Skip to content

Authentication & SSO

Login, single sign-on and permissions for your applications – matched to your customers, your data location and your operating effort.

dectria implements login, single sign-on (SSO) and user management for web applications, apps and SaaS platforms: sign-in with password, passkeys or a company account, tenants and roles, and automatic user provisioning from the customer's directory.

We know several solutions from production: NetCero, an ESG platform in which dectria holds a stake, uses Keycloak. Campivio, a booking platform for campsites in which dectria holds a stake, uses WorkOS. We used Clerk in a client project.

Which solution fits depends on your customers, the required data location and the operating effort you want to carry. We make this decision with you before the first line of code.

Michael Jauk Your contact Michael Jauk Contact for backend & architecture

What is SSO – and when do you need your own identity solution?

Authentication checks who signs in. Single sign-on (SSO) means that users sign in once – often with their company account, such as Microsoft Entra ID – and use several applications with it. Technically, this runs on the standards OpenID Connect (OIDC) or SAML.

Your own identity solution is worth it for B2B SaaS with business customers who require SSO and automatic user provisioning (SCIM), and for several applications with a shared login. It is not worth it for a single internal application: a direct connection to Entra ID is enough there.

Keycloak, WorkOS, Clerk, Auth0, Logto or self-built?

SolutionModelData locationStrengthOwn effort
Keycloakopen source, self-operatedyour serversfull control, many protocolshigher: operation and updates
Logtoopen source or Logto Cloudyour servers or Logto Cloud, incl. an EU regionmodern developer experience, tenantslow to medium
WorkOSSaaS from a US providerat the providerenterprise SSO and SCIM for B2B SaaSlow
ClerkSaaS from a US providerUSA, no region choiceready-made login components for React and Next.jslow
Auth0SaaS from Okta (USA)selectable region, incl. EU (Frankfurt)very broad feature setlow
Self-built, e.g. Better Authopen-source library in your own codeyour databasefull control without a separate servicemedium to high: security is on you

Capabilities

What We Build with Authentication & SSO

Keycloak Setup & Operation WorkOS & Clerk Integration OpenID Connect & SAML SSO with Entra ID & Google Workspace Automatic User Provisioning (SCIM) Tenants & Roles (RBAC) Passkeys & Multi-Factor Authentication Migration Between Identity Providers ID Austria Integration Securing APIs & MCP Servers

Use Cases

Typical Use Cases

SSO for B2B SaaS

Business customers sign in with their own account; new employees are provisioned automatically via SCIM and blocked when they leave.

Shared Login for Several Applications

One identity service for portal, app and internal tools – with consistent roles and one central place for security policies.

Migration & Consolidation

Moving from a self-built or outdated login to a maintained solution, without users having to reset their passwords where the export allows it.

FAQ

Authentication & SSO FAQ

Why do business customers require SSO?
Because their IT wants to control access centrally: employees sign in with their company account, policies such as multi-factor authentication apply automatically, and when someone leaves, they lose access to all applications at once. For B2B software, SSO is therefore a requirement in many tenders.
Keycloak, WorkOS, Clerk or Auth0 – which fits?
Keycloak if data should stay on your own servers and someone takes over operations. WorkOS if a B2B SaaS needs enterprise SSO and SCIM quickly. Clerk for fast logins in React and Next.js applications, Auth0 for a broad feature set with an EU region. If user data should live in your own database, a library such as Better Auth is an option.
Can we connect Entra ID or Google Workspace?
Yes. Sign-in runs via OpenID Connect or SAML, and user provisioning via SCIM if needed: when IT creates or blocks a person in the directory, this happens automatically in your application too. All solutions mentioned support these standards, with different effort in the details.
Where is user data stored?
That depends on the solution: with Keycloak and Better Auth on your own servers, with Logto and Auth0 optionally in an EU region, with Clerk and WorkOS at the US provider. With US providers, transfers usually rely on the EU-US Data Privacy Framework; it is best to align the assessment with your data protection advisor.
Can ID Austria be connected?
Yes. ID Austria supports OpenID Connect and SAML2, and private companies can also register as service providers. The company is registered as a service owner via the Austrian business service portal (USP) and the application as a service provider; then follow tests in the official reference environment and approval.

Every project starts with a conversation.

Let us talk about your individual needs and goals.

Start a project