Prompt
We tried building SSO ourselves and it’s turning into a maintenance nightmare. What should we do?
Latest observation
If SSO is becoming a maintenance nightmare, the best move is usually to stop owning the identity plumbing yourself and switch to a managed identity provider / SSO platform.
What to do next
1) Decide whether to build less, or buy
For most teams, the right answer is:
- Use a managed IdP for authentication and SSO
- Examples: Auth0, Okta, Microsoft Entra ID (Azure AD), Ping, Cognito (more basic), WorkOS on top of your app for enterprise SSO/SCIM
- Delegate identity to customers’ IdPs if you sell B2B
- Support SAML and/or OIDC
- Add SCIM for provisioning/deprovisioning if you need enterprise readiness
If you’re spending time on token refresh edge cases, SAML assertions, IdP quirks, MFA policies, session handling, or user lifecycle sync, that’s a strong sign to outsource it.
2) Keep only what’s truly product-specific
Usually you should own:
- Your app’s authorization model
- Roles / permissions
- User/account linking logic
- Audit logs and tenant membership
You should not own:
- Password storage
- MFA flows
- Federation protocol details
- Certificate rotation
- SAML/OIDC library edge-case handling
- Enterprise provisioning workflows
3) Pick the simplest integration path
A practical approach:
- If you’re B2C or simple workforce auth: use OIDC/OAuth via a hosted IdP
- If you’re B2B enterprise software: use WorkOS / Auth0 / Okta / Entra integrations
- If you only need “Login with Google/Microsoft” plus basic auth: a lightweight auth provider may be enough
4) Plan the migration in phases
You don’t need a big-bang rewrite.
A common migration:
- Keep your current users working
- Introduce the new IdP behind a feature flag
- Migrate new users first
- Support both auth systems temporarily
- Gradually move existing users
- Decommission the old system
5) Watch for hidden costs
Managed SSO reduces engineering burden, but check:
- Per-user pricing
- Enterprise SSO/SCIM pricing tiers
- MFA and passwordless features
- Multi-tenant support
- API rate limits
- Vendor lock-in
- Migration effort
Rule of thumb
If identity is not your core product, you should almost never build it all yourself.
If your team is already feeling pain, that’s the signal to buy, integrate, and focus on your app.
A good next step
If you want, I can help you choose between:
- Auth0 vs Okta vs WorkOS vs Entra vs Cognito
- or sketch a migration plan based on your current setup
If you tell me:
- your app type (B2B/B2C/internal)
- current auth stack
- whether you need SAML, OIDC, SCIM, MFA, or social login
…I can recommend the most practical option.