We should be able to demand users remembering their passwords, I dont like to cater towards users who simply dont want to put in the work to use my product.
Will I lose potential users over this? Yes. Does it feel bad knowing I am in control and wont have to offload to 3rd party vendors? Hell no.
You don't have to use a 3rd party service for OAuth. You can do it in house.
I want intentional users not the ones that click "sign up with google", try out the app once and never come back. Also I don't have the time to learn how to properly integrate more auth methods into my app. I want my own user table, I want predictability on how a user model looks and I want to be in control of everything.
SAML/SSO is indeed finicky, but the problematic part (mapping attributes) is often done by IT teams, ESPECIALLY if you use a third-party provider.
https://workos.com/docs/directory-sync/attributes
Also certificate renewal flows:
https://workos.com/changelog/certificate-renewal-flow
(I'm the founder.)
Auth isn’t something I want to think about. There are a lot of hidden traps.