Compare
Zitadel is a modern, passwordless-first identity platform available self-hosted (AGPL-3.0) or as a managed cloud. It is fully GA with an event-sourced audit trail and a SOC 2 / ISO-certified cloud — more mature than Qeet ID today. Choose Qeet ID for MAU-based (not DAU) billing, a permissive MIT license, an ABAC policy engine, and a tamper-evident hash-chained audit log.
Qeet ID
- License
- MIT (open source)
- Billing
- Per MAU
- Self-host
- First-class
- Runtime
- Go + Postgres
- Maturity
- Pre-GA
Zitadel
- License
- AGPL-3.0
- Billing
- Per DAU
- Self-host
- First-class
- Cloud
- SOC 2 / ISO
- Maturity
- GA (mature)
MAU billing, a permissive license, and ABAC.
Zitadel is a fully-GA, passwordless-first identity platform with a slick cloud — and honestly it is more mature than Qeet ID today. Where we differ: we bill per MAU (not DAU), ship under permissive MIT (not AGPL), and add an ABAC policy engine plus a tamper-evident audit chain.
Feature-by-feature
Verified against Qeet ID's implemented status and Zitadel's public docs. Where we're still building, we say so.
- Available
- Partial / gated
- Not offered
| Capability | Qeet ID | Zitadel |
|---|---|---|
| Authentication | ||
Passkeys / WebAuthn Zitadel is passwordless-first; passkeys are a core strength. | Yes | Yes |
Email + password | Yes | Yes |
Social login (Google, Apple, GitHub, Microsoft, …) | Yes | Yes |
MFA (TOTP, SMS, email, recovery codes) | Yes | Yes |
| Federation | ||
OAuth 2.0 / OIDC (you are the IdP) | Yes | Yes |
SAML 2.0 SP + IdP | Yes | Yes |
SCIM 2.0 provisioning Zitadel's SCIM support is limited / on its roadmap; Qeet ID ships SCIM 2.0 for users + groups. | Yes | Partial |
| Authorization | ||
RBAC + single-call /check API | Yes | Yes |
ABAC policy engine Zitadel centres on roles / grants; it has no dedicated attribute-based policy engine. | Yes | No |
Explainable authz (grant-path “why?” trace) Qeet ID returns the grant path or denial reason on every check. | Yes | No |
Multi-tenant isolation by default Both isolate tenants by default — Qeet ID via Postgres RLS, Zitadel via organizations. | Yes | Yes |
| Deployment | ||
Open-source license Qeet ID is permissive MIT; Zitadel relicensed from Apache-2.0 to AGPL-3.0 in 2025, which can carry copyleft obligations. | MIT | AGPL-3.0 |
Self-host first-class Both self-host well; Zitadel is fully GA, Qeet ID is pre-GA. | Yes | Yes |
First-party managed cloud (SaaS) | Yes | Yes |
| Pricing | ||
Billing unit Zitadel bills by daily active users (DAU); Qeet ID bills by monthly active users (MAU), which is easier to forecast for most apps. | Per MAU | Per DAU |
Free tier | 25,000 MAU | 100 DAU |
Paid entry plan | $25/mo, 50k MAU incl. | $100/mo, 25k DAU incl. |
No per-connection SSO fee Neither charges an 'SSO tax' — enterprise SSO is included on all tiers. | Yes | Yes |
| Security & audit | ||
Tamper-evident hash-chained audit log + /verify Zitadel keeps a rich event-sourced audit trail, but there is no hash-chain integrity endpoint to prove no row was altered. | Yes | Partial |
Full event-sourced audit trail Event sourcing is Zitadel's core architecture; Qeet ID stores an append-only hash-chained log rather than a full event store. | Partial | Yes |
| Compliance | ||
GDPR erasure / data export | Yes | Yes |
Managed-cloud SOC 2 Type II / ISO 27001 Zitadel's cloud carries SOC 2 / ISO certifications; Qeet ID's managed cloud is completing its audits before GA. | Roadmap (pre-GA) | Yes |
| Developer experience | ||
First-party typed SDKs Both ship first-party SDKs across popular languages. | React · Node · Go | Yes |
Native admin dashboard | Yes | Yes |
Comparison is based on publicly-available product information at the time of writing. We do our best to be accurate — if anything above is wrong, please let us know and we'll correct it.
Migrate from Zitadel
Try MAU-priced, MIT-licensed identity
Start free up to 25,000 MAU, or self-host the MIT core. If Zitadel's DAU model and AGPL license already work for you, that is a fine choice too.