Compare

Qeet IDvs. Zitadel

Zitadel is a modern, passwordless-first identity platform available self-hosted (AGPL-3.0) or as a managed cloud. It is fully GA with an event-sourced audit trail and a SOC 2 / ISO-certified cloud — more mature than Qeet ID today. Choose Qeet ID for MAU-based (not DAU) billing, a permissive MIT license, an ABAC policy engine, and a tamper-evident hash-chained audit log.

Qeet ID

License
MIT (open source)
Billing
Per MAU
Self-host
First-class
Runtime
Go + Postgres
Maturity
Pre-GA

Zitadel

License
AGPL-3.0
Billing
Per DAU
Self-host
First-class
Cloud
SOC 2 / ISO
Maturity
GA (mature)

MAU billing, a permissive license, and ABAC.

Zitadel is a fully-GA, passwordless-first identity platform with a slick cloud — and honestly it is more mature than Qeet ID today. Where we differ: we bill per MAU (not DAU), ship under permissive MIT (not AGPL), and add an ABAC policy engine plus a tamper-evident audit chain.

Per-MAU pricing that is easier to forecast than Zitadel's per-DAU model.
Permissive MIT license — no AGPL copyleft to reason about.
ABAC + explainable authz and a hash-chained /verify audit endpoint.

Feature-by-feature

Verified against Qeet ID's implemented status and Zitadel's public docs. Where we're still building, we say so.

  • Available
  • Partial / gated
  • Not offered
Feature comparison between Qeet ID and Zitadel
CapabilityQeet IDZitadel
Authentication
Passkeys / WebAuthn
Zitadel is passwordless-first; passkeys are a core strength.
YesYes
Email + password
YesYes
Social login (Google, Apple, GitHub, Microsoft, …)
YesYes
MFA (TOTP, SMS, email, recovery codes)
YesYes
Federation
OAuth 2.0 / OIDC (you are the IdP)
YesYes
SAML 2.0 SP + IdP
YesYes
SCIM 2.0 provisioning
Zitadel's SCIM support is limited / on its roadmap; Qeet ID ships SCIM 2.0 for users + groups.
YesPartial
Authorization
RBAC + single-call /check API
YesYes
ABAC policy engine
Zitadel centres on roles / grants; it has no dedicated attribute-based policy engine.
YesNo
Explainable authz (grant-path “why?” trace)
Qeet ID returns the grant path or denial reason on every check.
YesNo
Multi-tenant isolation by default
Both isolate tenants by default — Qeet ID via Postgres RLS, Zitadel via organizations.
YesYes
Deployment
Open-source license
Qeet ID is permissive MIT; Zitadel relicensed from Apache-2.0 to AGPL-3.0 in 2025, which can carry copyleft obligations.
MITAGPL-3.0
Self-host first-class
Both self-host well; Zitadel is fully GA, Qeet ID is pre-GA.
YesYes
First-party managed cloud (SaaS)
YesYes
Pricing
Billing unit
Zitadel bills by daily active users (DAU); Qeet ID bills by monthly active users (MAU), which is easier to forecast for most apps.
Per MAUPer DAU
Free tier
25,000 MAU100 DAU
Paid entry plan
$25/mo, 50k MAU incl.$100/mo, 25k DAU incl.
No per-connection SSO fee
Neither charges an 'SSO tax' — enterprise SSO is included on all tiers.
YesYes
Security & audit
Tamper-evident hash-chained audit log + /verify
Zitadel keeps a rich event-sourced audit trail, but there is no hash-chain integrity endpoint to prove no row was altered.
YesPartial
Full event-sourced audit trail
Event sourcing is Zitadel's core architecture; Qeet ID stores an append-only hash-chained log rather than a full event store.
PartialYes
Compliance
GDPR erasure / data export
YesYes
Managed-cloud SOC 2 Type II / ISO 27001
Zitadel's cloud carries SOC 2 / ISO certifications; Qeet ID's managed cloud is completing its audits before GA.
Roadmap (pre-GA)Yes
Developer experience
First-party typed SDKs
Both ship first-party SDKs across popular languages.
React · Node · GoYes
Native admin dashboard
YesYes

Comparison is based on publicly-available product information at the time of writing. We do our best to be accurate — if anything above is wrong, please let us know and we'll correct it.

Migrate from Zitadel

Try MAU-priced, MIT-licensed identity

Start free up to 25,000 MAU, or self-host the MIT core. If Zitadel's DAU model and AGPL license already work for you, that is a fine choice too.