HNHacker News
TopNewBestAskShowJobs

grinich

6,266 karma · joined February 23, 2009

Michael Grinich

WorkOS founder

mg@workos.com

https://twitter.com/grinich

submissionscomments
grinich··on The relay market powering token resellers and fraud
We do a lot more than device fingerprinting including training custom fraud models. We don't broadly publish our techniques for detection since that would make them much easier to circumvent.
grinich··on The relay market powering token resellers and fraud
This is the problem we've been working on solving with WorkOS Radar. We run it for Cursor and a bunch of other AI companies who have a free trial that gives some free inference to test the product.

It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.

https://workos.com/radar

(If you'd like to work on this, we are hiring :))

grinich··on From Supabase to Clerk to Better Auth
Custom roles per-org is supported natively with WorkOS. (I'm the founder.)

I think we have the most advanced RBAC system. You can even map roles from custom IdP groups via SCIM.

More info here: https://workos.com/guides/user-provisioning-scim

grinich··on From Supabase to Clerk to Better Auth
Hi I'm the founder of WorkOS.

We're working on multi-app support. The large majority of our customers only have 1 app (ChatGPT, Claude, Cursor, etc.) but this isn't the case for developers building lots of side projects.

Also working on shipping an agent-friendly Dashboard. Stay tuned :)

Would love to hear any more feedback: mg@workos.com

grinich··on From Supabase to Clerk to Better Auth
WorkOS has a built-in workflow for all the complex SAML/SCIM attribute mapping.

https://workos.com/docs/directory-sync/attributes

Also certificate renewal flows:

https://workos.com/changelog/certificate-renewal-flow

(I'm the founder.)

grinich··on Ask HN: How Are You Handling Auth in 2026?
Docs to migrate from Clerk to WorkOS: http://workos.com/docs/migrate/clerk

Claude Code can often one-shot it. Feel free to reach out if I can help!

grinich··on Ask HN: How Are You Handling Auth in 2026?
WorkOS powers auth for OpenAI, Anthropic, Cursor, Vercel, Perplexity, Clay, Webflow, Granola, and a bunch of others. Free up to 1m users, you pay for enterprise features.

I'm the founder and happy to help. We've differentiated by focusing on "b2b auth" via SAML/SCIM, but today we do everything else. We also have products for feature flags, encryption, bot blocking, MCP auth, etc.

Fun fact, we actually launched on HN in 2020 :) https://news.ycombinator.com/item?id=22607402

grinich··on Claude Status – Elevated error rates on the API
What do you use for RBAC today? Do you have AI rewrite it every time?
grinich··on Okta's NextJS-0auth troubles
If you’re looking for b2b identity, I’m the founder of WorkOS and we power this for a bunch of apps. Feel free to email me, mg@workos.com
grinich··on Kratos - Cloud native Auth0 open-source alternative (self-hosted)
OpenAI uses WorkOS for SSO and SCIM.

https://help.openai.com/en/articles/9627404-openai-chatgpt-s...

grinich··on Kurt Got Got
It's so bad

Here is a major vulnerability we disclosed earlier this year:

https://workos.com/blog/samlstorm

grinich··on Kurt Got Got
I got hit with the same kind of phishing attack a couple months ago

It's pretty incredible the level of UI engineering that went into it.

Some screenshots I took: https://x.com/grinich/status/1963744947053703309

grinich··on Auth.js is now part of Better Auth
They migrated SSO/SAML to WorkOS, and consumer auth to forked open source.
grinich··on Vendors that treat single sign-on as a luxury feature
(self plug since you asked!)

WorkOS does exactly this. It's "Stripe for enterprise features."

https://workos.com

Our customers include OpenAI, Anthropic, xAI, Cursor, Perplexity, Vercel, Replit, Webflow, Clay, Hex, Carta, Plaid, Drata, Vanta, and many others. If you've used these products, you've used WorkOS!

WorkOS makes it easy to "cross the enterprise chasm." Here's a bit more of the backstory: https://x.com/grinich/status/1841569664465568248

We also launched on HN 5 years ago :) https://news.ycombinator.com/item?id=22607402

grinich··on Vendors that treat single sign-on as a luxury feature
thank you! feedback very welcome if you have any suggestions for things to improve or ideas for what we should build next
grinich··on Vendors that treat single sign-on as a luxury feature
also if anyone wants to go down the rabbit hole about why SAML is hard to implement, this is a pretty interesting writeup of a major 0-day vuln we discovered earlier this year: https://workos.com/blog/samlstorm
grinich··on Vendors that treat single sign-on as a luxury feature
I started a startup to fix this exact problem integrating and configuring SSO/SAML.[0]

We launched here on HN 5 years ago[1] and today power SSO for OpenAI, Cursor, Vercel, and a thousand other apps. We also found the initial configuration step to be painful for users, so we built a self-serve wizard that enables enterprise admins to fix issues.[2]

It's still crazy how much complexity there is with enterprise identity systems and managing the user lifecycle for big orgs. It's like the whole thing is made of weird edge cases and even moreso when you add SCIM, RBAC, MFA, etc etc.

(If anyone reading this also loves suffering at the intersection of IAM and developer tools, we are hiring! Email in my profile :))

[0] https://workos.com

[1] https://news.ycombinator.com/item?id=22607402

[2] https://workos.com/admin-portal

grinich··on Ask HN: What do you use for user management/IAM in your SaaS app?
Hey I'm the founder of WorkOS.

Glad things are working well for you. If you have any feedback/ideas, I would love to hear them. Thanks! mg@workos.com

grinich··on You can now disable all AI features in Zed
Hey - I'm the founder of WorkOS. Happy to chat about the playbook we see with OSS projects spinning-off a commercial offering. It's pretty common and we work with a lot of these businesses, enabling them to continue investment in the ecosystem too. mg@workos.com
grinich··on Ask HN: What Are You Working On? (June 2025)
For SSO, RBAC, etc, check out https://workos.com

I’m the founder :) Happy to help!

grinich··on What a developer needs to know about SCIM
Hi - I work at WorkOS. That's the base price and it decreases exponentially as you scale.

Click on "Automatic volume discounts" here: https://workos.com/pricing

(Our pricing page is confusing and we're working to update it! If you have questions about pricing, please just email us support@workos.com)

grinich··on Launch HN: Better Auth (YC X25) – Authentication Framework for TypeScript
Hi - I'm the founder of WorkOS. Would love any feedback you can share here or via email (mg@workos.com)

Betterauth and WorkOS are pretty different. For example, WorkOS isn't designed exclusively for TypeScript (we support SDKs for a bunch of languages/platforms) and WorkOS runs as a cloud service. The developer experience will always be different because of this.

We also design the platform to be modular, which enables you to just use WorkOS for SSO or SCIM alongside an existing auth stack. We call these the standalone APIs and lots of customers use it this way.

WorkOS is focused on enterprise features for b2b apps and solving problems that come with growing upmarket. Today we power auth for OpenAI, Anthropic, Perplexity, Cursor, Vercel, Plaid, and hundreds more.

We love getting feedback so please feel free to post here, email, or twitter DMs are open. Thanks!

(I also love open source and am glad to see more innovation happening here in the ecosystem!)

grinich··on Any guide to migrate from ssojet to auth0
What about WorkOS? I'm the founder and would be happy to help. mg@workos.com
grinich··on Show HN: Torii – a framework agnostic authentication library for Rust
I'm the founder of WorkOS and we solve this problem for developers, primarily focusing on the challenges around enterprise SAML, SCIM, complex RBAC, fine-grained authorization, and more.

We build the Admin Portal for IdP configuration: https://workos.com/admin-portal

WorkOS actually launched on HN about 5 years ago[0] and today it's used by OpenAI, Cursor, Perplexity, and hundreds of other companies.

Feel free to email me if I can help: mg@workos.com

[0] https://news.ycombinator.com/item?id=22607402

grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
There are several open source options out there (several linked above) that could be a good fit for your business economics. I know lots of folks talk about Supabase and Auth.js on X.

If you have the time and patience, you can also certainly build it yourself. There's no miracles here, just complex engineering and solving a thousand edge cases.

If you decide to use open source, make sure you quickly update dependencies so you're always running latest. Ruby-SAML had a major vulnerability disclosed last month and thousands of apps were affected: https://workos.com/blog/ruby-saml-cve-2024-45409

grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
"You can think of us as an open source alternative to products like Auth0 or WorkOS." from SSOReady's README: https://github.com/ssoready

Single dev in contributors graph: https://github.com/ssoready/ssoready/graphs/contributors

Pre-pivot startup called Okapi (YC W24): https://news.ycombinator.com/item?id=39755927

grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
on changing emails: https://news.ycombinator.com/item?id=41927216
grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
Yes it will happen!
grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
I work at WorkOS / AuthKit.

We took the Heroku approach. All apps get a free *.authkit.app domain for the hosted login page.

AuthKit never has any WorkOS branding. Clerk puts "Powered by Clerk" on your login page unless you pay. This feels gross. Imagine if Heroku/Vercel were injecting ads into your app?!

AuthKit has free MFA. I believe everyone should get secure auth. Clerk charges to enable MFA. They also charge for passkeys and features like impersonation. Why?

Custom domains cost us $ to run (we pay Cloudflare) so we charge for this. It's also designed for commercial apps. The authkit.app is great for any hobby app.

grinich··on Comparing Auth from Supabase, Firebase, Auth.js, Ory, Clerk and Others
Security features seem like the ONE thing you wouldn't want an LLM generating/hallucinating ...
Page 1 of 34Next →