Category

European Identity & SSO Tools

Open and EU-hosted identity, single sign-on, and access management for teams that refuse to outsource authentication to a US hyperscaler.

2 listed tools

Identity is the single most sensitive shared infrastructure dependency in a modern stack. It sits in front of every other system, so the jurisdiction and ownership of the identity provider becomes the jurisdiction and ownership of the entire authentication path.

For European procurement teams, this is also where the largest concentration of US dependency sits today. Okta, Auth0, AWS Cognito, Entra ID, and Google Workspace SSO together cover a significant share of EU enterprise authentication, and each comes with the same recurring questions: where is the directory hosted, where are session tokens stored, who can be compelled to access them, and how is sub-processor disclosure handled.

European and open-source identity software addresses these questions differently. Self-hostable platforms such as Keycloak and Authentik can be deployed inside an EU-hosted environment with no third-party access to the identity store. Managed European providers such as ZITADEL offer the operational simplicity of SaaS without the US ownership question.

For an EU-first stack, identity is one of the highest-leverage categories to move first. Once the IdP is sovereign, every downstream SaaS integration inherits a cleaner trust boundary, and the procurement story becomes much easier to defend.

Directory

Tools in Identity & SSO

Profiles and replacements that fit this category right now.

Z
Identity & SSO

ZITADEL

Open-source IAM for customer and workforce identity with OIDC, SAML, SCIM, and machine identity support.

CH Switzerland and EU regions on managed cloud, or self-hosted
K
Identity & SSO

Keycloak

Mature open-source identity platform for SSO, federation, and authorization, with no required vendor data path when self-hosted.

EU Self-hosted; commonly deployed in EU-region Kubernetes clusters
Migration Paths

Common replacement patterns

Examples of the vendor switches teams usually consider first in this category.

Identity
Auth0
ZITADEL

Swiss open-source IAM platform with managed EU and CH cloud regions, full self-hosting support, and clear European jurisdiction.

Identity
Okta
Keycloak

Open-source IAM platform that you can deploy entirely inside EU infrastructure with no vendor data path.