---
title: "EAuth: sign-in for applications, free, from Switzerland"
description: "EAuth: sign-in to OAuth 2.1 and OpenID Connect with passkeys, a second factor and SAML. Free, with no user limit, run in Switzerland and the EU."
url: https://elchi.dev/en/eauth
language: en
---

Product

# The sign-in for your applications.

EAuth signs people in to your applications, to OAuth 2.1 and OpenID Connect, with passkeys, a second factor and organisations. Free, with no user limit, and with an export that lets you leave.

[Register an application](https://panel.elchi.dev/) [Quickstart, ten minutes](https://docs.elchi.dev/quickstart)

## In numbers

0CHF No paid tier and no user limit Source: EAuth terms of service, section 3

120a minute Token requests per application, up to 600 on request Source: EAuth terms of service, section 6.2

15minutes Lifetime of an access token; refresh tokens rotate on every use Source: docs.elchi.dev, security

## What is included

### OAuth 2.1 and OpenID Connect

Only the authorization code flow with PKCE, built to RFC 9700. Every common library configures itself from the address https://eauth.me.

### Passkeys

On for every application, with nothing to configure. A passkey only works on this site, so a copied sign-in page cannot use it.

### A second factor

An authenticator app with recovery codes, included rather than sold as an upgrade. An application or an organisation can require it for everybody.

### Organisations and SAML

For products sold to companies: members, roles, invitations, and per organisation sign-in through Entra ID, Okta or Google Workspace.

### Signed webhooks

Your application hears when somebody registers, signs in, withdraws consent or deletes their account.

### Arriving and leaving

Password hashes from Argon2id, bcrypt, scrypt and PBKDF2 can be imported. The export returns them in their original form.

## SDKs under the MIT licence

For any web page, React and Next.js, Svelte and SvelteKit, Nuxt. The core has no dependencies.

-   `@elchi-studios/eauth`
-   `@elchi-studios/eauth-react`
-   `@elchi-studios/eauth-sveltekit`
-   `@elchi-studios/eauth-nuxt`

[Open source](https://elchi.dev/en/open-source)

## Where the data is

Accounts, sessions and logs sit on our servers in Switzerland, Germany, the Netherlands and France. Mails to your users, such as an address confirmation or a password reset, are sent by Resend, a service from the United States.

[Who sees which data](https://elchi.dev/en/vertrauen)

## What is missing

-   No independent security audit and no certification. When it happens, we publish the result, whatever it is.
-   No directory sync through SCIM.
-   No ready-made sign-in components for your application's interface; the sign-in happens on our page.
-   No committed availability for the free service. For companies there is an agreement on it on request, and a licence to run EAuth on their own servers.

## An honest comparison

What your setup would cost at ten other providers, from their own pricing pages, and where you should pick another one.

[Compare the cost](https://devs.elchi.dev/compare)

[Register an application](https://panel.elchi.dev/) [Documentation](https://docs.elchi.dev/eauth) [For developers](https://devs.elchi.dev/)
