6,266 karma · joined February 23, 2009
WorkOS founder
mg@workos.com
https://twitter.com/grinich
It turns out to be a pretty complex program to solve at scale. Token fraud is a lucrative market and the adversaries are surprisingly sophisticated. It's a cat-and-mouse game, accelerated with AI.
(If you'd like to work on this, we are hiring :))
I think we have the most advanced RBAC system. You can even map roles from custom IdP groups via SCIM.
More info here: https://workos.com/guides/user-provisioning-scim
We're working on multi-app support. The large majority of our customers only have 1 app (ChatGPT, Claude, Cursor, etc.) but this isn't the case for developers building lots of side projects.
Also working on shipping an agent-friendly Dashboard. Stay tuned :)
Would love to hear any more feedback: mg@workos.com
https://workos.com/docs/directory-sync/attributes
Also certificate renewal flows:
https://workos.com/changelog/certificate-renewal-flow
(I'm the founder.)
Claude Code can often one-shot it. Feel free to reach out if I can help!
I'm the founder and happy to help. We've differentiated by focusing on "b2b auth" via SAML/SCIM, but today we do everything else. We also have products for feature flags, encryption, bot blocking, MCP auth, etc.
Fun fact, we actually launched on HN in 2020 :) https://news.ycombinator.com/item?id=22607402
https://help.openai.com/en/articles/9627404-openai-chatgpt-s...
Here is a major vulnerability we disclosed earlier this year:
It's pretty incredible the level of UI engineering that went into it.
Some screenshots I took: https://x.com/grinich/status/1963744947053703309
WorkOS does exactly this. It's "Stripe for enterprise features."
Our customers include OpenAI, Anthropic, xAI, Cursor, Perplexity, Vercel, Replit, Webflow, Clay, Hex, Carta, Plaid, Drata, Vanta, and many others. If you've used these products, you've used WorkOS!
WorkOS makes it easy to "cross the enterprise chasm." Here's a bit more of the backstory: https://x.com/grinich/status/1841569664465568248
We also launched on HN 5 years ago :) https://news.ycombinator.com/item?id=22607402
We launched here on HN 5 years ago[1] and today power SSO for OpenAI, Cursor, Vercel, and a thousand other apps. We also found the initial configuration step to be painful for users, so we built a self-serve wizard that enables enterprise admins to fix issues.[2]
It's still crazy how much complexity there is with enterprise identity systems and managing the user lifecycle for big orgs. It's like the whole thing is made of weird edge cases and even moreso when you add SCIM, RBAC, MFA, etc etc.
(If anyone reading this also loves suffering at the intersection of IAM and developer tools, we are hiring! Email in my profile :))
Glad things are working well for you. If you have any feedback/ideas, I would love to hear them. Thanks! mg@workos.com
I’m the founder :) Happy to help!
Click on "Automatic volume discounts" here: https://workos.com/pricing
(Our pricing page is confusing and we're working to update it! If you have questions about pricing, please just email us support@workos.com)
Betterauth and WorkOS are pretty different. For example, WorkOS isn't designed exclusively for TypeScript (we support SDKs for a bunch of languages/platforms) and WorkOS runs as a cloud service. The developer experience will always be different because of this.
We also design the platform to be modular, which enables you to just use WorkOS for SSO or SCIM alongside an existing auth stack. We call these the standalone APIs and lots of customers use it this way.
WorkOS is focused on enterprise features for b2b apps and solving problems that come with growing upmarket. Today we power auth for OpenAI, Anthropic, Perplexity, Cursor, Vercel, Plaid, and hundreds more.
We love getting feedback so please feel free to post here, email, or twitter DMs are open. Thanks!
(I also love open source and am glad to see more innovation happening here in the ecosystem!)
We build the Admin Portal for IdP configuration: https://workos.com/admin-portal
WorkOS actually launched on HN about 5 years ago[0] and today it's used by OpenAI, Cursor, Perplexity, and hundreds of other companies.
Feel free to email me if I can help: mg@workos.com
If you have the time and patience, you can also certainly build it yourself. There's no miracles here, just complex engineering and solving a thousand edge cases.
If you decide to use open source, make sure you quickly update dependencies so you're always running latest. Ruby-SAML had a major vulnerability disclosed last month and thousands of apps were affected: https://workos.com/blog/ruby-saml-cve-2024-45409
Single dev in contributors graph: https://github.com/ssoready/ssoready/graphs/contributors
Pre-pivot startup called Okapi (YC W24): https://news.ycombinator.com/item?id=39755927
We took the Heroku approach. All apps get a free *.authkit.app domain for the hosted login page.
AuthKit never has any WorkOS branding. Clerk puts "Powered by Clerk" on your login page unless you pay. This feels gross. Imagine if Heroku/Vercel were injecting ads into your app?!
AuthKit has free MFA. I believe everyone should get secure auth. Clerk charges to enable MFA. They also charge for passkeys and features like impersonation. Why?
Custom domains cost us $ to run (we pay Cloudflare) so we charge for this. It's also designed for commercial apps. The authkit.app is great for any hobby app.