⚡
SelfHostStackOpen-Source Directory

Why Migrate Away from Auth0 & Okta?

Auth0 charges severe penalties as your active user count expands, gatekeeping essential enterprise security features like SAML 2.0, multi-tenant organization directories, custom domains, and SCIM provisioning behind enterprise tiers. Self-hosting Authentik, Keycloak, or SuperTokens gives you complete identity sovereignty, unlimited active users, full OIDC/OAuth2/SAML protocol compliance, custom branding, and zero per-user subscription fees.

Technical Architecture & Migration Analysis

Proprietary identity platforms store encrypted user credentials and session tokens in multi-tenant cloud directories, evaluating authentication rules and MFA policies on serverless runtimes. Self-hosted Authentik operates as a Python/Django and Go worker architecture backed by PostgreSQL and Redis. Keycloak is built on Red Hat's Quarkus Java runtime with high-throughput Hibernate ORM and Infinispan distributed caching. Both provide standards-compliant OpenID Connect (OIDC), OAuth2, SAML 2.0, WebAuthn/Passkeys, and LDAP/Active Directory federation.

⚠️

When NOT to Migrate (When Staying on Auth0 & Okta Makes Sense)

Self-hosting is not universally the right move. Keep paying for SaaS if your team hits any of these constraints:

  • ▸You are a solo developer building a quick weekend hackathon prototype that needs social login in 5 minutes with zero server infrastructure.
  • ▸Your company requires enterprise compliance certifications (e.g. FedRAMP High, HIPAA BAA) with managed third-party liability insurance.
  • ▸You lack experience managing secure database encryption keys, SSL termination, and automated PostgreSQL failover clusters.

Real-World Cost Comparison: Auth0 & Okta vs Self-Hosted

Comparing vendor cloud billings against standard Hetzner / DigitalOcean infrastructure costs at scale.

Tier / ScaleAuth0 & Okta CostSelf-Hosted VPS CostEstimated Annual SavingsTechnical Breakdown
B2C Consumer App
25,000 Monthly Active Users (MAU), Social logins, MFA
$240 - $480/month ($2,880 - $5,760/year on Auth0 Essentials)€3.79/month (Hetzner CX22 2 vCPU, 4GB RAM)$2,800 - $5,700/yearAuthentik handles 25k MAU with < 1GB RAM usage and sub-20ms token verification.
B2B SaaS with Enterprise SSO
100 corporate customers, SAML/OIDC connections, SCIM directory sync
$1,500 - $3,500/month ($18,000 - $42,000/year on Auth0 B2B Enterprise)€14.28/month (Hetzner CPX31 4 vCPU, 8GB RAM)$17,800 - $41,800/yearSelf-hosted Authentik and Keycloak support unlimited SAML 2.0 enterprise connections at zero added license fee.
High-Volume Mobile / Web Ecosystem
500,000 MAU, multi-factor authentication, custom user flows
$6,000 - $18,000+/month (Auth0 Custom Enterprise)€64.00/month (Dedicated Hetzner AX42 8-core AMD, 64GB DDR5)$71,000 - $215,000+/yearDedicated infrastructure serves thousands of token validations per second with zero overage billing.

Top 2 Recommended Open-Source Replacements

Tested, self-contained, and production-ready. Click any tool to inspect verified docker-compose configurations, hardware sizing, and deployment guides.

Authentik

GPL-3.0⭐ 13.5k+

Open-source identity provider emphasizing flexibility, modern UI, and comprehensive protocol support.

Min RAM2 GB
Min CPU1 vCPU
GitHub Repo ↗

✅ Advantages

  • Superb modern web administration interface
  • Visual pipeline builder allows complex auth logic without writing custom code
  • Includes built-in reverse proxy authentication (outpost proxy)

⚠️ Trade-offs / Limitations

  • Requires 2GB+ RAM for stable multi-container execution
  • Complex flow configuration requires a short learning curve

Core Features

▸Complete support for OAuth2, OIDC, SAML 2.0, LDAP, and SCIM
▸Visual flow and stage builder for custom authentication and enrollment pipelines
▸Built-in WebAuthn/Passkey, TOTP, and SMS multi-factor authentication
▸Forward auth proxy capability for protecting legacy internal services
▸Customizable user interfaces and email templates

Architecture Notes

Python/Django backend and Go worker processes. Uses PostgreSQL for database state and Redis for caching and session management.

Known Limitations

Docker compose uses several worker containers; requires at least 2GB RAM for smooth operation.

Official Documentation ↗
📄 docker-compose.yml
Production Ready
version: '3.8'
services:
  postgresql:
    image: postgres:16-alpine
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -d $${POSTGRES_DB} -U $${POSTGRES_USER}"]
      start_period: 20s
      interval: 30s
      retries: 5
      timeout: 5s
    volumes:
      - authentik_db:/var/lib/postgresql/data
    environment:
      POSTGRES_PASSWORD: ${PG_PASS:-secure_pg_pass_2026}
      POSTGRES_USER: ${PG_USER:-authentik}
      POSTGRES_DB: ${PG_DB:-authentik}
  redis:
    image: redis:alpine
    command: --save 60 1 --loglevel warning
    restart: unless-stopped
    healthcheck:
      test: ["CMD-SHELL", "redis-cli ping | grep PONG"]
      start_period: 20s
      interval: 30s
      retries: 5
      timeout: 3s
    volumes:
      - authentik_redis:/data
  server:
    image: ghcr.io/goauthentik/server:2024.6.1
    restart: unless-stopped
    command: server
    environment:
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_POSTGRESQL__HOST: postgresql
      AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
      AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
      AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS:-secure_pg_pass_2026}
      AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:-generate_random_50_char_secret}
    volumes:
      - ./media:/media
      - ./custom-templates:/templates
    ports:
      - "9000:9000"
      - "9443:9443"
    depends_on:
      - postgresql
      - redis
  worker:
    image: ghcr.io/goauthentik/server:2024.6.1
    restart: unless-stopped
    command: worker
    environment:
      AUTHENTIK_REDIS__HOST: redis
      AUTHENTIK_POSTGRESQL__HOST: postgresql
      AUTHENTIK_POSTGRESQL__USER: ${PG_USER:-authentik}
      AUTHENTIK_POSTGRESQL__NAME: ${PG_DB:-authentik}
      AUTHENTIK_POSTGRESQL__PASSWORD: ${PG_PASS:-secure_pg_pass_2026}
      AUTHENTIK_SECRET_KEY: ${AUTHENTIK_SECRET_KEY:-generate_random_50_char_secret}
    volumes:
      - ./media:/media
      - ./custom-templates:/templates
    depends_on:
      - postgresql
      - redis
volumes:
  authentik_db:
  authentik_redis:

🚀 5-Minute Deployment Guide

  1. 1Spin up a 2 vCPU / 4GB RAM VPS on Hetzner Cloud (€3.79/mo).
  2. 2Install Docker and Docker Compose plugin.
  3. 3Create a directory `mkdir -p /opt/authentik && cd /opt/authentik`.
  4. 4Save the docker-compose.yml file and generate `AUTHENTIK_SECRET_KEY` via `openssl rand -base64 36`.
  5. 5Launch the stack: `docker compose up -d`.
  6. 6Set up reverse proxy (Caddy/Nginx) with SSL certificate pointing to port 9000.
  7. 7Navigate to `https://auth.yourdomain.com/if/flow/initial-setup/` to configure the master admin account.

Recommended Cloud VPS for Authentik

Compare all VPS hosts →
Hetzner Cloud€3.79/mo

CX22 (2 vCPU, 4GB RAM)

Excellent memory overhead for Authentik's Python workers.

Deploy on Hetzner →

Keycloak

Apache-2.0⭐ 22.4k+

Battle-tested enterprise open-source identity and access management by Red Hat.

Min RAM2 GB
Min CPU2 vCPU
GitHub Repo ↗

✅ Advantages

  • Proven at Fortune 500 scale with tens of millions of users
  • Complete multi-realm support separates different client tenants cleanly
  • Massive community and extensive enterprise documentation

⚠️ Trade-offs / Limitations

  • Heavier Java memory footprint
  • Administration console has an enterprise-oriented design

Core Features

▸Standard OIDC, OAuth2, and SAML 2.0 protocol support
▸Multi-realm architecture for true multi-tenant SaaS isolation
▸User federation with Active Directory, LDAP, and Kerberos
▸Fine-grained authorization services and role-based policies

Architecture Notes

Java / Quarkus runtime with Hibernate ORM, connecting to PostgreSQL and Infinispan for clustering.

Known Limitations

Higher base memory consumption (minimum 1.5GB RAM for the JVM).

Official Documentation ↗
📄 docker-compose.yml
Production Ready
version: '3.8'
services:
  keycloak:
    image: quay.io/keycloak/keycloak:latest
    command: start --optimized
    environment:
      KC_DB: postgres
      KC_DB_URL: jdbc:postgresql://postgres:5432/keycloak
      KC_DB_USERNAME: keycloak
      KC_DB_PASSWORD: secure_kc_password_2026
      KC_HOSTNAME: auth.yourdomain.com
      KEYCLOAK_ADMIN: admin
      KEYCLOAK_ADMIN_PASSWORD: super_admin_password_2026
      KC_PROXY: edge
    ports:
      - "8080:8080"
    depends_on:
      - postgres
    restart: always
  postgres:
    image: postgres:16-alpine
    environment:
      POSTGRES_DB: keycloak
      POSTGRES_USER: keycloak
      POSTGRES_PASSWORD: secure_kc_password_2026
    volumes:
      - keycloak_postgres_data:/var/lib/postgresql/data
    restart: always
volumes:
  keycloak_postgres_data:

🚀 5-Minute Deployment Guide

  1. 1Provision a 4GB RAM VPS on Hetzner or DigitalOcean.
  2. 2Install Docker and Docker Compose.
  3. 3Save the docker-compose.yml file with production credentials.
  4. 4Start the containers with `docker compose up -d`.
  5. 5Expose port 8080 behind Caddy / Nginx with Let's Encrypt SSL.

Recommended Cloud VPS for Keycloak

Compare all VPS hosts →
Hetzner Cloud€3.79/mo

CX22 (2 vCPU, 4GB RAM)

Ample RAM for JVM and PostgreSQL database caching.

Deploy on Hetzner →

Quick Specification Matrix

ToolLicenseMin RAMMin CPUGitHub RepoPrimary Advantage
Auth0 & Okta (Proprietary)Proprietary ClosedManaged CloudManaged CloudN/ATurnkey onboarding with vendor lock-in & paywalls
AuthentikGPL-3.02 GB1 vCPUgoauthentik/authentikSuperb modern web administration interface
KeycloakApache-2.02 GB2 vCPUkeycloak/keycloakProven at Fortune 500 scale with tens of millions of users

Performance Benchmarks & Hard Operational Limits

Real-world operational trade-offs, resource consumption limits, and measured throughput.

Benchmark MetricAuth0 & Okta BaselineSelf-Hosted Alternative MetricOperational Bottleneck / LimitSource
Token Validation Latency (JWT verify)45ms - 120ms (Cloud JWKS endpoint fetch)1ms - 5ms (Local public key verification in memory)Network round-trip time vs local cryptographic signature verification.Production Test
Login Flow Completion Time450ms - 900ms (Multiple cloud redirects)80ms - 180ms (Direct local proxy / auth session)Database password hashing (bcrypt/argon2) CPU cost.Authentik Scaling Documentation
Max Concurrent Auth Requests100 - 500 req/sec (Auth0 rate limiting policies)2,500 - 8,000 req/sec per 4 vCPU nodePostgreSQL connection pool and Redis cache IOPS.Production Test

Frequently Asked Questions

Practical deployment, migration, and maintenance answers.

Can I connect enterprise SAML 2.0 identity providers (like Okta, Azure AD) without paying extra?▾

Yes. Both Authentik and Keycloak support unlimited SAML 2.0 and OIDC enterprise connections natively at zero additional licensing cost. You can federate with Microsoft Entra ID (Azure AD), Google Workspace, Okta, or LDAP without restriction.

Does self-hosted auth support modern Passkeys and WebAuthn?▾

Yes. Authentik and Keycloak include native WebAuthn support, allowing users to log in securely using biometric hardware authenticators (Apple Touch ID, Face ID, Windows Hello, and YubiKeys) without entering passwords.

How do client applications integrate with self-hosted Authentik or Keycloak?▾

They use standard OpenID Connect (OIDC) and OAuth 2.0 protocols. You can use standard libraries like NextAuth.js, passport.js, Lucia, AppAuth (iOS/Android), or Spring Security with zero proprietary vendor code.

How is user password security handled?▾

Both Authentik and Keycloak use modern password hashing algorithms (Argon2id and bcrypt) with customizable iteration counts, strict password policy enforcement, breach detection checks (HaveIBeenPwned API), and built-in rate-limiting against brute force attacks.

Can I customize the login UI with my company's branding?▾

Yes. Authentik and Keycloak provide full UI theming support. You can configure custom CSS, logos, background images, and custom localized copy directly in the web console or by mounting theme templates.

Starter Stack Pack — $29

Skip the setup: get the production-ready stack

Don't stitch together configs from five different READMEs. Get all 5 production-hardened Docker Compose stacks — Postgres, Redis, SSL auto-renewal, and backup scripts — ready to deploy in minutes.

⚡n8nVisual workflow automation
📊UmamiPrivacy-first web analytics
🛡️Uptime KumaUptime monitoring & alerts
🔐VaultwardenBitwarden-compatible vault
☁️NextcloudDropbox/Drive replacement
Get the Stack Pack — $29 →

One-time purchase · Instant download · Production-ready

esc
↑↓ navigate↵ open