Solutions

One sign-in for every application

One account for all of them instead of a password per application, with passkeys, a second factor and sign-in with the company's own account.

Today

Every application has its own sign-in. The customer portal, the booking system and the internal tools each store a password, often the same one. Whoever leaves the company keeps access until somebody remembers every place. And whoever builds an application writes the sign-in again each time, with every mistake that comes with it.

Afterwards

An application sends people to sign in at EAuth and gets a verified identity back. People have one account, sign in with a passkey or a password and a second factor, and see on one page where they are signed in. A company with its own Microsoft or Google account signs its people in through SAML, with the roles they hold in your application.

How it works

On the standards every library knows

OAuth 2.1 and OpenID Connect, always with PKCE. Every common library configures itself from one address; there are SDKs for React, Svelte and Nuxt under the MIT licence.

Passkeys and a second factor, at no extra cost

Passkeys are on for every application. So is an authenticator app with recovery codes, and an application can require it for everybody.

Organisations with roles

If you sell a product to companies, you create organisations, invite members and assign roles. Each organisation can connect its own sign-in through SAML.

You can leave

The export contains the password hashes in their original form. Moving to another provider forces nobody to set a new password.

What it costs

Nothing. There is no paid tier and no user limit, and the terms do not reserve the right to charge later. For companies, an agreement on availability is available on request.

What it cannot do

  • No directory sync (SCIM). Somebody removed from your Microsoft account can no longer sign in through SAML, but stays a member until somebody removes them.
  • No independent security audit so far, and no ISO 27001 or SOC 2 certification. If your procurement requires one, we cannot provide it today.
  • No committed availability for the free service. We measure it publicly at status.elchi.dev.