Four systems, four pricing models: what this comparison is about
The question sounds technical but is really a budget and sovereignty decision: who manages your users' identities, and what does that cost at 1,000, 10,000, or 100,000 accounts? Four systems dominate the shortlists of mid-sized companies: Keycloak, Auth0, Supabase Auth, and Microsoft Entra ID. All four solve the same core problem — login, single sign-on, roles. Their pricing and operating models could hardly be more different.
A wrong decision costs you twice here: first the running fees, then the migration. Nobody swaps an identity system on the side, because password hashes, sessions, and every connected application hang off it. All the more reason to understand the pricing models before the decision instead of after.
About the scope: this comparison is written for decision-makers facing a concrete choice. I deliberately leave out Okta Workforce, AWS Cognito, and Firebase Auth; the four candidates here cover the scenarios we actually encounter in mid-sized companies.
A note on methodology up front: I verified all prices directly on the vendors' pricing pages on September 28, 2026; they are list prices in US dollars. Wherever my own project experience comes in instead, I flag it explicitly.
Keycloak: open source with operational responsibility
The model
Keycloak is an open-source IAM under the Apache 2.0 license: born at Red Hat, an Incubating project of the Cloud Native Computing Foundation (CNCF) since April 2023 — with, per CNCF statistics, more than 12,900 contributors from around 2,500 organizations. You run it yourself, on your own servers or with an EU hoster. What the system does in detail is covered in our foundational article What is Keycloak?.
The strengths
No other system in this comparison offers these three properties in combination:
- Data sovereignty: identities, credentials, and sessions live on your EU infrastructure — no third-country transfer, full audit control.
- Protocol coverage: OIDC and SAML in both roles (IdP and SP), plus LDAP and Active Directory federation for existing directories.
- Cost curve: software costs stay at zero, whether 1,000 or 500,000 users sign in.
White-label logins, customizable authentication flows, and your own extensions come at no extra charge.
The limits
To be honest: Keycloak is the only system on this list that puts operational responsibility on you. Updates, availability, monitoring, and several releases per year need a named owner. An SLA only exists if you organize it yourself — through a service provider or Red Hat's commercial build. For a two-person team without ops capacity, that is the wrong deal.
The second limit: project effort. The admin console is powerful but no self-runner; the realm concept, client configuration, and theming want to be understood. For a clean setup, plan an integration project rather than an afternoon.
The pricing logic
License costs: zero. What you actually budget is setup and operations (explicitly my own estimate from project experience, not a vendor figure): EU infrastructure for a single instance runs at around €50 per month, a high-availability cluster for six-figure user counts at €200 to €500. Maintenance effort comes on top. You will find the full calculation including setup costs in What does Keycloak cost?.
Auth0 by Okta: convenience with a MAU meter
The model
Auth0 is the SaaS classic among identity services, part of Okta since 2021. You embed an SDK; Auth0 handles operations, scaling, and security patches. Billing is per monthly active user (MAU), split into B2C plans for consumer apps and considerably more expensive B2B plans for business-customer portals. For you, that means: no servers, no patches, but a permanent subscription whose size your users determine.
The strengths
The developer experience sets the industry benchmark: quickstarts for every framework, precise documentation, a production-ready login in hours instead of days. The free plan goes surprisingly far with 25,000 MAU. Enterprise requirements such as SAML federations, organization management, and adaptive MFA are available — as paid add-ons or in higher plans.
Then there is the ecosystem: with Actions you extend login flows in code, marketplace integrations cover edge cases, and compliance attestations such as SOC 2 or ISO 27001 are ready to hand. That counts when your customers run audits.
The limits
The pricing tiers have two catches. First: if your user count falls between two tiers, you pay the higher one — at 1,100 MAU that means the 2,500 tier at $175 instead of the $70 for 1,000. Second: the jump from B2C to B2B multiplies the price at the same user count.
Then there is the vendor question: Auth0 is a US service; an EU data region is selectable, but the legal vendor relationship remains. My assessment: negotiable for most mid-sized companies, a genuine review criterion for strictly regulated industries.
The pricing logic
As of September 28, 2026, per auth0.com/pricing: the B2C Essentials plan costs $35 per month for 500 MAU, $70 for 1,000, $700 for 10,000, and $3,500 for 50,000. The B2B Essentials plan: $300 for 1,000 MAU, $2,100 for 10,000. Professional sits well above either: $1,600 for 10,000 B2C MAU. Annual billing equals eleven monthly installments. Self-service booking ends between 20,000 and 50,000 MAU depending on the plan; above that, an enterprise contract applies at a negotiated price.
Supabase Auth: the built-in option
The model
Supabase Auth is not a standalone identity service but a building block of the Supabase platform: authentication wired directly into the Postgres database and its Row Level Security. Users, sessions, and permissions live in the same database as your application data. How we use Supabase in client projects is on our service page Supabase development.
The strengths
The price is the argument: authentication costs nothing of its own, it is included in the platform price — 50,000 MAU in the free plan, 100,000 in the Pro plan at $25 per month. Social logins, magic links, MFA, and passkeys are on board. And because Supabase is open source, self-hosting remains available as an exit option.
For developer teams, the integration advantage counts: permissions move to the data as Row Level Security rules instead of living in a separate policy engine. That saves an entire synchronization layer between the identity system and the database.
The limits
The decisive limit: Supabase Auth is the authentication of one application, not a central identity provider. It speaks SAML in one direction only — as a service provider, so enterprise users can sign in through their company IdP. It is not built to act as an IdP for third-party applications, for SSO across several systems, or for AD federation. Tenant separation in the style of Keycloak realms is missing too. That is exactly where Keycloak territory begins.
The pricing logic
As of September 28, 2026, per supabase.com/pricing: free plan with 50,000 MAU, Pro plan at $25 per month with 100,000 MAU included, $0.00325 per MAU beyond that. Enterprise SSO via SAML costs extra: 50 SSO MAU included, then $0.015 per SSO MAU. Even 200,000 users would come to $350 per month — a fraction of every other SaaS price in this comparison.
Microsoft Entra ID and External ID: the corporate standard
The model
Two products need to be kept apart here. Entra ID (formerly Azure AD) manages employee identities and is licensed per user. Entra External ID is the CIAM offering for customers and partners, billed per MAU — and at the same time the successor to Azure AD B2C, which Microsoft has not sold to new customers since May 2025.
External ID comes in two tenant types: workforce tenants for B2B guests in your own directory, external tenants for consumer apps. For the pricing question, both count together: all external MAU of the linked Azure subscription are billed.
The strengths
In Microsoft shops, Entra ID is simply a given: Conditional Access, Intune connectivity, M365 integration. Employee identities live there anyway, and through Microsoft 365 bundles such as E3 (includes P1) or E5 (includes P2) they are often already paid for. External ID scores with the largest free allowance in this comparison: the first 50,000 MAU cost nothing.
The limits
The flip side is maximum ecosystem lock-in. Login flows and interfaces allow less freedom than Keycloak or Auth0, and the web of plans, add-ons, and meter types takes time to learn. If you are still on Azure AD B2C, you also carry a migration topic: according to Microsoft, support runs until at least May 2030, after which External ID is the designated path.
The pricing logic
As of September 28, 2026, per Microsoft's pricing page: Entra ID P1 costs $7, P2 $10 per user per month with annual billing. External ID stays free up to 50,000 MAU; above that, Microsoft's price list shows $0.03 per MAU. At 100,000 users, that is $1,500 per month. Add-ons such as SMS authentication, ID Governance, or M2M transactions come on top — with no free allowance of their own.
The decision matrix
As different as the models are, the picture becomes clear once you lay five decision criteria side by side. The cost rows assume the cheapest fitting plan in each case: Auth0 B2C Essentials, Supabase Pro, External ID without add-ons. The Keycloak figures are our operating estimate for EU infrastructure, excluding staff effort for maintenance.
| Criterion | Keycloak | Auth0 | Supabase Auth | Entra External ID |
|---|---|---|---|---|
| Data sovereignty / EU | Full control on your own EU servers | EU region selectable, US vendor | EU region selectable, self-hostable | Microsoft cloud with EU Data Boundary |
| SAML enterprise capability | Full: as IdP and SP | Yes, as a paid add-on | SP only, no IdP | Yes, core feature |
| Operational effort | High: operations are on you | Minimal | Minimal | Low to medium |
| Cost at 1,000 users | approx. €50 to €100 infrastructure (estimate) | $70 | $0 to $25 | $0 |
| Cost at 10,000 users | approx. €100 to €200 (estimate) | $700 | $25 | $0 |
| Cost at 100,000 users | approx. €200 to €500 (estimate) | Enterprise contract | $25 | $1,500 |
| Vendor lock-in | None | High | Medium | High |
Two reading aids. First: the Auth0 column shows B2C prices; for B2B portals, multiply the row by roughly a factor of three to four. Second: the Keycloak costs look small but contain no staff effort — if you outsource operations, budget a maintenance retainer on top.
Third, on data sovereignty: “EU region selectable” is not the same as control. With US vendors, vendor access and the US legal framework remain in place; how heavily that weighs depends on your industry and your data protection officer.
The MAU bill of a SaaS IdP is the only cloud cost line that grows automatically with your market success.
Which solution fits which scenario?
From the matrix and the pricing logic follows a set of recommendations I also stand by in consulting conversations — honest enough not to land on Keycloak every time.
Startup app: one application, fast growth
Take the built-in option. If you are building on Supabase anyway: Supabase Auth, and the topic is settled for at most $25 per month. Without Supabase in the stack, Auth0's free plan with 25,000 MAU is a fair start. A central IdP would be overhead here: you would run one more system without realizing an advantage.
The moment to switch only comes when a second application needs SSO or an enterprise customer demands SAML. Until then: the simplest solution that covers your scenario is the right one.
Mid-market portal: customer login, data sovereignty, predictable costs
This is where Keycloak plays its strengths: customer data on your own EU infrastructure, SAML for connecting business customers, costs independent of user-base growth. In our projects, we combine it with Supabase — Keycloak as the identity layer, Supabase as the data backend.
A worked example for a portal with 10,000 business-customer users: Auth0 B2B Essentials costs $2,100 per month, a good $25,000 per year. In our experience, running Keycloak including a maintenance retainer comes in well below that — and the curve stays flat when 10,000 users become 30,000.
Check External ID as a counter-offer if your company sits deep in Microsoft 365 and stays permanently below 50,000 customer MAU: then Microsoft's free allowance is hard to beat. But run the numbers for growth beyond that threshold before you sign.
Enterprise with Active Directory
For employee identities, there is rarely a way around Entra ID: they already exist there, paid for through M365 licenses. The real decision falls on the customer login. External ID fits if the free allowance and Microsoft governance convince you. Keycloak fits if business units demand customizable flows, white-labeling, or independence from Microsoft's pricing logic — and both together work: AD federation is one of Keycloak's core features.
Next steps
My closing advice: do not calculate today's numbers but your user count in three years — and run it against all four pricing models. If you decide at 5,000 MAU and land at 80,000, Auth0, Supabase, and External ID hand you three completely different bills. That single table row is the most expensive line of this whole comparison.
Are you facing this decision right now? In a free initial consultation, we run your scenarios with your user numbers: with an honest recommendation, even if it reads “stick with SaaS”.
