Skip to content
Notifications
Clear all

Best identity provider for a Python/Django app with 10k users

3 Posts
3 Users
0 Reactions
13 Views
(@emilyk22)
Honorable Member
Joined: 3 months ago
Posts: 465
Topic starter   [#26418]

I'm currently architecting the authentication and authorization layer for a mid-sized Django application that is projected to scale to approximately 10,000 registered users within the next 18 months. Our stack is Python 3.11/Django 4.2 with a PostgreSQL backend, and we require a robust, external identity provider to handle user management, social logins, and eventually, role-based access controls.

Having evaluated the landscape, Auth0 is a primary contender, but I am conducting a thorough feature and pricing analysis against other providers like Cognito, FusionAuth, and Okta's developer offering. For our specific context—a B2B SaaS with potential for enterprise clients—the critical evaluation criteria are:

* **Django Integration Depth:** The simplicity and security of integrating the `python-jose` and `django-allauth` libraries, or a dedicated SDK, versus a more manual OIDC/JWT implementation.
* **Progressive Profiling & Migration:** The ability to seamlessly add required user profile fields post-initial login and a clear path for migrating existing users from our legacy system.
* **Cost Predictability at Scale:** Analysis of the Active Monthly Users (MAU) pricing model, specifically where 10k users would place us on the Auth0 scale and the cost implications of enterprise features like custom domains, branded emails, and advanced anomaly detection.
* **SLA & Operational Burden:** The tangible difference in uptime guarantees between the Developer Pro and Enterprise plans and the real-world reduction in operational overhead for my team in managing password resets, breached password detection, and MFA enforcement.

My preliminary research indicates Auth0's documentation for Django is comprehensive, but I am seeking practical, long-term experiences. For those who have implemented Auth0 in a similar Python environment at this user scale:

* What were the most significant hurdles during implementation, particularly with session management and stateless JWT validation in Django?
* How does the reality of the MAU billing model align with a growing application, and were there any unexpected cost drivers as you approached the 10k user threshold?
* Compared to running a self-hosted solution like Keycloak or a competing cloud service, has the reduction in internal support tickets for authentication-related issues justified the ongoing subscription cost?

I am particularly interested in a side-by-side comparison of the total cost of ownership and developer experience, rather than a generic feature list.


Support is a product, not a department.


   
Quote
(@data_shipper_joe)
Prominent Member
Joined: 5 months ago
Posts: 680
 

I'm Joe, a data engineer at a fintech with about 50K MAU. We built our core product on Django and spent the last year migrating its auth layer from an in-house system to an external IdP, so I've lived this exact journey.

**Django Integration & Dev Experience:** Auth0's Django quickstart is the most polished. You can go from zero to a working login flow in under an hour. For Cognito, you're effectively building your own OIDC client with `django-allauth`; it's more work and I've spent days debugging quirks with the `username` field mapping. FusionAuth sits in the middle with a cleaner Django SDK than Cognito, but less community material than Auth0.
**Progressive Profiling & Migration Reality:** Auth0 has built-in progressive profiling rules and a very flexible Actions pipeline to handle it. Their migration assistant and bulk import tools worked for moving our 8K legacy users. With Cognito, you'll be writing Lambda triggers (adds devops overhead) to add fields post-login, and their user import is more manual.
**Cost Predictability at Our Scale:** At 10K MAU, Auth0's B2C plan (which works for B2B SaaS) runs about $0.07 per MAU, so ~$700/month. Cognito seems cheaper at ~$0.055 per MAU after the free tier, but you pay for Lambda invocations for custom auth flows and SMS MFA, which added about 20% to our bill. FusionAuth's open-core model is cost-fixed if you self-host, but then you're on the hook for infra and scaling.
**Where It Breaks / The Gotcha:** Cognito's hosted UI is difficult to customize deeply for a polished B2B product. Auth0's pricing gets steep if you need enterprise features like breached password detection or unlimited social connections, which move you to the B2B plan. FusionAuth's managed cloud offering is relatively new; at my last shop, we ran the Docker setup and hit scaling issues past 5K concurrent sessions that required tuning our Redis cache.

Given you're a B2B SaaS with enterprise aspirations, I'd recommend Auth0 for its out-of-the-box Django integration and superior enterprise readiness. If your primary constraint is hard cost control and you have the devops bandwidth to manage triggers and tuning, a deep look at Cognito is warranted. Tell us your monthly budget cap and whether you have a dedicated devops person to manage the IdP, and the choice gets clearer.


ship it


   
ReplyQuote
(@ashp99)
Honorable Member
Joined: 2 months ago
Posts: 377
 

Great breakdown. For your B2B SaaS context, the progressive profiling and migration path should be a top-three decision factor.

We went with Auth0 two years ago at a similar scale, and the migration tooling for our legacy user table was a lifesaver. Their bulk import and password migration features worked seamlessly.

That said, for pure cost predictability, you can't beat FusionAuth's flat pricing. If your growth projections are solid, run the numbers for 10k MAU on both - Auth0's per-MAU model can get surprisingly steep.


data over opinions


   
ReplyQuote