Product

The sign-in for your applications.

EAuth signs people in to your applications, to OAuth 2.1 and OpenID Connect, with passkeys, a second factor and organisations. Free, with no user limit, and with an export that lets you leave.

In numbers

0CHF No paid tier and no user limit Source: EAuth terms of service, section 3
120a minute Token requests per application, up to 600 on request Source: EAuth terms of service, section 6.2
15minutes Lifetime of an access token; refresh tokens rotate on every use Source: docs.elchi.dev, security

What is included

OAuth 2.1 and OpenID Connect

Only the authorization code flow with PKCE, built to RFC 9700. Every common library configures itself from the address https://eauth.me.

Passkeys

On for every application, with nothing to configure. A passkey only works on this site, so a copied sign-in page cannot use it.

A second factor

An authenticator app with recovery codes, included rather than sold as an upgrade. An application or an organisation can require it for everybody.

Organisations and SAML

For products sold to companies: members, roles, invitations, and per organisation sign-in through Entra ID, Okta or Google Workspace.

Signed webhooks

Your application hears when somebody registers, signs in, withdraws consent or deletes their account.

Arriving and leaving

Password hashes from Argon2id, bcrypt, scrypt and PBKDF2 can be imported. The export returns them in their original form.

SDKs under the MIT licence

For any web page, React and Next.js, Svelte and SvelteKit, Nuxt. The core has no dependencies.

  • @elchi-studios/eauth
  • @elchi-studios/eauth-react
  • @elchi-studios/eauth-sveltekit
  • @elchi-studios/eauth-nuxt
Open source

Where the data is

Accounts, sessions and logs sit on our servers in Switzerland, Germany, the Netherlands and France. Mails to your users, such as an address confirmation or a password reset, are sent by Resend, a service from the United States.

Who sees which data

What is missing

  • No independent security audit and no certification. When it happens, we publish the result, whatever it is.
  • No directory sync through SCIM.
  • No ready-made sign-in components for your application's interface; the sign-in happens on our page.
  • No committed availability for the free service. For companies there is an agreement on it on request, and a licence to run EAuth on their own servers.

An honest comparison

What your setup would cost at ten other providers, from their own pricing pages, and where you should pick another one.

Compare the cost