Pricing
Pricing built for B2B SaaS.
Per-MAU usage with predictable per-connection enterprise add-ons. Real free tier.
All passwordless methods, OAuth, 1 SSO connection. No credit card required.
- ✓1,000 MAUs included
- ✓1 SSO connection
- ✓1 SCIM directory
- ✓Up to 1,000 MAUs
- ✓All passwordless methods
- ✓Drop-in SDKs (React, Next.js, Go, Python, Swift, Kotlin, RN, Flutter)
5,000 MAUs, 5 SSO/SCIM, custom domain, email support.
- ✓5,000 MAUs included
- ✓5 SSO connections
- ✓5 SCIM directories
- ✓Custom domain
- ✓30-day audit retention
- ✓Webhooks + analytics
25,000 MAUs, unlimited SSO/SCIM, FGA up to 1M checks/mo, SOC2 reports.
- ✓25,000 MAUs included
- ✓Unlimited SSO connections
- ✓Unlimited SCIM directories
- ✓Fine-grained authorization
- ✓Audit log streams (S3 / ClickHouse / Datadog)
- ✓90-day audit retention
2,000,000 MAUs, dedicated CSM, custom DPA, advanced threat detection, 99.99% SLA, priority SAML queue.
- ✓2,000,000 MAUs included
- ✓Unlimited SSO connections
- ✓Unlimited SCIM directories
- ✓Fine-grained authorization
- ✓Everything in Growth, plus:
- ✓99.99% uptime SLA
Dedicated infra, BAA/DPA, EU residency, BYO-KMS, 99.99% SLA.
- ✓Unlimited SSO connections
- ✓Unlimited SCIM directories
- ✓Fine-grained authorization
- ✓Custom MAU + connection allotments
- ✓Single-tenant dedicated infra
- ✓BYO-KMS (AWS KMS grants)
The full comparison.
What is included by tier. Nothing hidden in a footnote.
| Feature | Developer | Starter | Growth | Business | Enterprise |
|---|---|---|---|---|---|
| MAUs included | 1,000 | 5,000 | 25,000 | 2,000,000 | Custom |
| Overage per 1,000 MAUs | — | $15 | $10 | $5 | Negotiated |
| SSO connections (SAML / OIDC) | 1 | 5 | Unlimited | Unlimited | Unlimited |
| SCIM directories | — | 5 | Unlimited | Unlimited | Unlimited |
| Passkeys, magic links, OAuth social | ✓ | ✓ | ✓ | ✓ | ✓ |
| Custom domain | — | ✓ | ✓ | ✓ | ✓ |
| Admin Portal (customer-facing SSO setup) | ✓ | ✓ | ✓ | ✓ | ✓ |
| Fine-grained authorization (FGA) | — | Add-on | Included | Included | Included |
| Audit log retention | 7 days | 30 days | 90 days | 180 days | Custom (up to 7 years) |
| Audit log streams | — | — | ✓ | ✓ | ✓ |
| Webhooks + delivery analytics | ✓ | ✓ | ✓ | ✓ | ✓ |
| Adaptive risk engine | Basic | Basic | Full | Full + advanced threat detection | Full + custom rules |
| Data residency (US / EU / IN / AU) | US | US | US | US / EU | Pick any |
| BAA / DPA | — | DPA | DPA | Custom DPA | BAA + DPA |
| BYO-KMS | — | — | — | — | ✓ |
| SAML configuration queue | Standard | Standard | Standard | Priority | White-glove |
| Support | Community | Email, 48h | Priority, 24h | Dedicated CSM | Named CSM + on-call |
| Contractual SLA | — | 99.9% | 99.95% | 99.99% | 99.99% |
Pricing FAQ.
What counts as a Monthly Active User (MAU)?
+
An MAU is a unique end-user identity that completed at least one successful authentication ceremony (passkey, magic link, OAuth callback, SAML ACS, or refresh token exchange) within a 30-day rolling window in your project. Dashboard operators (your team) do not count toward MAUs; end users do. The same human identity counted once per project per month, even if they belong to many of your customer organizations.
What counts as an SSO connection?
+
An SSO connection is a single configured SAML 2.0 or OIDC integration tied to one customer organization. If Acme Corp configures Okta SAML, that is one connection. If they later add a second Azure AD connection for a subsidiary, that is two. SCIM directories are billed separately as SCIM directories; an SSO connection without SCIM is one connection.
What happens if I exceed my MAU cap?
+
We do not lock you out mid-month. Overages are billed at the per-1,000-MAU rate listed in the comparison matrix and shown in your dashboard usage panel before the cycle closes. If sustained usage suggests you should upgrade to the next tier we will surface that recommendation explicitly; you are never auto-upgraded.
Is the free tier really free?
+
Yes. The Developer tier is free forever for projects under 1,000 MAUs. It includes one SSO connection so you can ship a real B2B product without ever giving us a credit card. We rate-limit the API at sane defaults; no time-bombs.
Annual vs. monthly billing?
+
Annual saves you two months — pay for 10, get 12. There is no other lock-in; you can downgrade at any renewal. The price shown for annual in the tile is the total annual amount, not a per-month equivalent dressed up.
When should I pick Business over Growth?
+
Pick Business when you are above ~250k MAUs, when a 99.99% SLA is a deal-blocker in your enterprise procurement reviews, or when a customer's legal team needs a custom DPA (not the standard one). Business also unlocks the priority SAML configuration queue — Growth uses the standard queue, which is fine, but Business jumps to the front. The 2M MAU pool included with Business is the same pool Enterprise quotes typically start from, so it is the natural step before negotiating Enterprise.
Refunds?
+
Pro-rated refunds within 30 days of an upgrade or initial purchase, no questions asked. After 30 days, plan changes prorate forward to the next renewal but are not refunded backward. Enterprise contracts have their own refund terms; talk to your account manager.
Taxes?
+
Prices shown are exclusive of applicable sales tax, VAT, or GST. We collect tax where we are registered to do so and itemize it on every invoice. Tax-exempt organizations can upload their exemption certificate from the billing page.
Currency?
+
USD is the canonical billing currency. We can invoice in EUR or GBP on Enterprise contracts at the prevailing 30-day average exchange rate.
Can I migrate from Auth0 / Clerk / Cognito / Firebase / Supabase?
+
Yes. The Authio CLI ships an `authio import` sub-command for each. We never import password hashes (we have no place to put them) — existing users are enrolled into passkeys via a magic-link first login. Progressive migration is the default. See the docs for runbooks.
Do I get a discount as a startup or non-profit?
+
Yes. Pre-seed and seed startups (≤ $5M raised, ≤ 2 years old) get the Growth tier free for 12 months. Registered 501(c)(3) non-profits get a permanent 50% discount on any paid tier. Email founders@authio.com or send a verifiable cap-table link.
Build for free. Pay when you have users.
No credit card required for the Developer tier.