Workforce IAM is the employee directory: joiners, leavers, and access to internal apps. CIAM is the other stack. It is the signup, login, session, and consent path your customers and tenant admins actually hit, at consumer or B2B scale. Mixing those jobs is the usual mis-buy. You end up with a workforce tenant that cannot host a consumer consent screen, or a CIAM that cannot govern employee joiner-mover-leaver. If you are shopping this page, you are buying a CIAM platform seat, not 20 logos.
Startup Stash already keeps a wide catalog at Top 20 Customer Identity and Access Management (CIAM) Tools. This page is the buyer shortlist: seven platforms that cover signup through consent. We checked each platform's product and pricing pages using our How we review tools method. Workforce identity is a different shortlist on Best Enterprise IGA Platforms in 2026.
CIAM Platforms at a Glance
| Platform | Best for | Pricing model | Highlights |
|---|---|---|---|
| Auth0 (Okta) | Developer CIAM with social, Organizations, Actions, and an FGA path | MAU, public B2C/B2B plans | Actions at login. Organizations as a first-class B2B object |
| Amazon Cognito | AWS-native user pools plus hosted UI at volume rates | MAU, public AWS rates | Lite, Essentials, and Plus. Managed Login. Passkeys on Essentials+ |
| Microsoft Entra External ID | Azure CIAM when the shop already lives in Microsoft | MAU, public Microsoft rates | Next-gen external tenant. Not a rename of Azure AD B2C |
| Clerk | Turnkey auth UI and orgs for Next.js / modern JS startups | MRU, public plans | Prebuilt components. First Day Free. Orgs plus one Enterprise connection on Pro |
| Frontegg | Productized B2B multi-tenant identity | Free floor then scale | Admin portal, RBAC, SSO/SCIM, unlimited Organizations on PAYG |
| Ping Identity | Orchestrated enterprise CIAM (PingOne for Customers) | Annual packages, public starts | DaVinci no-code journeys. ForgeRock lineage, separate SKU from Advanced Identity Cloud |
| FusionAuth | Self-hostable CIAM when SaaS MAU pricing is the blocker | Community free; paid cloud calculator | Unlimited Community self-host. OAuth, OIDC, SAML. Passkeys with a free license |
Auth0 (Okta)

Auth0 is the developer CIAM benchmark on this shortlist. Okta closed the Auth0 acquisition on 3 May 2021. Auth0 remains the product brand. Social login, Organizations, Actions (Node.js functions at login and other triggers), and a Fine-Grained Authorization path sit on the same product family. Unlimited social connections are on Free. Organizations start at five on Free and ten on Essentials for B2C. Free lists one Enterprise connection, self-service SSO, and SCIM. B2C Essentials and Professional show blank cells for Enterprise connections, so a B2C team upgrading from Free to Essentials can lose SSO. B2B Essentials includes three connections.
Public plans split B2C and B2B. The Free floor is the same 25,000 MAU either way. Paid B2B starts much higher than paid B2C at the same 500 MAU rung. You get a programmable tenant and a first-class org object, and you pay Auth0's MAU ladder. At serious volume, Cognito's public rates undercut Auth0. At the Free size, Auth0's 25,000 MAU floor is larger than Cognito's.
Best for: Teams that want developer CIAM with social, Organizations, Actions, and an FGA path, and will live on Auth0's MAU plans.
Key features:
- Social login, Organizations, and Actions at login and other triggers
- Fine-Grained Authorization as a path on the same family
- Public B2C and B2B MAU plans, with a 25,000 MAU Free floor
Why we like it: Actions let you change what happens after login inside the tenant, instead of standing up a side service. Organizations are a real B2B object, not a metadata field you hope the app respects.
Notable limitations:
- Paid B2B is a different ladder from paid B2C at the same MAU count
- Extra Organizations, Enterprise SSO on the B2C paid rungs, and FGA depth still need a plan check
- High MAU volume is where AWS-native rates usually win on the public price list
Pricing: Free is $0 up to 25,000 MAU, same for B2C and B2B. Essentials from $35 per month (B2C) or $150 per month (B2B) at 500 MAU. Professional from $240 per month (B2C) or $800 per month (B2B) at 500 MAU. Enterprise is contact sales. Yearly billing is listed as 11 times the monthly price.
Amazon Cognito

Amazon Cognito is AWS-native CIAM: user pools, Managed Login / hosted UI, and social plus SAML/OIDC federation. New pools default to Essentials. Lite is the value tier (password and social, without the newer passwordless path). Essentials adds Managed Login and passwordless options with passkeys, email, or SMS. Plus adds threat protection (risk-based adaptive authentication, compromised credentials, event export) and has no free MAU floor. Identity pools that mint AWS credentials are a different, no-charge line. Do not mix that into the user-pool bill.
The 10,000 MAU free floor on Lite and Essentials (direct and social) is not the largest Free grant on this page. Auth0's 25,000 MAU, Clerk's 50,000 MRU, and Entra's 50,000 MAU all beat it. Cognito gets cheap at serious paid volume, especially Lite's tiered pennies. The bill shock comes from SMS via Amazon SNS, email via Amazon SES, Plus or Advanced Security Features, machine-to-machine tokens (no free tier), and SAML/OIDC federation after a 50 MAU free slice.
Best for: Teams already on AWS that want user pools and hosted UI, and will model SMS, federation, and Plus as separate lines.
Key features:
- User pools with Lite, Essentials (default), and Plus
- Managed Login, social IdPs, and SAML/OIDC federation
- Passkeys and other passwordless options on Essentials and Plus
Why we like it: Passkeys and Managed Login land on Essentials without a second identity vendor when AWS is already the bill. Lite still exists if you only need the older password and social path at volume rates.
Notable limitations:
- Productized B2B admin portal, orgs, and SCIM are not the Cognito story. Federation is a metered add, not a tenant console
- SMS, email, Plus, M2M, and SAML/OIDC federation sit beside the MAU rate. The 10,000 floor is not the whole invoice
- Consent and privacy tooling are thinner than dedicated CIAM suites. You will build some of that in the app
Pricing: Lite and Essentials: 10,000 MAU free per month for direct and social sign-in (indefinite, not the 12-month AWS Free Tier). Essentials example after that floor: $0.015 per MAU. Lite examples after the floor: $0.0055 then $0.0046 per MAU in the published tiers. Plus example: $0.020 per MAU with no free MAU. SAML/OIDC federation: 50 MAU free, then $0.015 per MAU. SMS via Amazon SNS and email via Amazon SES are extra.
Microsoft Entra External ID

Microsoft Entra External ID is Microsoft's next-generation CIAM for customers and business collaborators. It is not a rename of Azure AD B2C. Azure AD B2C is no longer available to purchase for new customers effective 1 May 2025. Existing B2C customers can continue. Support runs until at least May 2030, and Microsoft publishes migration guidance to External ID. External ID uses an external tenant for those customer and collaborator identities, separate from the employee workforce tenant.
Entra External ID puts Conditional Access, MFA, branded sign-up, and Microsoft 365 collaborator scenarios next to a CIAM story. ID Governance for business collaborators is an add-on path, not the core MAU floor. If the users are employees, you wanted workforce Entra ID or IGA, not this page.
Best for: Microsoft shops that need customer or collaborator CIAM in an external tenant, not another employee directory.
Key features:
- External tenant for customers, partners, and other non-employee identities
- Customizable sign-up and sign-in, MFA, and Conditional Access
- Documented succession from Azure AD B2C, with B2C support until at least May 2030
Why we like it: The external tenant keeps consumer and collaborator identities out of the workforce directory, which is the split this category actually needs.
Notable limitations:
- Microsoft's FAQ has listed $0.03 per MAU above 50,000. Confirm the current rate in the Azure price list
- SMS, machine-to-machine, Go-Local, and ID Governance are add-ons without that core free floor
- B2C customers still on P1 are in a support window, not a greenfield SKU. Azure AD B2C P2 was discontinued for all customers on 15 March 2026. New buys should quote External ID
Pricing: The Microsoft Entra External ID core offering is free for the first 50,000 MAU. Above that, the public Azure table shows a unit rate only as a signed-in list price, not a number we can reprint. Premium add-ons (including SMS phone authentication) have no free tier on that page. Confirm the overage rate in the Azure price list the day you buy.
Clerk

Clerk is turnkey authentication UI plus user management for Next.js and other modern JS apps. Prebuilt sign-up, sign-in, and user-profile components are the product, not a hosted login you restyle for a quarter. Billing is Monthly Retained Users (MRU), not MAU. A user counts only if they come back at least a day after signup (First Day Free), so a one-visit trial is not billed. Hobby is free at 50,000 MRU per app. Passkeys and MFA start on Pro. Social connections are capped at three on Hobby and unlimited on Pro.
B2B is real, with a catch on enterprise SSO. Organizations exist on every plan (100 monthly retained organizations included). Pro includes one Enterprise connection (SAML, OIDC, or EASIE) per app, then a published overage. The B2B Authentication add-on unlocks unlimited members, custom roles, and linking those Enterprise connections to organizations. A single SSO customer fits Pro; a roster of enterprise connections is a second bill line.
Best for: Next.js and modern JS startups that want prebuilt auth UI and orgs, and whose SSO demand still fits one (or a few) Enterprise connections.
Key features:
- Prebuilt sign-up, sign-in, and user-profile components, with Next.js first among frameworks
- Organizations on every plan; B2B add-on for unlimited members and custom roles
- MRU billing with First Day Free, plus one Enterprise connection on Pro
Why we like it: First Day Free means a spike of users who never return does not become an MRU line.
Notable limitations:
- Passkeys, MFA, and extra Enterprise connections are Pro (or add-on) rows, not Hobby
- Enterprise SSO beyond one connection is a published extra. A procurement-heavy B2B roster will feel that add-on cost
- Hobby social connections stop at three. Session lifetime on Hobby is fixed at seven days
Pricing: Hobby is free, 50,000 MRU per app. Pro is $25 per month ($20 on annual) plus $0.02 per MRU after 50,000. Business is $300 per month ($250 on annual). One Enterprise connection is included on Pro, then $75 per month each (volume discounts later). B2B Authentication add-on is $100 per month ($85 on annual) for unlimited members and custom roles. Enterprise is custom.
Frontegg

Frontegg is productized B2B multi-tenant identity: hosted login, an embedded admin portal, RBAC, organizations, and SSO/SCIM as objects you did not have to design. Frontegg also sells Agen.co, an agent-identity layer. This shortlist entry is the CIAM platform, not that agent product. PAYG starts free with 7,500 monthly active users, five Enterprise connections (SSO/SCIM), unlimited Organizations, a custom domain, and fully customized hosted login.
Frontegg is the B2B SaaS purchase on this list when the job is tenant admins, roles, and enterprise SSO, not a consumer social wall. What the public page does not print is a simple overage table past 7,500 MAU. Treat the calculator and sales as the rest of the bill. Enterprise is contact sales (private deployments, SLAs, HIPAA/BAA).
Best for: B2B SaaS teams that want an admin portal, RBAC, and SSO/SCIM without building a second identity app.
Key features:
- Hosted login plus an embedded self-service admin portal
- Unlimited Organizations, custom roles, and Enterprise SSO/SCIM
- Passkeys, MFA, and consent management listed on the CIAM feature set
Why we like it: Tenant admins can change roles, SSO, and users in a portal Frontegg already shipped. That is the behavior B2B teams otherwise build themselves on top of a generic user pool.
Notable limitations:
- Overage past 7,500 MAU is not a printed per-MAU rate. Model it in the calculator or on a sales call
- Agen.co is a separate agent-identity story on the same site. Quote CIAM if that is the job
- This is the wrong pick for a high-volume consumer social app with no tenant admin
Pricing: PAYG is $0 per month with 7,500 MAU, five Enterprise connections (SSO/SCIM), unlimited Organizations, custom domain, and hosted login included. Enterprise is contact sales. Confirm overage above 7,500 MAU in Frontegg's calculator; it is not a simple public table.
Ping Identity (PingOne for Customers)

PingOne for Customers is Ping's orchestrated enterprise CIAM: no-code journeys (DaVinci), authentication, user management, MFA, and consent. Essential starts with orchestration, SSO, registration, unified profile, and SCIM inbound. Plus adds adaptive MFA, FIDO2/biometrics, mobile SDK MFA, and API access management. A PingOne for Customers Passwordless package exists as its own contact-sales row. Do not treat that SKU as the Essential package.
ForgeRock combined into Ping on 23 August 2023 (Thoma Bravo). The deal closed on 23 August 2023. PingOne for Customers is still this cloud CIAM package. It is not PingOne Advanced Identity Cloud, and it is not PingOne for Workforce, the per-user employee package on the same pricing page. Quote the customer SKU by name.
Best for: Enterprises that want orchestrated customer journeys in PingOne for Customers, not a startup MAU ladder and not workforce Ping.
Key features:
- DaVinci no-code orchestration for registration, login, and preference management
- SSO, unified customer profile, SCIM inbound, OAuth, OIDC, and SAML
- Adaptive MFA and FIDO2 options on Plus; passwordless as a separate sales package
Why we like it: DaVinci lets a team change registration and login flows on a canvas instead of filing a professional-services ticket.
Notable limitations:
- Public starts are annual packages in the tens of thousands of dollars. This is not a startup Pro plan
- Passwordless is contact sales, not the Essential start. Do not mix Workforce per-user rates into this quote
- Do not flatten this SKU with PingOne Advanced Identity Cloud after the ForgeRock combination
Pricing: PingOne for Customers Essential starts at $35k annually. Plus starts at $50k annually. Passwordless is contact sales. A trial is offered. PingOne for Workforce Essential at $3 per user per month (5,000-user minimum) is a different product on the same pricing page. Do not use it here.
FusionAuth

FusionAuth is the self-hostable, portable CIAM on this shortlist. Community is free and unlimited on your own infrastructure: OAuth 2.0, OpenID Connect, SAML v2, social login, basic TOTP MFA, lambdas, and a full API. Passkeys and WebAuthn are on Community with a free license. Paid Starter adds advanced MFA, breached-password detection, and basic hosting. Essentials and Enterprise add SCIM and threat detection, plus hosting and support. Cloud is a calculator, not a single list rate.
This is the row when SaaS MAU pricing is the blocker and you will staff a cluster. It is not a hosted login you never touch. Community support is forums, Slack, and GitHub. Email and 24/7 support sit on paid plans. Cloud prices are calculator output that move with MAU and hosting. Do not treat a slider default as a universal list rate.
Best for: Teams that need CIAM they can run themselves, or a portable cloud, because a SaaS MAU ladder is the wrong bill.
Key features:
- Community self-host, free and unlimited, with OAuth, OIDC, and SAML
- Passkeys on Community with a free license; advanced MFA on Starter+; SCIM on Essentials and Enterprise
- FusionAuth Cloud with a public calculator that moves with MAU
Why we like it: You can keep the identity store in your own network and still speak the same protocols as the SaaS platforms. Passkeys are not locked behind the expensive cloud SKU.
Notable limitations:
- Self-host is a staffing decision. Community does not include paid support or the advanced security rows
- Cloud prices are calculator output. Re-run the slider at your MAU. A default view is not a flat enterprise list
- Productized B2B admin-portal depth is thinner than Frontegg. You still own more of the tenant UX
Pricing: Community self-host is free and unlimited. FusionAuth Cloud is usage-based. At a 1,000 MAU calculator default, Starter showed $162 per month billed annually; Essentials and Enterprise showed $2,970 per month (hosting included in that view). Re-run the calculator at your MAU. Passkeys on Community require the free license FusionAuth documents on that page.
CIAM platform features compared
| Platform | Signup and social | B2B orgs, SSO, SCIM | MFA, passkeys, consent |
|---|---|---|---|
| Auth0 (Okta) | Hosted plus SDKs. Unlimited social on Free | Organizations (5 Free, 10 Essentials B2C). SSO/SCIM listed on Free; confirm the paid rung | Passwordless on Free. Pro MFA on Essentials. Consent is OIDC-shaped |
| Amazon Cognito | Managed Login / hosted UI. Social IdPs on the user pool | SAML/OIDC federation is metered. No productized tenant admin portal | Passkeys on Essentials+. Fraud signals on Plus. Consent mostly in your app |
| Microsoft Entra External ID | Customizable sign-up/sign-in in an external tenant. Social IdPs supported | Collaborator access plus ID Governance as an add-on. Not a B2B SaaS admin portal | MFA and Conditional Access. Privacy add-ons billed separately |
| Clerk | Prebuilt components. 3 social on Hobby, unlimited on Pro | Orgs on every plan. 1 Enterprise connection on Pro. Directory Sync (SCIM) GA since 16 April 2026. B2B add-on for custom roles | Passkeys and MFA on Pro+. Privacy is plan/GDPR language, not a consent suite |
| Frontegg | Custom hosted login. Social listed on CIAM | Unlimited Organizations. 5 SSO/SCIM connections on PAYG. Embedded admin portal | Passkeys, MFA, and consent management on the CIAM feature set |
| Ping Identity | Orchestrated registration and SSO in DaVinci | SCIM inbound, unified profile, open-standards apps. Enterprise customer CIAM | Adaptive MFA and FIDO2 on Plus. Consent on the customer package. Passwordless is sales |
| FusionAuth | Self-hosted or cloud login. Social IdPs unlimited on Community | Tenants and RBAC on Community. SCIM on Essentials and Enterprise | Passkeys on Community (free license). Consent management in the feature matrix |
How these platforms deploy and where they fit
| Platform | Deploy | Cloud fit | How you pay |
|---|---|---|---|
| Auth0 (Okta) | SaaS (private deployment on Enterprise) | Cloud-neutral. Okta-owned product brand | Public MAU plans, B2C and B2B ladders |
| Amazon Cognito | AWS user pools. Hosted UI you brand | Already on AWS. Identity pools are a separate free AWS credential path | Public MAU tiers plus SMS, email, federation, Plus |
| Microsoft Entra External ID | Azure external tenant | Azure and Microsoft 365 fit. Not the workforce tenant | Free core MAU floor, then Azure list. Add-ons extra |
| Clerk | SaaS. Components in your JS app | Framework-first (Next.js), not a hyperscaler IAM | Public MRU plans plus SSO and B2B add-ons |
| Frontegg | SaaS. Private deployments on Enterprise | B2B SaaS apps. CIAM SKU, not the agent layer | Free PAYG floor, then calculator or Enterprise quote |
| Ping Identity | PingOne cloud. LDAP gateway if you still have one | Enterprise customer programs. Not Advanced Identity Cloud | Public annual package starts, then options |
| FusionAuth | Self-host (ZIP, Docker, Kubernetes) or FusionAuth Cloud | Portable. No AWS/Azure identity lock-in | Community free. Cloud calculator by MAU |
Strategic Decision Framework
Four questions to ask before you buy. Stay inside this shortlist.
| Critical question | Why it matters | What to evaluate | Red flag |
|---|---|---|---|
| Are the users consumers, or B2B tenant admins? | A consumer pool needs social login and consent. A multi-tenant app needs tenant admins, SSO, and SCIM. | Name who creates a tenant, who invites users, and whether SSO/SCIM is a week-one requirement. | The demo is a pretty hosted login, and orgs are a JSON field you still have to build. |
| Is AWS or Azure already the gravity well? | Cognito and Entra External ID are cheap to start inside a cloud you already operate, and expensive to leave. | If every app already sits in one cloud, quote that CIAM first. If you are multi-cloud, prefer a portable tenant. | You pick Cognito or Entra because the console is familiar, then need a B2B admin portal neither page actually sells. |
| Will you pay a SaaS MAU curve, or run the cluster? | MAU and MRU bills compound. Self-host is a staffing cost. | Model year-two MAU on the public rates. If that number is the objection, FusionAuth Community is the portable path. | The plan is “we will just self-host” with no owner for upgrades, or a Free floor treated as the forever price. |
| Do you need full CIAM, or only enterprise SSO? | Signup, session, consent, and tenant admin are a platform. An SSO checkbox is a bolt-on. | Walk a new user from sign-up through consent and, if B2B, through an admin inviting a teammate via SSO. | The RFP is CIAM, and the product you demoed is workforce SSO or a single SAML connection with no user store. |
What usually goes wrong when buying a CIAM platform
Most mismatches happen because a workforce directory is treated as customer identity, because a Free MAU floor is treated as the bill, because turnkey UI is asked to carry a full enterprise SSO roster, or because two overlapping vendors are signed before either path has failed.
| Problem | Solution |
|---|---|
| You buy workforce IAM and call it CIAM | If the users are employees, use the IGA shortlist. If they are customers or tenant admins, stay on this page. An employee tenant will not grow a consumer consent screen |
| Cognito looks free, then SMS, Plus, M2M, or federation arrive | Model SNS, SES, Plus or ASF, machine tokens, and SAML/OIDC MAUs as their own lines. The 10,000 social MAU floor is not the invoice |
| Clerk is asked to carry a roster of enterprise SSO connections | Count Enterprise connections and whether you need the B2B add-on. One connection fits Pro. A dozen customer IdPs is a different bill line, or a different platform |
| You sign two identity vendors before one has failed | Pick one platform for signup through session. Do not add a second CIAM, or a workforce suite, because the first demo lacked a single checkbox. Finish one POC |
Which CIAM platform should you pick
If AWS is already the bill and you can live without a productized B2B admin portal, start with Amazon Cognito and model SMS, Plus, and federation before you treat the 10,000 MAU floor as the price. If the shop is Azure, start with Microsoft Entra External ID in an external tenant, not a leftover Azure AD B2C purchase. If you want a programmable developer CIAM with Organizations and Actions, start with Auth0 and pick the B2C or B2B ladder on purpose. If the app is Next.js and you want components this week, start with Clerk, and count Enterprise connections before you promise every customer their own IdP.
If the product is B2B SaaS and the missing piece is an admin portal with RBAC and SSO/SCIM, start with Frontegg. If the login path is an orchestrated enterprise program, start with PingOne for Customers and quote that SKU, not workforce Ping and not Advanced Identity Cloud. If a SaaS MAU curve is the blocker and you will run a cluster, start with FusionAuth Community.


