Compare
WorkOS sells enterprise-readiness APIs — SSO, SCIM, Audit Logs, Directory Sync — that you bolt onto your own user store. Qeet ID is the user store too: identity, RBAC, MFA, sessions, admin UI, plus the same enterprise APIs in one binary.
Qeet ID
- License
- MIT (open source)
- What it ships
- Full IdP + admin
- User store
- Yes (Postgres)
- Self-host
- First-class
- Pricing
- Linear per-MAU
WorkOS
- License
- Proprietary SaaS
- What it ships
- Enterprise APIs only
- User store
- Bring your own
- Self-host
- Not available
- Pricing
- Per-connection + per-event
WorkOS is half the system. Qeet ID is the whole one.
If you already have a user database and just need SSO + SCIM, WorkOS is great. If you're building from scratch — or want to consolidate — Qeet ID gives you the user store, MFA, sessions, admin UI, and the enterprise APIs in a single Postgres-backed service.
Feature-by-feature
Verified against Qeet ID's implemented status and WorkOS's public docs. Where we're still building, we say so.
- Available
- Partial / gated
- Not offered
| Capability | Qeet ID | WorkOS |
|---|---|---|
| What you get | ||
User store (users, sessions, passwords) WorkOS doesn't store users — you bring your own DB. | Yes | No |
Built-in MFA (TOTP, SMS, email, recovery) | Yes | No |
Hosted admin dashboard | Yes | AdminPortal (per-customer) |
RBAC permissions engine | Yes | No |
| Federation | ||
SAML 2.0 SSO | Yes | Yes |
OIDC SSO | Yes | Yes |
SCIM 2.0 (Users + Groups) | Yes | Yes |
SAML 2.0 IdP (be an SSO source) Qeet ID is both a SAML SP and a SAML IdP; WorkOS focuses on consuming customer IdPs. | Yes | Partial |
LDAP / AD federation | Yes | Yes |
Hosted Directory Sync connectors (Google, Okta, Entra) Qeet ID consumes SCIM today; turnkey directory-sync connectors are on the roadmap. | Partial | Yes |
Magic links | Yes | Yes |
| Auth methods | ||
Email + password | Yes | via AuthKit |
Passkeys / WebAuthn | Yes | via AuthKit |
Social login | Yes | via AuthKit |
| Compliance | ||
Audit logs (search, export) | Yes | Yes |
Tamper-evident audit chain (SHA-256) + /verify Qeet ID chains every audit row by hash; tampering breaks the chain, and /verify proves it. | Yes | Partial |
SOC 2 Type II | Roadmap (pre-GA) | Yes |
Self-hosted = your compliance boundary | Yes | No |
| Deployment | ||
Self-host (single binary + Postgres) | Yes | No |
Bring-your-own database | Yes | No |
Air-gapped / on-prem | Yes | No |
| Pricing | ||
Free tier | 25,000 MAU | 1 million events / month |
B2B SSO included | Yes | Per-connection pricing |
SCIM included | Yes | Per-connection pricing |
Audit-log export | Yes | Paid tier |
Comparison is based on publicly-available product information at the time of writing. We do our best to be accurate — if anything above is wrong, please let us know and we'll correct it.
Migrate from WorkOS
One binary, one bill, one identity stack
Replace your user store, MFA library, session manager, and enterprise-SSO bolt-on with Qeet ID. Or keep what you have and migrate gradually.