Compare

Qeet IDvs. AWS Cognito

AWS Cognito is Amazon's managed identity service — tightly integrated with the AWS ecosystem and proven at massive scale. Choose Qeet ID when you want open-source code, deployment outside AWS, a dedicated admin UI, and a first-class authorization engine.

Qeet ID

License
MIT (open source)
Self-host
First-class
Pricing
Linear per-MAU
Stack
Go + Postgres
Data residency
EU / US / self

AWS Cognito

License
Proprietary (AWS)
Self-host
Not available
Pricing
Per-MAU (Essentials)
Stack
Managed (AWS)
Data residency
AWS regions

The same standards, without the AWS lock-in.

Cognito is a solid choice if you already live in AWS. Qeet ID gives you the same OIDC / SAML core as open-source code you can run anywhere — plus a real admin UI and a proper authorization engine.

MIT-licensed core you can self-host on any infrastructure — not just AWS.
A dedicated identity admin UI, not the AWS console.
Built-in RBAC + ABAC with a single-call /check and explainable grant paths.

Feature-by-feature

Verified against Qeet ID's implemented status and AWS Cognito's public docs. Where we're still building, we say so.

  • Available
  • Partial / gated
  • Not offered
Feature comparison between Qeet ID and AWS Cognito
CapabilityQeet IDAWS Cognito
Authentication
Passkeys / WebAuthn
Cognito added passkeys in its 2024–25 Essentials update.
YesYes
Magic links
Cognito ships email / SMS OTP passwordless; magic links need a custom auth flow.
YesNo
MFA (TOTP, SMS)
YesYes
Federation
OAuth 2.0 / OIDC (you are the IdP)
YesYes
SAML 2.0 SP + IdP
Cognito federates to external SAML IdPs (acts as SP) but is not itself a SAML IdP.
YesPartial
SCIM 2.0 provisioning
Cognito is not a SCIM provisioning IdP.
YesNo
Authorization
RBAC + single-call /check API
Cognito groups give coarse roles; there is no dedicated authorization /check API.
YesPartial
ABAC policy engine
Cognito's ABAC targets AWS resource access, not a general policy engine.
YesPartial
Explainable authz (grant-path “why?” trace)
YesNo
Multi-tenant isolation by default
YesSeparate user pools
Deployment
Open-source code (MIT)
YesNo
Self-host (single binary + Postgres)
Cognito is AWS-only; there is no self-hosted option.
YesNo
Air-gapped / fully offline
YesNo
Pricing
Free tier MAU cap
User pools created before Nov 2024 keep the legacy 50,000 free MAU.
25,00010,000 (Essentials)
Per-MAU pricing
Cognito's legacy Lite tier is cheaper at scale (roughly $0.0046–$0.0055/MAU).
$0.02 / MAU (Pro)$0.015 / MAU (Essentials)
SSO / federated sign-in included
Cognito bills federated SAML / OIDC sign-in at $0.015/MAU.
YesPartial
Security & audit
Tamper-evident hash-chained audit log + /verify
Cognito events reach CloudTrail but are not hash-chained or independently verifiable.
YesPartial
Breached-password rejection (HIBP)
Offered through Cognito's paid advanced-security (Plus) tier.
YesPartial
Adaptive / risk-based MFA + bot detection
Cognito's Plus tier ships adaptive auth; Qeet ID's is planned.
RoadmapYes
Compliance
SOC 2 Type II / ISO 27001
AWS carries broad, mature compliance attestations.
Roadmap (pre-GA)Yes
Self-hosted = your compliance boundary
YesNo
Developer experience
Native admin dashboard
AWS console only — no dedicated end-user identity admin UI.
YesPartial
Webhook events with HMAC + retries
Cognito uses Lambda triggers rather than signed HTTP webhooks.
YesPartial
First-party SDKs
React · Node · GoAWS Amplify + broad SDKs

Comparison is based on publicly-available product information at the time of writing. We do our best to be accurate — if anything above is wrong, please let us know and we'll correct it.

Migrate from AWS Cognito

Own your identity layer, on any cloud

Start free on our hosted plan, or run the Qeet ID binary on your own infrastructure — including air-gapped.