Authentication for startups
In short
Use a standards-based OAuth 2.0 provider with no per-user meter, so sign-in does not become a line item that scales faster than revenue.
- Standard OAuth 2.0 and OpenID Connect means you can move later without rewriting clients.
- No monthly-active-user meter, so a traffic spike is not a bill.
- No user directory to hold, secure, back up or breach.
The flow: Authorization Code with PKCE
- 1
Skip building sign-up entirely
Registration, password reset, email verification and account recovery are four features you do not have to write, test or support.
- 2
Register the app and wire one flow
One client ID, one redirect URI per environment, one Authorization Code flow with PKCE. Most integrations are an afternoon.
Full detail in the docs - 3
Keep the scope list short
Ask for what your product reads today. Adding a scope later is a smaller conversation than explaining one you never used.
Full detail in the docs - 4
Turn MFA on before you have users to migrate
Account security is cheap to adopt early and awkward to retrofit once there is a user base with habits.
Common mistakes
- Choosing on the free tier alone. Check what the tier above costs before you need it.
- Rolling your own password storage to save money. It is the single highest-consequence code in the product.
- Picking a provider whose tokens only its own SDKs understand.
Quickstart
Open the guide