Aeion Auth Pricing — Identity Without the Per-MAU Tax
No per-connection fee. No per-MAU charge. No feature gate hiding MFA or SSO behind an upcharge. Aeion Auth is a platform service, included free with every Aeion module: 10 OAuth providers, MFA (TOTP + WebAuthn), magic links, RBAC, scoped API keys, immutable audit logs, SAML 2.0 SSO, and SCIM 2.0 directory sync all ship at no extra cost.
What's Included — Everything, No Tiers
Aeion Auth doesn't have its own pricing tiers. It's platform plumbing — like billing, files, or notifications — bundled free with every module you run. There's no Free/Professional/Enterprise ladder to climb for auth specifically; you pay for the business modules you need (commerce, CRM, helpdesk, etc.), and identity comes with all of it:
What You Actually Pay — Worked Example
A B2B SaaS with 50 customer-tenants, each on SSO + MFA + magic links + API keys, with one team admin per customer auditing logs monthly.
How Pricing Decisions Get Made
Aeion isn't a third-party billing line item bolted onto your app. It's the operating system. You pay for the vertical business modules you use (commerce, CRM, helpdesk, and so on); the platform-plumbing services that every module depends on — auth, billing, files, notifications, search — are included free. Per-MAU pricing for auth primitives (which cost ~$0 in actual compute) would just be a tax on growth.
Pricing FAQ
Yes. Auth is a platform service, included at no charge with every Aeion module — not a paid add-on, not a metered line item. All 10 OAuth providers, MFA, magic links, SAML 2.0 SSO, SCIM 2.0 directory sync, unlimited scoped API keys, and RBAC ship the moment you activate any module.
No. Every deployment ships all 10 OAuth providers plus the generic OIDC provider (which connects to Okta / Auth0 / Ping / OneLogin / JumpCloud / any OIDC-compatible IdP), with unlimited custom OIDC IdP registrations.
No. TOTP + WebAuthn (FIDO2 hardware keys) are included free. There is no per-device or per-enrollment fee.
All login history entries land in your tenant database. There's no volume cap — only a retention window, which defaults to 90 days. Aeion doesn't gate audit-event volume because the storage cost lives on your VPS / cloud, not Aeion's.
Yes. Aeion tracks where each connection migrated from, so you can audit the cutover after the fact. Plan ~1-2 sprints for test SSO + dual-run validation before cutover.
Yes — both are included free, no extra charge. Connect your IdP, map attributes, and SCIM keeps the user list in sync (auto-provision on join, auto-revoke on offboard). PIV/CAC smart-card sign-in is available for federal / defense deployments.
Your data stays in your tenant database. Use Aegis to take a final snapshot. All identity data (OAuth connections, MFA configs, login history, API keys, etc.) is in YOUR tenant database — there's nothing held in Aeion's central infrastructure to migrate out.