Okta Customer Identity and Auth0 licensing covers the two platforms Okta sells for identities that are not the customer’s own workforce: consumers, business customers, partners and other external users. Okta Customer Identity runs on the Okta platform and is bought in Monthly Active Users per Year (MAU per Year).[1] Auth0 is a separate platform with its own SKUs, bought in Monthly Active Users per calendar month and per tenant.[2] Both are governed by the Okta Master Subscription Agreement. Auth0 self-service plans are also governed by an amending Product Specific Schedule.[5] Workforce users of Okta are covered in Okta Workforce Identity licensing.
Editions
Okta Customer Identity
All Okta Customer Identity solutions “start with the Enterprise base platform”. The pricing page lists it from USD 3,000 per month, with unlimited OIDC and outbound SAML apps, Okta APIs and enterprise SLAs.[3] The PSRG states that “a customer must always subscribe to the base Enterprise SKU”.[1] A Core Enterprise Platform SKU exists as well. It includes one default custom authorization server limited to 100,000 NHI Authentication Tokens per subscription year.[1]
| Offering | Contents |
|---|---|
| Enterprise base platform | Required base; multiple production applications with unlimited OIDC clients and custom SAML apps[1] |
| B2C Suite | Enterprise, Customer Identity Workflows (50, 150 or Maximum flows), MFA or Adaptive MFA, Single Sign-On with Unlimited OIN Apps[1] |
| B2B Suite | B2C components plus Inbound Federation, Access Governance and Lifecycle Management (5 or Unlimited OIN Apps)[1] |
| Add-ons | Identity Threat Protection, Lifecycle Management, Identity Governance, MFA, Adaptive MFA, SSO Integrations, Access Gateway, API Access Management, API AM M2M, Directory Integrations, Inbound Federation, Workflows, DynamicScale[3] |
Like the workforce suites, the Customer Identity Suites are “currently only available to new Customers” and must be bought as a complete Suite.[1]
Auth0
Auth0 has self-service plans and enterprise SKUs. In the B2C view, the self-service price page lists Free (USD 0, up to 25,000 monthly active users), Essentials (from USD 35 per month) and Professional (from USD 240 per month), both priced from 500 monthly active users. An Enterprise plan is available on request.[4] On an enterprise Order Form, a customer must subscribe either to a Primary Auth SKU (Enterprise Basic, Enterprise or Enterprise Premium) or to a Growth SKU (B2C Essentials, B2C Professional, B2B Essentials or B2B Professional).[2]
| Auth0 SKU | Enterprise connections | Actions + Forms | Tenants |
|---|---|---|---|
| Enterprise Basic | None | 30 | Not limited in the guide |
| Enterprise | Up to 5 | 30 | Not limited in the guide |
| Enterprise Premium | Unlimited (subject to system limitations) | 30 | Not limited in the guide |
| B2C Essentials / B2B Essentials | None / up to 3 | 10 | 3 |
| B2C Professional / B2B Professional | None / up to 5 | 15 | 6 |
All figures in the table come from the Auth0 PSRG.[2] Growth SKUs “are only compatible with limited add-ons” and have further limits shown in the Auth0 dashboard.[2] Catalog: Auth0 Growth SKUs limit the number of tenants.
Metrics
MAU per Year (Okta Customer Identity). A Monthly Active User “shall be calculated as when a User authenticates with or is authorized by the Service”. Repeat sign-ins in one subscription month count once. MAU per Year is the sum of the monthly MAUs over the subscription year.[1] The pricing page uses the same monthly definition.[3] Catalog: MAU per Year; MAU per Year sums monthly active users over the subscription year.
MAU (Auth0). A MAU is “a User with a successful authentication event with the Auth0 Platform within a calendar month”, and MAU “are unique per Auth0 Tenant”.[2] The Auth0 billing documentation adds that “Auth0 counts users on a per-tenant basis”, and that a user who logs in to several applications on the same tenant counts once.[6] Catalog: Auth0 MAU; Auth0 MAU are counted per tenant; Auth0 active users are counted per tenant across applications.
Who counts. An Okta Customer Identity User is anyone who uses the service to reach applications other than the workforce applications covered by Workforce Identity.[1] Auth0 draws the line between External Users and Internal Users. Internal Users are personnel of the customer or its Affiliates authenticating for an internal business purpose. Employees who use the customer’s service in the same way as any other user still count as External Users.[2] The Primary Auth and Growth SKUs “do not include Internal Users”, which need the Enterprise Internal SKU.[2] Catalog: Employees using apps for work are Internal Users, not External Users.
Other units. Machine-to-machine traffic is measured in tokens. Okta Customer Identity counts Client Credentials access tokens per subscription year. Auth0 counts the M2M tokens a customer may generate “during one calendar month”.[1][2] Auth0 Advanced Extensibility counts Actions + Forms. Active Actions are those executed with traffic in the billing month, and a Form related to an Action counts as two.[2]
Counting / floors
The same user, two metrics
The two platforms count very differently. Under MAU per Year, a user active once in the year counts as 1, and a user active in every month, or every day, counts as 12.[1] Under Auth0, the same user counts once in each calendar month, and once per tenant if they sign in to several tenants.[2] A licence position should therefore be computed from the platform’s own report. On Okta Customer Identity that means monthly unique authenticated users summed over the contract year. On Auth0 it means the per-tenant monthly figure that the Support Center’s Quota Utilization report shows “against the available subscription limit”.[7] Splitting users across tenants does not reduce an Auth0 count. It can increase it.
Add-on quantities
On Okta Customer Identity, “The total subscription MAU per Year quantity for any add-on Okta Customer Identity SKU must never exceed the subscription MAU per Year quantity for the base Enterprise SKU”.[1] Customer Identity Workflows and Okta Identity Governance must match the Enterprise quantity exactly.[1] Auth0 has the same structure. Add-on SKUs denoted in MAUs “should equal the MAU quantity on the primary authentication SKU and may never exceed it”.[2] Each add-on then has its own activation event: MFA counts MAUs enrolled in a factor, Inbound Federation counts MAUs that generated an inbound federation event, and Directory Integration counts MAUs sourced from AD or LDAP that authenticated.[1] Catalog: Customer Identity add-ons may not exceed the Enterprise base quantity; Auth0 add-on MAU must equal the primary SKU.
Floors and contract length
Okta Customer Identity has no monthly option. “The Customer Identity Enterprise platform and all add-ons require an annual contract”, and add-on pricing is based on usage such as total Monthly Active Users per year.[3] For Auth0 enterprise Order Forms, the MAU quantity “may not be decreased during the Term”, and any MAU added mid-term ends with the current Term.[2] Catalog: Okta Customer Identity requires an annual contract.
Overage
The two Auth0 channels handle overage in different ways.
- Enterprise. “In the event that Customer exceeds the purchased quantity of MAUs in any given term”, the parties enter an additional Order Form for the next MAU tier for each remaining annual term through the end of the subscription.[2] M2M tokens follow the same rule.[2] Catalog: Exceeding Auth0 MAU requires an Order Form for the next tier.
- Self-service. If usage exceeds the purchased limits, the customer must “pay via CC Payment the Fees to upgrade to the next applicable pricing and usage tier”, or sign an Order Form on request. A customer whose use no longer qualifies for a Self Service Plan must move to an enterprise plan within 30 days of Okta’s written request.[5] The Free Plan has a 25,000-user mark. Passing it requires a paid plan sized to the user count.[4] Catalog: Auth0 self-service overuse moves the customer to the next tier.
On Okta Customer Identity, sustained traffic above the purchased rate limit leads Okta to “require that customers purchase an applicable DynamicScale offering in line with usage”.[1] Catalog: Sustained traffic above rate limits requires DynamicScale.
Virtualization & partitioning
Not applicable as processor licensing. The unit of partitioning is the Auth0 tenant, “a logical isolation unit, or dedicated share of a particular Auth0 Platform instance”.[5] Self-service customers may not “simultaneously use or access multiple Tenants” beyond the limits of their plan.[5] Growth SKUs cap tenants at 3 or 6, counting production, staging and development tenants alike.[2] Catalog: Self-service customers may not use multiple tenants beyond plan limits.
Cloud / BYOL
Auth0 runs on a multi-tenant Public Cloud by default. Private Cloud SKUs give a dedicated deployment on AWS or Azure, and “The quantity of the SKU purchased, refers to the number of deployments”.[2] Capacity is sold as a Performance Multiple, “where 1X is 100 RPS”.[2] Private Basic allows up to 100 requests per second, Private Performance Azure up to 500 and Private Performance Plus Azure up to 1,500. Private Basic Azure and the Private Performance Azure SKUs are not compatible with HIPAA compliance.[2] Burst SKUs allow the purchased multiple for up to 80 hours a month. A sustained two-second breach above base capacity uses a one-hour burst interval.[2] On the Public Cloud, Public Performance Burst raises the 100 RPS limit for up to 48 hours a month, counted in 2,880 one-minute increments.[2] The Service-Specific Terms add that burst SKUs extend only Authentication API limits, not the Management API.[8]
Programs
- Customer Identity Suites. B2C and B2B bundles for new customers, priced on MAU per Year.[1]
- Auth0 Self Service Plans. These cover plans bought on the website or a marketplace, and the Startup, Growth and Open Source Software plans.[5] A plan renews automatically for the same Term unless the customer signs an Order Form or deletes all Tenants. The renewal is charged at the then-current Subscription Page fees.[5] Unpaid fees or an uncured breach let Okta downgrade the customer to the Free Plan or suspend it on five business days’ notice.[5] Credits or refunds after a cancellation may be available for tenants with minimal or no login history, subject to Okta’s evaluation.[6] Catalog: Auth0 self-service plans renew at then-current fees.
- Free use. The Auth0 Free Plan is treated as an “Auth0 Platform Free Trial” under the MSA’s free trial terms.[5] The paid-plan trial lasts 22 days and then reverts to the Free Plan.[4] The Okta Integrator Free Plan allows a non-production Okta environment for up to 10 active users.[3]
- Auth0 for Startups and nonprofits. Auth0 advertises a startup plan with 100K monthly external active users free for a year. All paid plans are eligible for a Social Impact discount.[4]
Out of scope
- Fine Grained Authorization, which has its own reference guide.
- Auth0 Marketplace partner terms, HIPAA BAA and PCI environments.
- Okta Customer Identity and Auth0 prices beyond those on the public pricing pages.
- Okta for AI Agents and Auth0 for AI Agents in depth. See Okta Privileged Access and AI agents licensing.