6
Security
Build vs buy for authentication in a B2B SaaS
Control ↔ Time-to-market
Context
Enterprise customers are asking for SSO (SAML/OIDC) and SCIM.
We have homegrown email/password auth. Enterprise prospects require SAML SSO, SCIM provisioning and audit logs. I'm the only security engineer.
Buying gets us there in weeks but per-MAU pricing scares finance. Building means owning SAML parsing — historically a minefield of signature-wrapping bugs.
Constraints
- Team
- 1 security engineer
- Deadline
- Q3 enterprise deal
Build in-housevsBuy (Auth0 / Clerk / WorkOS)
Community verdict
Build in-house 30%Buy (Auth0 / Clerk / WorkOS) 70%
10 engineers · 3 opinions
With these constraints, what would you choose?
One choice per engineer. You can change it any time.
Build in-house
Buy (Auth0 / Clerk / WorkOS)
Time-to-market →
Trade-offs
Dimensions
Build in-houseBuy (Auth0 / Clerk / WorkOS)out of 5
- Control
- 5Build in-house scores 5 of 52Buy (Auth0 / Clerk / WorkOS) scores 2 of 5
- Time-to-market
- 1Build in-house scores 1 of 55Buy (Auth0 / Clerk / WorkOS) scores 5 of 5
- Cost at scale
- 4
Community discussion
3 comments
Have you made this decision in production? Share your reasoning.
Sign in to commentSAML is where I draw the line. XML signature validation has produced critical CVEs in mature libraries. Buy the enterprise-SSO piece; you can keep your own session handling.
Keycloak is the third option: self-hosted, SAML and SCIM supported, no per-user fees. You pay in operations instead of licence fees.
Negotiate pricing per organisation rather than per MAU — most B2B auth vendors will do it. Enterprise SSO is usually what closes the deal anyway, so the cost is easy to justify.