Prompt
What should I use to support SAML and OIDC for customers?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you need to support both SAML and OIDC for customers, the usual choices are:
Best practical options
-
Use an identity broker / customer identity platform
- Examples: Auth0, Okta Customer Identity, Azure AD B2C, FusionAuth, WorkOS
- Good if you want to:
- Support enterprise SSO quickly
- Avoid building SAML/OIDC protocol handling yourself
- Offer a nicer setup experience for customers
-
Use an IdP-agnostic SSO layer in your app
- Your app integrates with a single service, and that service handles SAML + OIDC connections to customer IdPs.
- Especially useful if you have many enterprise customers and want self-serve SSO config.
-
Build it yourself with libraries
- For OIDC: straightforward with most web frameworks.
- For SAML: significantly more complex and error-prone.
- Only recommended if you have strong security/auth expertise and specific reasons to own it.
Rule of thumb
- If this is for customer-facing enterprise SSO, WorkOS or Auth0/Okta are often the fastest paths.
- If you need full CIAM (sign-up/sign-in, user management, enterprise SSO), look at Auth0, Okta CIC, or Azure AD B2C.
- If you mainly need enterprise SSO only, WorkOS is a common choice.
What I’d recommend
- Small/medium SaaS wanting enterprise SSO: WorkOS
- Need broader auth/user management platform: Auth0 or Okta Customer Identity
- Microsoft-heavy enterprise customers / Azure ecosystem: Azure AD B2C
- Prefer self-hosted/open-source: FusionAuth
If you want, I can also give you:
- a comparison table
- a recommendation based on your stack
- or a build-vs-buy decision guide