Enterprise features as an API: single sign-on, directory sync, audit logs and the rest of what a large customer asks for before they will sign.
Do not build this if you sell to enterprises. Every identity provider quirk absorbed is the product. SAML is a specification that every vendor implements slightly differently. Then directory synchronisation, which is another protocol with its own inconsistencies, and each customer's identity team expecting their own arrangement to work on the first attempt. That accumulated compatibility is what you are buying, and it is what unlocks larger deals. WHEN TO KEEP PAYING - Customers asking for SAML or user provisioning, which is the moment this becomes a revenue question rather than a cost one - The first enterprise deal, where the integration standing between you and the contract is worth more than the fee WHEN TO BUILD - No enterprise customers yet. Then ordinary authentication covers it, and the shape is under Stytch elsewhere in this catalogue - **OIDC only**, if your customers all use providers that speak it. That is a reviewed library and an afternoon, and it covers a surprising share of modern identity providers IF YOU IMPLEMENT SAML YOURSELF - Use a reviewed library. Never parse or validate assertions by hand - **Validate the signature properly**, on the assertion and not merely the response, and pin the expected certificate per connection. Signature confusion in SAML has produced real authentication bypasses in well-known products - Check the audience, the recipient, the conditions and the timestamps, and reject replays by tracking assertion identifiers - One configuration per customer, tested against their actual provider before go-live, because none of them behave identically - Directory synchronisation as an incremental job with a cursor, idempotent, where a deprovisioned user is deactivated immediately — that path is the one an auditor asks about WHAT TO BUILD REGARDLESS An append-only audit log of authentications, provisioning changes and permission changes, exportable. Enterprise customers ask for it, it takes an afternoon, and it cannot be reconstructed later. THE ONE-LINE VERSION Start with OIDC. Buy SAML when a customer asks, because by then it is a deal rather than a cost — and never hand-roll assertion validation.
What you lose
- SAML implementations that work against dozens of identity providers, each with its own interpretation of the specification
- Directory sync through SCIM, which is a second protocol with its own edge cases
- Support during a customer's security review, which is when this matters most
If you would rather not build
- A reviewed SAML library plus just-in-time provisioning
- WorkOS itself, if you have several enterprise customers
What it costs
read from their page 17 Aug 2026
| Plan | Billed monthly | Billed yearly | Last read |
|---|---|---|---|
| — | $125/mo | — | 17 Aug 2026 |
Their pricing page is where these came from. Seeing a different price? Tell us.
The escape hatch
open source · no votes, no paid placement
Keycloak
$0Acts as a broker so your app speaks one protocol while it handles the rest.
keycloak/keycloakfree · open source
SuperTokens
$0Self-hosted authentication with an enterprise single sign-on add-on.
supertokens/supertokens-corefree · open source
Why this verdict
our own opinion · changed only by a person
22/100
Verdict no at 22. One customer is a week of work; a dozen identity providers is a product. The four validation checks are non-negotiable either way.
History
tracked since 10 Aug 2026 · nothing is ever overwritten
Questions about WorkOS
answered from the record above
Is WorkOS free?
No — the plan we track is $125 a month. Priced per enterprise connection, from around $125/month per organisation connected.
Can you replace WorkOS by building your own?
KEEP IT. The value is the network, the data or the infrastructure. Keep paying. Replacement score 22 out of 100, build time longer than it saves. Read what you lose before you decide.
How much does WorkOS cost?
$125 a month on Per connection — $1,500 a year. Recorded 10 Aug 2026.
What do you lose by replacing WorkOS?
SAML implementations that work against dozens of identity providers, each with its own interpretation of the specification; Directory sync through SCIM, which is a second protocol with its own edge cases; Support during a customer's security review, which is when this matters most. If any of those carry weight for you, keep paying.
Is there an open-source alternative to WorkOS?
Yes: Keycloak, SuperTokens. The prompt on this page is for when you want it your way instead.
Related entries
same category first, most replaced first
Every week, something stops being worth paying for.
New verdicts, prices that moved, entries added. One email a week. Unsubscribe in one click. Nothing is being sent yet — your address is kept here, and the first issue is the first thing it is used for.
free forever · no tracking pixel · stored here, never passed to anyone

