You can easy deploy Zitadel to Hetzner though ;-)
125 karma · joined February 19, 2021
You can easy deploy Zitadel to Hetzner though ;-)
The matter is definitely more complex than yes and no... my general stand has been that jurisdiction matters a lot when you store and process data from customers, like many cloud services do. iIt matters less if you can take a software and self-host it.
Zitadel started in Switzerland under the name CAOS AG and has still a lot of its operations in Europe. For our US go to market strategy we incorporated Zitadel Inc. which operates out of SF where I also tend to be.
Happy to share more if interested
My take is that Dual Licensing is the better approach here. I.e. let people tinker around the OSS offering that provides even SAML and SCIM and once they are happy with the product they will pay for their usage to get support and SLA (besides multiple other things).
Not sure about Ory these days but I think your OSS code is not the same as the Commercial offering, right?
We agree—Zitadel is a strong platform. Our main challenge as an infrastructure product is balancing flexibility with ease of use. While we offer a lot of adaptability for different use cases, getting started can be daunting. We're actively working to make our onboarding process smoother so users can get up and running more quickly. For example we just started working on a lot of improvements on our SDKs as well as a template login app in nextjs that people can fork.
Some prefer self-hosting, while others opt for SaaS—it really depends on their specific needs. If you require data residency and complete control, self-hosting is the way to go. On the other hand, if you want a hands-off operational experience, SaaS makes more sense.
From our experience at Zitadel, we’ve found that mid-market and enterprise customers often also look for industry standards like SAML and OpenID Connect to integrate their services, so we’ve made those a core part of our offering—including providing fully compliant SAML and OpenID Connect endpoints. It looks like Tesseral is taking a more focused approach with SDK and API integrations for web apps, which makes a lot of sense for many teams starting out.
We also believe that, over time, the distinction between B2C and B2B use cases will blur, and both will be consolidated into a potent, unified identity infrastructure platform. That’s the direction we’re building toward with Zitadel.
Wishing you all the best as Tesseral grows. If you ever want to swap stories about auth, don't hesitate to reach out!
But I have not checked their docs, so I could be wrong.
Zitadel excels in multi-tenancy cases and is easy to self-host
Best of luck with it!
(Disclosure: I'm a co-founder of Zitadel, also building solutions in this space.)
Customer facing it looks like a combination of nextauth and auth0 (at least on my end)
I’ll take your points for a spin internally. We’ve already had some ideas that address some of your concerns, especially around the quotas.
Like a $25ish developer tier I guess, right?
So, if we would increase the free amount and the included in the pro tier it would a little alleviate this pain?
On the definition, we wanted to use DAU because with this we can have on metric to price consumers, business customers and service accounts. To us it was weird to pay for a MAU when a consumer only logs in once a month. Coming back to my reply above... would a "bigger" number of included DAU solve this?
Would you mind sharing your thoughts on our pricing? We certainly love to improve this. Its not our intent to have a smoke and mirrors pricing ;-)
On the subject of maturity and security. Many known enterprises trust Zitadel for their identity needs, especially the self-hosted version, which can be used for free. I think what makes Zitadel a great package in regard of security is that our community actively provides vulnerability disclosures to the project which we track in public.
Let us know what we can improve to show that we take security and stability serious!
We also have a good oidc library that helps you plug into systems that support open id connect.
Zitadel, Casdoor, Ory, Keycloak, Logto?
And yes I am clearly biased.
I see what you mean with "enterprisy", that has some truth to it ;-)
We have some ideas to improve this and to reduce the learning curve for that. I guess from many people we could "hide" the whole multi-tenancy part and just given them a single organzitation to start with.
Disclaimer: I am the CEO of Zitadel ;-)
Disclaimer: I am a co-founder
Providers will most of the time allow to register multiple passkeys or other authentication means, hopefully ;-) which has its own downsides.
I am well aware how the internals work of keystores. But the benefit with "client certs" is that on mTLS you get added benefits besides where the key is stored. And that is that you can "prevent" mitm attacks.
But I guess that is a subject for another thread.