report - You would rather somebody else be responsible when a login flow is attacked - Compliance questionnaires are part of your sales process WHEN TO BUILD - Consumer product, ordinary sign-in, no enterprise buyers - Then authentication is a known problem with reviewed libraries, and it is covered in full under Stytch elsewhere in this catalogue WHATEVER YOU DECIDE, DO THESE - **Passkeys first**, password second. Phishing-resistant, nothing to steal from your database, and support is now broad - Check every new password against a breached-password corpus using k-anonymity so it never leaves your machine. That one check does more than any complexity rule - Never reveal whether an address exists: identical responses and identical timing for a wrong password and an unknown account, on every route - Rate limits per address hash and per account, on everything - A password change or reset revokes every other session, and the user is told - An append-only auth_events table. When somebody asks what happened to an account, that is the only answer you will have THE MIGRATION QUESTION, ASKED EARLY If you adopt a provider, check now how you would get out: can you export password hashes, or would every user have to reset? That answer decides whether this is a decision or a marriage. THE ONE-LINE VERSION Pay for the enterprise connections and the attack data. Do not pay to avoid learning how sessions work.
What you lose
- SAML and enterprise directory connections, which is what unlocks larger customers and is genuinely tedious
- Attack protection — credential stuffing detection, breached password checks, bot defence
- A security posture somebody else is accountable for
If you would rather not build
- Ory Hydra and Kratos, if you want components
What it costs
read from their page 15 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $35/mo | — | 15 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Keycloak
$0A mature open identity server with OIDC, SAML and social connections.
keycloak/keycloakfree · open source
Logto
$0A modern self-hostable identity service with a usable admin console.
logto-io/logtofree · open source
Why this verdict
our own opinion · changed only by a person
26/100
Verdict no at 26. Self-hosting an identity server is legitimate; writing authentication is not. The enterprise connections are what the price really buys.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about Auth0
answered from the record above
Is Auth0 free?
No — the plan we track is $35 a month. Essentials from around $35/month billed monthly for 500 monthly active users, rising steeply with usage.
Can you replace Auth0 by building your own?
KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 26 out of 100, build time longer than it saves. Read what you lose before you decide.
How much does Auth0 cost?
$35 a month on Essentials — $420 a year. Recorded 10 Aug 2026.
What do you lose by replacing Auth0?
SAML and enterprise directory connections, which is what unlocks larger customers and is genuinely tedious; Attack protection — credential stuffing detection, breached password checks, bot defence; A security posture somebody else is accountable for. If any of those carry weight for you, keep paying.
Is there an open-source alternative to Auth0?
Yes: Keycloak, Logto. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

