// Engineering Log
Accounts and SSO: Part 4 — Auth0
Published on 2026-09-22
Auth0 — a cloud authentication service: it takes care of registration, login, account storage and token issuance, and the application connects to it via SDKs and standard protocols. Since May 2021 Auth0 has been owned by Okta, which bought it for $6.5 billion.
What it can do
- Pre-built login pages (Universal Login) and SDKs for web, mobile, and server applications.
- OpenID Connect, OAuth 2.0 and SAML protocols — sign-in for your apps and integration of clients’ corporate identity providers.
- Sign-in via external providers — Google, Apple, GitHub and others.
- Multi-factor authentication (MFA), protection against password guessing and suspicious logins.
- Extendable logic with Actions — snippets of code that run during signup, login and token issuance.
- Separate B2C and B2B scenarios: for B2B there are Organizations, corporate SSO for clients, and an organization-based role model.
Pricing
Prices as of September 2026 according to the Auth0 website (with annual billing you pay for 11 months):
| Plan | B2C | B2B |
|---|---|---|
| Free | $0, up to 25,000 monthly active users | $0, up to 25,000 monthly active users |
| Essentials | from $35 per month | from $150 per month |
| Professional | from $240 per month | from $800 per month |
| Enterprise | on request | on request |
Paid plans scale with the number of monthly active users (MAU), and some features — corporate SSO, advanced MFA, inter-service tokens — are available as add-on modules.
Why it’s convenient
- Speed. Login with registration, password reset and social providers can be connected in a day, not written over weeks.
- No infrastructure to manage. Updates, scaling and availability are the provider’s responsibility.
- Documentation and SDKs for most popular languages and frameworks.
Limitations
- Cost as you grow. The free tier is enough to start, but as the number of users grows and paid modules are added the bill grows faster than the cost of running your own server like Keycloak.
- Vendor lock-in. Rules in Actions, settings and password hashes live inside Auth0; migrating to another system is a separate project, especially if users must retain their passwords.
- Data with a third party. Accounts are stored in the provider’s cloud in the selected region.
Can it be used in Russia
For a Russian company Auth0 is practically inapplicable for two reasons.
- Payment. Paid plans are charged to a foreign card, and Visa and Mastercard issued in Russia have not worked abroad since March 2022.
- Personal data. As of July 1, 2025 the primary collection of personal data of Russian citizens is allowed only in databases located on the territory of the country (clause 5 of Article 18 of Federal Law No. 152-FZ). Registering users directly in a foreign cloud service does not comply with this requirement.
If your users are Russian citizens, it is more reasonable to choose an authentication server hosted on your own server in Russia: Keycloak or FusionAuth.
Common mistakes
- Choosing Auth0 for speed without calculating the cost at the target number of users.
- Keeping business logic in Actions without a copy in your own repository.
- Not planning ahead how to export users when changing providers.
When to choose
Auth0 is justified for a product that targets foreign markets, needs to launch quickly, and is willing to pay to avoid maintaining its own authentication server. It is not suitable for a Russian project with users in Russia.
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related