Prompt
I’m trying to decide between hosted auth and self hosted auth for a B2B SaaS app, what are the tradeoffs?
Latest observation
For a B2B SaaS app, the choice between hosted auth and self-hosted auth is mostly a tradeoff between speed and simplicity versus control and customization.
Hosted auth
Examples: Auth0, Clerk, Firebase Auth, Cognito, WorkOS (for some use cases)
Pros
- Fastest to ship: You avoid building core auth flows from scratch.
- Less security burden: Password storage, MFA, recovery flows, session handling, and threat mitigation are mostly handled for you.
- Better reliability by default: Mature vendors usually have solid uptime, monitoring, and support.
- Built-in features: Social login, email verification, MFA, magic links, SSO, SCIM, user management, etc.
- Compliance help: Vendors may reduce the amount of auth infrastructure you need to audit yourself.
Cons
- Vendor lock-in: Migrating later can be painful, especially if your app depends on vendor-specific concepts.
- Higher marginal cost: Pricing often grows with MAUs, organizations, logins, or enterprise features.
- Less flexibility: Custom login UX, unusual org/tenant behavior, or deep policy control can be constrained.
- Dependent on a third party: If they have an outage or rate limit issue, your login can break.
- Data/control concerns: Some enterprises care where identity data lives and how it’s processed.
Self-hosted auth
Examples: Keycloak, Ory, FusionAuth, Homegrown auth stack
Pros
- Maximum control: You own the data model, login flows, tenant model, and policy logic.
- Deep customization: Easier to support unique B2B requirements like org-based access, complex roles, custom SSO flows, or specialized provisioning.
- Potentially lower long-term cost at scale: Especially if auth becomes very high volume and you have strong infra/ops capacity.
- Less vendor dependency: You’re not tied to a SaaS auth provider’s pricing or roadmap.
- Easier to align with enterprise requirements: More control over data residency, network isolation, and auditability.
Cons
- Slower to build and maintain: Auth is deceptively complex; the “last 20%” is a lot.
- Security risk: You own password security, MFA, token/session handling, account recovery, and attack mitigation.
- Operational burden: Upgrades, scaling, monitoring, backup/recovery, incident response, and support are yours.
- Harder compliance work: You’ll need stronger internal processes and audits.
- Engineering distraction: Time spent on auth is time not spent on core product.
What matters most for B2B SaaS
B2B SaaS usually needs some combination of:
- Multi-tenant org/account model
- SSO (SAML/OIDC)
- SCIM / automated provisioning
- RBAC / granular permissions
- Audit logs
- Enterprise-specific controls like domain capture, invitation flows, and admin roles
If you need those quickly, hosted auth with strong enterprise support often wins early. If your requirements are very specific or you expect lots of enterprise complexity, self-hosted may be better long term.
A practical rule of thumb
Choose hosted auth if:
- You want to launch quickly.
- You have a small team.
- Your auth needs are fairly standard.
- You expect to iterate on product-market fit before auth becomes a strategic differentiator.
- You can tolerate vendor pricing and some lock-in.
Choose self-hosted auth if:
- You have strong platform/security engineering capacity.
- You need extensive customization or strict data/control requirements.
- You expect heavy enterprise identity integration.
- Auth is central to your product or business model.
- You want to avoid third-party dependency and can support the operational load.
Common middle path
A lot of B2B SaaS companies do this:
- Start with hosted auth
- Keep auth abstractions in your app so migration is possible
- Avoid embedding vendor-specific assumptions into your core domain model
- Move to self-hosted later only if enterprise needs or cost justify it
Recommendation
If you’re early-stage or mid-stage and not already staffed for identity/security infrastructure, hosted auth is usually the right default for B2B SaaS.
If you already know you’ll need complex enterprise SSO/provisioning/data residency and have the team to run it, self-hosted may pay off.
If you want, I can also give you:
- a decision matrix,
- a build vs buy checklist for B2B SaaS auth, or
- recommendations based on your stack and company stage.