Authentication break-even calculator
Two columns instead of one: the quote you are looking at, against the hours doing it yourself would take.
It does not ask how many users you have. That is the input that makes every calculator on this subject curve the same way, and the article this comes from explains why it is the wrong question: the vendor bill steps up when your product changes category, and the maintenance bill does not.
The quote you were given
Your figures, from the pricing page you are actually looking at. We ship nobody's price list as a default: it would read as current long after it stopped being.
Doing it yourself
The hours start at what the maintenance list in the article adds up to for a system already built. Change them to yours.
The quote you were given0a year
Doing it yourself1,920a year
Same currency as the numbers you typed: the tool has none of its own.
Buying comes out 1,920 lower a year at these numbers.
This is the row where the honest answer is least comfortable for us. The invoice is only half of it: organizations, roles and invitations are weeks of your own work rather than hours, and our free tier does not have them yet.
What the two columns are
The quote you were given is whatever a hosted provider is asking for the shape of product you are building: a plan, and the add-ons that switch on when you start selling to companies. You type it in, because it is the number on the page you are looking at rather than one we copied months ago.
Doing it yourself is the part no comparison page can compute, because they have no product to maintain. It is password storage, rate limiting, email deliverability, session revocation and the security advisory that lands in your auth library on a Tuesday. For a system already built it is a few hours a quarter, and the important property is not that it is small: it is that it stays flat while your user count does not.
Why the question is what you are building
The vendor bill steps up when your product changes category. The maintenance bill does not. That is the whole asymmetry, and it is why the four buttons above change the answer more than any number you can type.
- Consumer app, no companies involved
- At this size the money is a rounding error either way. Decide on ownership and lock-in, not on price.
- Small B2B SaaS with teams
- This is the row where the honest answer is least comfortable for us. The invoice is only half of it: organizations, roles and invitations are weeks of your own work rather than hours, and our free tier does not have them yet.
- Selling to enterprise
- SAML and SCIM are months of work, and they are the part vendors charge the most for. If a large customer is asking this quarter, buy it.
- Internal tool, strict data rules
- Here the arithmetic is beside the point. The reason to keep it yourself was never money, it is that the data never leaves.
Questions this raises
- Why does it not ask how many users I have?
- Because that input decides the answer before you type it. Every calculator that asks it produces the same curve: self-hosting wins eventually, at a scale most products never reach. What actually moves the invoice is selling to companies, which happens early and has nothing to do with headcount.
- Why are the vendor fields empty?
- Because we do not ship anybody's price list. A figure we hardcoded would be right the week we wrote it and quietly wrong afterwards, and a tool carries no date the way an article does. The worked example from our own article is one click away, and it says which month it was read.
- Where does the maintenance number come from?
- From a list of files rather than an estimate: the authentication code in this kit, item by item, with the hours each one costs to keep. The article linked below walks through all of them, including the advisory in our auth library that we patched the same day it landed.
- When is buying simply the right answer?
- Enterprise single sign-on and directory provisioning, SAML and SCIM, are months of work and the part vendors charge the most for. Compliance that goes faster with a certified subprocessor is a legitimate reason on its own. Neither of those is a price comparison.
The maintenance side is not an estimate, it is a list of files: what authentication costs goes through each one, including the advisory that landed in our auth library and was patched the same day.