Compare
AWS Cognito is Amazon's managed identity service — tightly integrated with the AWS ecosystem and proven at massive scale. Choose Qeet ID when you want open-source code, deployment outside AWS, a dedicated admin UI, and a first-class authorization engine.
Qeet ID
- License
- MIT (open source)
- Self-host
- First-class
- Pricing
- Linear per-MAU
- Stack
- Go + Postgres
- Data residency
- EU / US / self
AWS Cognito
- License
- Proprietary (AWS)
- Self-host
- Not available
- Pricing
- Per-MAU (Essentials)
- Stack
- Managed (AWS)
- Data residency
- AWS regions
The same standards, without the AWS lock-in.
Cognito is a solid choice if you already live in AWS. Qeet ID gives you the same OIDC / SAML core as open-source code you can run anywhere — plus a real admin UI and a proper authorization engine.
Feature-by-feature
Verified against Qeet ID's implemented status and AWS Cognito's public docs. Where we're still building, we say so.
- Available
- Partial / gated
- Not offered
| Capability | Qeet ID | AWS Cognito |
|---|---|---|
| Authentication | ||
Passkeys / WebAuthn Cognito added passkeys in its 2024–25 Essentials update. | Yes | Yes |
Magic links Cognito ships email / SMS OTP passwordless; magic links need a custom auth flow. | Yes | No |
MFA (TOTP, SMS) | Yes | Yes |
| Federation | ||
OAuth 2.0 / OIDC (you are the IdP) | Yes | Yes |
SAML 2.0 SP + IdP Cognito federates to external SAML IdPs (acts as SP) but is not itself a SAML IdP. | Yes | Partial |
SCIM 2.0 provisioning Cognito is not a SCIM provisioning IdP. | Yes | No |
| Authorization | ||
RBAC + single-call /check API Cognito groups give coarse roles; there is no dedicated authorization /check API. | Yes | Partial |
ABAC policy engine Cognito's ABAC targets AWS resource access, not a general policy engine. | Yes | Partial |
Explainable authz (grant-path “why?” trace) | Yes | No |
Multi-tenant isolation by default | Yes | Separate user pools |
| Deployment | ||
Open-source code (MIT) | Yes | No |
Self-host (single binary + Postgres) Cognito is AWS-only; there is no self-hosted option. | Yes | No |
Air-gapped / fully offline | Yes | No |
| Pricing | ||
Free tier MAU cap User pools created before Nov 2024 keep the legacy 50,000 free MAU. | 25,000 | 10,000 (Essentials) |
Per-MAU pricing Cognito's legacy Lite tier is cheaper at scale (roughly $0.0046–$0.0055/MAU). | $0.02 / MAU (Pro) | $0.015 / MAU (Essentials) |
SSO / federated sign-in included Cognito bills federated SAML / OIDC sign-in at $0.015/MAU. | Yes | Partial |
| Security & audit | ||
Tamper-evident hash-chained audit log + /verify Cognito events reach CloudTrail but are not hash-chained or independently verifiable. | Yes | Partial |
Breached-password rejection (HIBP) Offered through Cognito's paid advanced-security (Plus) tier. | Yes | Partial |
Adaptive / risk-based MFA + bot detection Cognito's Plus tier ships adaptive auth; Qeet ID's is planned. | Roadmap | Yes |
| Compliance | ||
SOC 2 Type II / ISO 27001 AWS carries broad, mature compliance attestations. | Roadmap (pre-GA) | Yes |
Self-hosted = your compliance boundary | Yes | No |
| Developer experience | ||
Native admin dashboard AWS console only — no dedicated end-user identity admin UI. | Yes | Partial |
Webhook events with HMAC + retries Cognito uses Lambda triggers rather than signed HTTP webhooks. | Yes | Partial |
First-party SDKs | React · Node · Go | AWS Amplify + broad SDKs |
Comparison is based on publicly-available product information at the time of writing. We do our best to be accurate — if anything above is wrong, please let us know and we'll correct it.
Migrate from AWS Cognito
Own your identity layer, on any cloud
Start free on our hosted plan, or run the Qeet ID binary on your own infrastructure — including air-gapped.