HN user

mffap

454 karma

working at https://github.com/zitadel

Posts42
Comments47
View on HN
github.com 1y ago

Zitadel's new login built with TypeScript

mffap
1pts0
github.com 1y ago

Zitadel Supports SCIM

mffap
4pts0
www.youtube.com 2y ago

Complete guide to identity federation with Google IDP [video]

mffap
2pts0
thenewstack.io 2y ago

Transforming Identity and Access Management with Event Sourcing

mffap
4pts1
github.com 2y ago

Password Hashing Package for Go

mffap
15pts2
github.com 2y ago

Authenticate with PHP Symfony Through OIDC

mffap
9pts0
github.com 2y ago

Zitadel SDK and Client in Go

mffap
1pts0
github.com 2y ago

B2B identity infrastructure written in Go

mffap
1pts0
github.com 2y ago

Unified Go package for password hashing and swapping

mffap
4pts0
github.com 2y ago

Easy to use OpenID Connect client and server library written for Go

mffap
165pts44
github.com 2y ago

Zitadel v2.33.0 – SMS/Email OTP and Custom SAML Attributes

mffap
4pts0
github.com 3y ago

Zitadel v2.20.0 Release Notes

mffap
1pts0
zitadel.com 3y ago

Full stack ZITADEL integration with NextJS

mffap
5pts0
zitadel.com 3y ago

Is public WiFi as dangerous as people claim?

mffap
15pts4
github.com 3y ago

Zitadel v2.5.0 – SAML 2.0 Support

mffap
6pts0
zitadel.com 3y ago

Use OIDC authorize request to customize user login

mffap
3pts0
github.com 3y ago

Zitadel v2.3.0 – PostgreSQL Support

mffap
5pts0
zitadel.com 3y ago

Is Zero Trust worth the hype?

mffap
8pts1
zitadel.com 3y ago

Pay-as-you-go all the way with ZITADEL Cloud

mffap
2pts0
zitadel.com 4y ago

Children online are not safe anymore

mffap
7pts0
zitadel.com 4y ago

Are Magic Links Outdated?

mffap
135pts224
news.ycombinator.com 4y ago

Zitadel V2 Beta Out

mffap
5pts2
zitadel.com 4y ago

DNSSEC Adoption

mffap
1pts0
zitadel.com 4y ago

IMO – DNSSEC

mffap
7pts0
zitadel.com 4y ago

It's Time to Ditch Passwords

mffap
6pts0
github.com 4y ago

Zitadel: The best of Auth0 and Keycloak combined

mffap
100pts59
zitadel.ch 4y ago

Smishing

mffap
45pts31
zitadel.ch 4y ago

What makes ZITADEL a great Keycloak alternative

mffap
6pts0
zitadel.ch 4y ago

Why ZITADEL is a great Auth0 alternative

mffap
7pts0
zitadel.ch 4y ago

SaaS or self-hosted for identity management?

mffap
5pts0

It's probably going to be vendor-specific or you will implement your own auth. At ZITADEL we decided to offer all the standards like OIDC and SAML, and offer a session API for more flexible auth scenarios. You will also be able to mix.

[dead] 2 years ago

Hi HN, we're thrilled to announce that Zitadel just raised $9M in Series A funding! This will help us make Zitadel, our open source identity platform, even better for developers to build secure applications.

Zitadel simplifies user management, authentication, and authorization with built-in multi-tenancy, making it easy to manage users across different customers, departments, or organizations. This way, you can focus on what matters most: creating amazing products. We're also working on exciting new features like user activity monitoring, which will allow you to easily audit user behavior, build custom reports, and enhance security with tools to detect and react to threats.

We believe everyone deserves access to simple and secure identity solutions. Check out Zitadel and let us know what you think!

ZITADEL would be a good choice if you have multiple tenants and want delegate things like access management and configuring auth per tenant in self-service - that part comes out of the box with ZITADEL and could save you quite some development. I wanted to throw that in, because for the authentication part most solutions would match your requirements, but keep also authorization and auditability in mind.

That being said with ZITADEL you can also move between self-hosted and cloud: https://zitadel.com/docs/guides/migrate/sources/zitadel

ps: I'm biased (see bio).

All of these features are included. Main drivers for pricing in this case, I assume will be daily active users (sum over the month) and how many third-party identity providers you have configured. Unlimited tenants, users, permissions etc. are included. We use DAU instead of MAU, since there are many different use cases and that seems work quite well. Just take the MAU and multiply by how many times per month your users will sign-in. In the enterprise tier we offer more custom quotes for higher volumes, guarantee requirements, and support SLAs.

Have a look at ZITADEL (https://github.com/zitadel/zitadel or https://zitadel.com/), I think that does what you want. You can create multiple tenants (called Organizations) and you can setup security / login rules per organization such as enforcing MFA. Furthermore you can configure on each tenant a separate SSO and users are directly forwarded to their identity provider. When you first enter your username (could be an email) on the login screen, the policies of the user's organization will be applied. That allows you to route users based on their email domain etc. One additional thing to mention is that ZITADEL does not only handle authentication, but also authorization with self-service. Managers of an organization can, for example, assign users of their organization roles.

For RBAC, I see two main challenges. You need to make sure that you get all the roles for all client applications for a user to make a decision. That becomes a bit more complex if you go into scenarios where each tenant can also manage their own clients and roles. Secondly, complexity comes from the self-service to assign roles, ie. delegating access management to the tenants. You need to allow certain users to assign the roles to users in their organization, or in general manage their users. That authorization model has to be applied to the whole system, including APIs obviously.

Most solution solve the authentication part, so login with a local user or federated users via identity brokering (eg, OIDC/SAML via EntraID). The main selling point of ZITADEL is that it also solves the authorization, as mentioned above, across multiple tenants as well as the self-service aspect of delegating configuration of security policies and user management to "Managers" in the tenants. You get that out of the box, no development needed. You can read more here: https://zitadel.com/blog/multi-tenancy-with-organizations Also, you can self-host ZITADEL which is not available for all solutions, but is quite a selling point when talking to enterprise customers.

I think the b2b niche was already mentioned in this thread. But I don't think it is underserved, as many vendors jump onto that. Healthcare and Manufacturing are two sectors that are hard to crack with IAM for their special requirements. The tools I've seen are working but very expensive and customized. Yet also the two sectors are very traditional (read: on-prem AD) and need a lot of work if they want to move to more federated IAM systems.

One of the challenges we see is providing self-service for team management. That includes letting an admin assign roles to their users, manage user lifecycle (eg through sso), and setting up security policies. For sure you can build the basics, but it becomes complex later on if you manage a lot of tenants or or more enterprise customers. For Auth only there are many solutions out there that work great. There's only a few solutions with multi-tenancy at the core, though, like https://github.com/zitadel/zitadel

Is Germany funding the oss projects as well? Traditionally they have this mindset of free open source software, with a strong emphasis on free, while not factoring in the cost of maintaining a project. When the usage gets higher there should be a plan for sustainable progress and maintenance.

That's basically what it does. You can activate Domain Discovery and verify a Domain on an organization, with that zitadel routes users to the organization based on the suffix (ie. email domain)

Thanks for mentioning ZITADEL. Co-founder here. Supertokens is a good solution with obviously a lot of open source traction, which is great to see in this space. Expanding to authorization makes a lot of sense. ZITADEL supports both authentication and authorization in a turnkey solution (AuthN, AuthZ, APIs, UI, DB). Looking at Supertoken's roadmap, Zitadel seems to be more feature rich offering Passkeys, OTP, multi-tenancy, account linking and a management ui.

Unfortunately, very valid point. Love the example btw :)

Browsers have been getting better at warning users. Which is actually a great help, I think. But no guarantee at all, especially for less tech-savvy users.

[dead] 4 years ago

Hey HN

happy to share with you that we've now officially released v2.0 of ZITADEL. Integrate user management and authentication easy as pie.

Check out the TL;DR in the release notes on what's changed.

We also launched on ZITADEL on ProductHunt. Share with us what you like best about the project, what's the one thing you would improve, or what you want to see next!

Happy to answer any questions. Cheers.

Yes. To my knowledge WebAuthN works great on Chrome, Safari, Firefox (most times) on MacOS/iOS and Windows devices. Linux is still an issue unfortunately as it seems.