Authentication & SSO
Login, single sign-on and permissions for your applications – matched to your customers, your data location and your operating effort.
dectria implements login, single sign-on (SSO) and user management for web applications, apps and SaaS platforms: sign-in with password, passkeys or a company account, tenants and roles, and automatic user provisioning from the customer's directory.
We know several solutions from production: NetCero, an ESG platform in which dectria holds a stake, uses Keycloak. Campivio, a booking platform for campsites in which dectria holds a stake, uses WorkOS. We used Clerk in a client project.
Which solution fits depends on your customers, the required data location and the operating effort you want to carry. We make this decision with you before the first line of code.
Your contact Michael Jauk Contact for backend & architecture What is SSO – and when do you need your own identity solution?
Authentication checks who signs in. Single sign-on (SSO) means that users sign in once – often with their company account, such as Microsoft Entra ID – and use several applications with it. Technically, this runs on the standards OpenID Connect (OIDC) or SAML.
Your own identity solution is worth it for B2B SaaS with business customers who require SSO and automatic user provisioning (SCIM), and for several applications with a shared login. It is not worth it for a single internal application: a direct connection to Entra ID is enough there.
Keycloak, WorkOS, Clerk, Auth0, Logto or self-built?
| Solution | Model | Data location | Strength | Own effort |
|---|---|---|---|---|
| Keycloak | open source, self-operated | your servers | full control, many protocols | higher: operation and updates |
| Logto | open source or Logto Cloud | your servers or Logto Cloud, incl. an EU region | modern developer experience, tenants | low to medium |
| WorkOS | SaaS from a US provider | at the provider | enterprise SSO and SCIM for B2B SaaS | low |
| Clerk | SaaS from a US provider | USA, no region choice | ready-made login components for React and Next.js | low |
| Auth0 | SaaS from Okta (USA) | selectable region, incl. EU (Frankfurt) | very broad feature set | low |
| Self-built, e.g. Better Auth | open-source library in your own code | your database | full control without a separate service | medium to high: security is on you |
Related topics
Capabilities
What We Build with Authentication & SSO
Use Cases
Typical Use Cases
SSO for B2B SaaS
Business customers sign in with their own account; new employees are provisioned automatically via SCIM and blocked when they leave.
Shared Login for Several Applications
One identity service for portal, app and internal tools – with consistent roles and one central place for security policies.
Migration & Consolidation
Moving from a self-built or outdated login to a maintained solution, without users having to reset their passwords where the export allows it.
FAQ
Authentication & SSO FAQ
Why do business customers require SSO?
Keycloak, WorkOS, Clerk or Auth0 – which fits?
Can we connect Entra ID or Google Workspace?
Where is user data stored?
Can ID Austria be connected?
Every project starts with a conversation.