WorkOS Blog
https://workos.com
Developer APIs / SDKs for enterprise-ready features like Single Sign-On (SSO/SAML), Passwordless Authentication, Directory Sync (SCIM), Audit Trail (SIEM), and more. Get started for free.
フィード
SCIM best practices
WorkOS Blog
User provisioning is hard, and there are many things you can get wrong if you do it in-house. We gathered some best practices on SCIM to help you with that.
6日前
Seamless onboarding with the WorkOS Admin Portal
WorkOS Blog
An often overlooked but important component of identity management is customer onboarding.
9日前
The 5 best user management software tools in 2024
WorkOS Blog
Discover the best user management software tools in 2024, their key features, and why you should consider them for your app.
10日前
Auth0 SSO: Is it worth the high cost?
WorkOS Blog
Learn what Auth0 offers, how much it costs, and why WorkOS is a better, more affordable alternative.
10日前
Auth0 vs. Cognito vs. WorkOS: Which is best in 2024?
WorkOS Blog
Auth0 vs. Cognito vs. WorkOS — how do they compare, and which one should you use? Learn everything you need to know here.
10日前
Clerk pricing: How it works and compares to WorkOS
WorkOS Blog
Explore how Clerk’s pricing stacks up against WorkOS. Understand the costs and features of each service to make an informed decision for your business.
10日前
FGA’s meaning: definition, benefits, and real-world examples
WorkOS Blog
Want to understand Fine-Grained Authorization’s (FGA) meaning? Read on to learn how it works, benefits, and real-world applications.
10日前
Clerk vs. Auth0 vs. WorkOS: which should you choose?
WorkOS Blog
Compare Clerk vs. AuthO vs. WorkOS to know which one you should use to manage identities in your app.
10日前
Frontegg vs. Auth0 vs. WorkOS: which is best in 2024?
WorkOS Blog
Frontegg vs. Auth0 vs. WorkOS: Learn their features, costs, and which is best for your needs.
10日前
Stytch vs. Auth0 vs. WorkOS: which is best?
WorkOS Blog
Compare Stytch, Auth0, and WorkOS to learn what each does, its features, and which one you should use.
10日前
November Updates
WorkOS Blog
Launch Week recap (FGA, Radar, Passkeys, Widgets, Actions, Entitlements, Next.js Starter Kit) and more
10日前
6 best user management services for 2024
WorkOS Blog
Explore the top user management services in 2024, including WorkOS, Okta, Zluri, and more.
11日前
The ultimate guide to user management in 2024
WorkOS Blog
Learn about user management, including why it’s important, the most important functions, key protocols, and more.
11日前
The 5 best Frontegg alternatives in 2024
WorkOS Blog
Discover the top five Frontegg alternatives for 2024. Compare features, pricing, and best use cases to find the perfect fit for your needs.
11日前
The 5 best Clerk alternatives in 2024
WorkOS Blog
Explore why businesses seek Clerk alternatives, featuring top options like WorkOS, Auth0, Okta, Firebase, and OneLogin.
11日前
5 best Auth0 alternatives in 2024: head-to-head
WorkOS Blog
Explore the top Auth0 alternatives in 2024: WorkOS, Cognito, Firebase, KeyCloak, and Frontegg.
11日前
4 WorkOS alternatives + which to choose
WorkOS Blog
Explore four top WorkOS alternatives: Auth0, Frontegg, Clerk, and Stytch. Compare their features, pricing, and what they are best suited for.
11日前
RBAC vs. ACL: what's the difference and how do they work together?
WorkOS Blog
Compare RBAC vs. ACL, their differences, how they work together, and which to use.
11日前
Why Google Zanzibar shines at building authorization
WorkOS Blog
Learn what makes Google Zanzibar the best authorization solution and how WorkOS FGA builds on top of these features.
12日前
Access management: What it is and how it works
WorkOS Blog
Learn what access management is, why it matters, how it works, and strategies to protect your business data effectively.
12日前
SSO best practices
WorkOS Blog
SSO is necessary if you want to sell to enterprise customers, but doing it well is hard. We gathered some best practices that can help you with that.
12日前
Failed authentication events: use cases and how-to
WorkOS Blog
Learn about the failed authentication events you can get from WorkOS and how you can use them to implement features in your app.
16日前
The complete guide to OAuth 2.0
WorkOS Blog
Learn everything you need to know about OAuth: what it is, what problem it solves, and how it works.
17日前
How to build document access control with S3, WorkOS FGA, and Lambda authorizers
WorkOS Blog
In this tutorial, paired with companion code, you’ll learn to build a secure, scalable document access control system using WorkOS FGA, AWS Lambda Authorizers, and Amazon S3.
17日前
Common SAML security vulnerabilities and how to defend against them
WorkOS Blog
Review some of the common SAML security vulnerabilities and see how you can defend against them.
18日前
How to map role data from identity providers to roles in your app
WorkOS Blog
Learn how to map groups from external identity providers to user roles in your app using SSO or SCIM.
1ヶ月前
Next.js B2B Starter Kit — fast-track your SaaS app from 0 to 1
WorkOS Blog
Every business starts with an idea, followed by the challenge of picking the right tech stack. In a crowded field where choosing the right technology is key yet time-consuming, starter kits help you focus on building your idea rather than reinventing the basics. That’s why we’re announcing the WorkOS-built Next.js B2B Starter Kit today.
1ヶ月前
Entitlements sync between Stripe and your app
WorkOS Blog
WorkOS is introducing Entitlements powered by Stripe: one-button setup for enabling immediate, subscription-based access to plans, features, and products. Entitlements are available to all AuthKit customers for free.
1ヶ月前
Widgets — ready-made components for complete enterprise features
WorkOS Blog
Widgets are ready-made components that provide complete enterprise features with a few lines of code. They are now available for free to all AuthKit customers.
1ヶ月前
Actions — customize AuthKit behavior in real-time
WorkOS Blog
We often think of auth as a binary decision—allowed or denied—but what if you want to factor in private knowledge or custom logic at runtime? Actions let you change how WorkOS behaves and customize user registration and authentication logic with AuthKit. Actions are also free to all AuthKit customers.
1ヶ月前
Fine-Grained Authorization is now generally available
WorkOS Blog
FGA is the most flexible and granular authorization system, built for product and engineering teams looking to quickly implement fine-grained permissions in their applications. Use FGA to centralize your authorization logic, implement complex authorization schemes like Google Docs-style permissions, and define precise access control that goes beyond RBAC.
1ヶ月前
Introducing Radar — real-time protection against bots, fraud, abuse
WorkOS Blog
Radar enhances AuthKit with powerful security features to protect your application from abuse, fraud, and attacks. It automatically detects authentication patterns that indicate malicious or suspicious behavior and includes six built-in preventions that can be enabled with a single click.
1ヶ月前
How to build browser-based OAuth into your CLI with WorkOS
WorkOS Blog
Ever wondered how tools like GitHub's CLI let you authenticate with a single gh auth login command? In this tutorial with companion code repo, we go through the implementation step by step.
1ヶ月前
Passkeys, a safer and simpler alternative to passwords
WorkOS Blog
Passkeys allow you to log into your account using biometrics instead of a password. They are now available for free to all AuthKit customers.
1ヶ月前
SCIM challenges: navigating the idiosyncrasies of different providers
WorkOS Blog
Every provider does SCIM differently. If you don't pay attention, the results can be catastrophic. Read about these differences, the challenges that arise from them, and how WorkOS can help you overcome them.
1ヶ月前
Understanding cross-site scripting (XSS) attacks
WorkOS Blog
XSS attacks are not to be taken lightly. Learn what XSS is, the different types of attacks, and how you can defend against them.
1ヶ月前
Best practices for CLI authentication: a technical guide
WorkOS Blog
Learn how to securely authenticate users accessing your service through a command-line tool, enabling safe, scriptable workflows across terminals, machines, and Docker containers.
1ヶ月前
How SAML certificate renewal works - and what happens when it fails
WorkOS Blog
Learn why it is important for SAML certificates to expire and how having a plan in place to handle expiration can avoid downtime.
1ヶ月前
What is SCIM? The ultimate guide
WorkOS Blog
What is SCIM, and why do you need to support it in your SaaS? We’ll discuss the SCIM standard in-depth, how it works, and how you can add SCIM support to your app.
1ヶ月前
How to add social logins in your app with WorkOS
WorkOS Blog
Learn what social logins are, how they work, and how you can integrate them into your app using WorkOS.
1ヶ月前
JWT validation: how-to and best libraries to use
WorkOS Blog
Learn about JSON Web Token (JWT) validation, why it’s important, what the best practices are, and how to do it using trusted third-party libraries.
1ヶ月前
How SCIM deprovisioning works
WorkOS Blog
Learn what is user deprovisioning, how it works with SCIM, and how you can implement it with WorkOS.
1ヶ月前
What is Universal Login and how does it work?
WorkOS Blog
Universal Login or Universal SSO streamlines user authentication to log employees into multiple apps quickly and securely. Learn how it works.
1ヶ月前
What is user provisioning?
WorkOS Blog
User provisioning simplifies onboarding, tightens security, and automates user access management.
1ヶ月前
ReBAC vs RBAC: What's the difference and which should you choose?
WorkOS Blog
RBAC associates permissions with roles, which are then assigned to users. ReBAC allows you to model complex relationships. Which is better for your use case?
1ヶ月前
Top 5 Google Zanzibar open-source implementations in 2024
WorkOS Blog
Google Zanzibar is a globally distributed authorization system that manages permissions at scale. Learn how it works and which open source implementations are right for you.
1ヶ月前
What is the Okta Integration Network?
WorkOS Blog
What is the Okta App Store or Integration Network (OIN), and should you use it?
1ヶ月前
What is an authentication token?
WorkOS Blog
Learn what authentication tokens are, the different types, and how you can generate and secure them.
1ヶ月前
How to add SSO to your app with WorkOS
WorkOS Blog
Learn why Single Sign-On (SSO) is essential, which are the best practices to follow, and how to add SSO to your app using WorkOS.
2ヶ月前
How to secure RAG applications with Fine-Grained Authorization: tutorial with code
WorkOS Blog
With RAG and GenAI applications, how can you ensure users only see results from documents they have permission to access? In this runnable tutorial, we demo using WorkOS Fine-Grained Authorization to secure your documents.
2ヶ月前
OTP bots explained: What they are and how to stop them
WorkOS Blog
Learn how OTP bots work, their role in bypassing MFA, and the top methods to protect your accounts from these cyber threats.
2ヶ月前
Model your B2B SaaS with organizations
WorkOS Blog
A guide on how to model your SaaS using organizations and WorkOS.
2ヶ月前
What is the Azure AD or Entra ID app gallery and why should you care?
WorkOS Blog
The Microsoft Entra ID app gallery is a collection of thousands of apps pre-integrated with the Microsoft Identity stack. Learn how this gallery can help, and when it's not the right choice.
2ヶ月前
The easiest way to implement SAML in any app
WorkOS Blog
Implementing SAML on your own can be a challenge. In this article, we’ll show you an easier way of adding SAML support to any app using the WorkOS SSO API.
2ヶ月前
How SCIM provisioning works - tutorial with API calls
WorkOS Blog
SCIM is a widely used protocol, but not many people understand it. This straightforward and comprehensive guide steps through how it works, using real-world examples and API calls and responses.
2ヶ月前
The Developer’s Guide to Fine-Grained Authorization
WorkOS Blog
As apps have become more complex, especially with the rise of user-generated content, the need for a more granular and scalable authorization scheme has become crucial. Unlike other models, Fine-Grained Authorization defines permissions at the resource level, providing precision and the ability to handle millions of authorization requests per second.
2ヶ月前
Auth0 pricing: how it works and compares to WorkOS
WorkOS Blog
Explore the details of Auth0's pricing, its limitations, and what makes WorkOS a more transparent and scalable alternative.
2ヶ月前
Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight
WorkOS Blog
On September 10th, 2024, a critical security flaw was disclosed in the Ruby-SAML and OmniAuth-SAML libraries, exposing a vulnerability that allows complete authentication bypass. This flaw, CVE-2024-45409, earned the highest possible score of 10 on GitHub's CVE rubric and a 9.8 NIST base score, making it a "worst-case scenario".
2ヶ月前
X.509 certificates: what they are & how to get one
WorkOS Blog
Learn what X.509 certificates are and how to generate them with our comprehensive guide. Easy-to-follow steps included.
2ヶ月前
From RBAC to Fine-Grained Authorization part II: integrate with your app
WorkOS Blog
A technical guide on how you can migrate your RBAC implementation to Fine-Grained Authorization (FGA) using WorkOS. Learn how to check a user’s access to resources, manage your FGA implementation, and favor performance vs consistency on a per request basis.
2ヶ月前
From RBAC to Fine-Grained Authorization part I: design your model
WorkOS Blog
Migrate your RBAC implementation to Fine-Grained Authorization (FGA) using WorkOS. Learn what is FGA, how to define resources, relationships, and inheritance rules, and how to test and validate the access model.
2ヶ月前
What is Enterprise SSO and why does it matter?
WorkOS Blog
Learn what enterprise SSO is, why enterprises need it, how it works, and why you should support it in your SaaS.
2ヶ月前
What is OpenID Connect (OIDC)?
WorkOS Blog
Learn what OpenID Connect (OIDC) is, how it works, why you should use it, and how to implement it using WorkOS.
2ヶ月前
September Updates
WorkOS Blog
Enterprise Ready Conference, HIPAA compliance, frontend sessions, AuthKit branding customization
3ヶ月前
What is Single Logout and why is there such limited support for it?
WorkOS Blog
Learn what single logout is, its benefits, why it's important, and why it has such limited support.
3ヶ月前
Session management for frontend apps with AuthKit
WorkOS Blog
AuthKit now supports sessions for public clients, like mobile and single-page apps. Use the WorkOS React SDK to keep your users logged in for longer while keeping them safe from attacks.
3ヶ月前
The Developer’s Guide to Auth Sessions
WorkOS Blog
Learn what sessions are and how you can implement them from scratch or using an auth provider like WorkOS.
3ヶ月前
Secure authentication for frontend apps with PKCE
WorkOS Blog
Learn what PKCE is, why it's essential for securely authenticating users in mobile and single-page apps, and how you can keep your users safe by using AuthKit and WorkOS.
3ヶ月前
What are fine-grained permissions?
WorkOS Blog
An in-depth look at fine-grained permissions, their benefits, challenges, use cases, and best practices for implementation.
3ヶ月前
OAuth vs. OAuth 2: differences + what you need to know
WorkOS Blog
Learn the most important differences between OAuth vs. OAuth 2.
3ヶ月前
The five different types of authentication
WorkOS Blog
Learn about the five major types of authentication and understand how they work.
3ヶ月前
Coarse-grained vs. fine-grained access control: which should you use?
WorkOS Blog
Compare coarse-grained vs. fine-grained access control and find out which is right for you.
3ヶ月前
What is fine-grained access control?
WorkOS Blog
Learn what Fine-Grained Access Control is and how it works.
3ヶ月前
August Updates
WorkOS Blog
Certificate renewal flow, organization switching APIs, modeling your app docs, provider icons API
4ヶ月前
What is Attribute Based Access Control (ABAC)?
WorkOS Blog
Attribute-Based Access Control (ABAC) provides a targeted, more precise way to manage who can see and use different resources and under which conditions.
4ヶ月前
Top user management features for SaaS + implementation tips
WorkOS Blog
Learn key user management features for SaaS apps like secure login, onboarding, and role management. Get implementation tips with WorkOS.
4ヶ月前
7 Attribute-Based Access Control (ABAC) examples
WorkOS Blog
Explore Attribute-Based Access Control examples across various sectors, including corporate data access, healthcare, finance, and more.
4ヶ月前
What is Authorization (AuthZ)?
WorkOS Blog
Learn what authorization is, its different patterns, and best practices.
4ヶ月前
What is granular control? Benefits + examples
WorkOS Blog
Learn what granular control is, how it works, its benefits, and some practical examples.
4ヶ月前
Managing SAML X.509 Certificates
WorkOS Blog
In this article, we’ll dive into what SAML X.509 certificates are, their role in your SAML Single Sign-On (SSO) connections, and best practices for managing these to ensure there is no downtime for your enterprise customers.
4ヶ月前
Auth Glossary
WorkOS Blog
A glossary of terms and definitions for all things related to authentication and authorization.
4ヶ月前
8 Role-Based Access Control (RBAC) examples in action
WorkOS Blog
Explore Role-Based Access Control examples across industries like corporate, healthcare, finance, education, government, e-commerce, and media.
4ヶ月前
Build vs. buy part II: ROI comparison between homegrown and pre-built solutions
WorkOS Blog
For high-growth startups, time is the single most important resource. It’s so important that months of delay in shipping SSO and SCIM can result in a potential revenue loss of $7.95M compared to using a pre-built solution. The ROI difference is staggering too: 9% for a homegrown solution vs. 1,954% for a pre-built one. This article explains the methodologies used to calculate these numbers.
4ヶ月前
What is data access control?
WorkOS Blog
Learn what data access control is, why it matters, the various types, when to implement it, and effective strategies for doing so.
4ヶ月前
The 5 best Clerk alternatives in 2024
WorkOS Blog
Explore why businesses seek Clerk alternatives, featuring top options like WorkOS, Auth0, Okta, Firebase, and OneLogin.
4ヶ月前
SCIM vs SSO: What's the difference and how do they work together?
WorkOS Blog
SCIM vs SSO: Learn the differences between SCIM and SSO and how they work together in identity and access management.
4ヶ月前
The 5 access control models: benefits + which to choose
WorkOS Blog
A breakdown of the five main types of access control models: Discretionary, Mandatory, Role-Based, Attribute-Based, and Relationship-Based access control.
4ヶ月前
How to implement access control: step by step
WorkOS Blog
Learn how to implement access control in your organization with our comprehensive guide and best practices.
4ヶ月前
Top 7 API authentication methods and how to use them
WorkOS Blog
Learn about the different API authentication methods, including how they work, their use cases, and best practices to follow.
4ヶ月前
RBAC vs IAM: what's the difference and how do they work together?
WorkOS Blog
Learn what RBAC vs IAM are and how they can be used to manage access.
4ヶ月前
What is entitlement management? A guide to secure access
WorkOS Blog
Learn all about entitlement management — what it is, how it works, its benefits, and how to implement it effectively.
4ヶ月前
RBAC vs. FGA: What's the difference and how do they work together?
WorkOS Blog
Compare FGA vs. RBAC to learn how they manage access and how they can complement each other.
4ヶ月前
The ultimate guide to OIDC providers (or building your own)
WorkOS Blog
Learn what an OIDC provider is and why you should use one, how to connect to an OIDC provider, and how to create your own OIDC provider.
4ヶ月前
What is Google Zanzibar?
WorkOS Blog
Learn what Google Zanzibar is, how to implement it, and how it compares to other authorization technologies.
4ヶ月前
July Updates
WorkOS Blog
RBAC for AuthKit, Fine-Grained Authorization early access, SCIM role assignment, updated Node SDK, and new Log Streams destination
5ヶ月前
Implementation challenges of a homegrown SCIM solution
WorkOS Blog
SCIM provisioning is an important enterprise feature that provides user lifecycle management (ULM) and automated access control. Building this in-house means you must deal with fragmentation issues across onboarding, implementation, and triage, incurring significant engineering cost, delayed time to market, and potential security issues.
5ヶ月前
Build vs buy part I: complexities of building SSO and SCIM in-house
WorkOS Blog
Time is invaluable for SaaS startups aiming to become Enterprise Ready quickly. Building complex (yet table stakes) features in-house, like SSO and SCIM, can significantly delay enterprise adoption. In part 1, we will dive into the hidden challenges you will face with a homegrown solution, highlighting just how demanding and time-consuming the process can be.
5ヶ月前
Introducing Role-Based Access Control (RBAC) for AuthKit
WorkOS Blog
AuthKit now supports RBAC as part of its core authorization capabilities. RBAC is a common authorization scheme where each user is assigned one or more roles, and each role is assigned a set of permissions that defines which resources and actions the user can access in your application.
5ヶ月前
The Developer’s Guide to RBAC and IdPs: Part II
WorkOS Blog
When building authorization for enterprise customers, supporting IdP role mapping is a challenging yet important task. This allows organizations to manage their roles and permissions through a single source of truth, the IdP, rather than dealing with unique permissions schemes for each SaaS tool.
5ヶ月前
What is RBAC? How it works and when to use it
WorkOS Blog
Learn what RBAC stands for, its key benefits, and how to implement it effectively to maintain access control.
5ヶ月前