7 Best European WorkOS Alternatives in 2026
The best European alternative to WorkOS in 2026 is Hanko, based in Germany. All 7 options below are European-owned, GDPR-native and ranked by feature parity and relevance.
By the EU Alternatives team Last updated
Our top pick this year is Hanko, but every option on this list is European-owned, GDPR-native, and production-ready. Worth a closer look: ZITADEL, Ory, cidaas, Engity.
WorkOS alternatives are mainly Security & Identity and Developer Tools. Browse any of those categories for a wider shortlist beyond this list.
Top European WorkOS alternatives compared
| # | Alternative | Country | Open source | Free tier | Compare |
|---|---|---|---|---|---|
| 1 | Hanko | Germany | Yes | No | vs WorkOS → |
| 2 | ZITADEL | Switzerland | Yes | No | vs WorkOS → |
| 3 | Ory | Germany | Yes | No | vs WorkOS → |
| 4 | cidaas | Germany | No | No | — |
| 5 | Engity | Germany | No | No | — |
-
Open source authentication solution with passkeys, 2FA, SSO support. GDPR compliant, built in Europe. Switch between self-hosted and cloud anytime.
Hanko is an open-source authentication and user management platform from Kiel, Germany, built as a modern, privacy-first alternative to Auth0, Clerk, and Cognito. It puts passkeys front and centre while still supporting passwords, passcodes, and OAuth social logins.
Developers get Hanko Elements, a set of framework-agnostic Web Components that drop into any frontend in minutes, plus a full backend API for custom flows. The Passkey API can also be bolted onto existing auth systems without a full migration.
Key features:
- Passkey-first authentication with FIDO2-certified, phishing-resistant biometric login
- Multiple auth methods including passwords, email passcodes, OAuth (Google, Apple, GitHub), and 2FA
- Hanko Elements, framework-agnostic Web Components for React, Vue, Angular, and more
- Flexible hosting, either self-hosted (AGPLv3) or Hanko Cloud with no lock-in migration
- User management with profiles, sessions, and audit logs out of the box
- GDPR compliant with EU infrastructure and data minimalism by design
Trusted by 10,000+ developers and used in production by SAP and Volt.io. The core is fully open source under AGPLv3 and MIT licences, with GitHub stars growing fast.
-
Manage user identities securely with customizable authentication, SSO, MFA, and RBAC. Offers easy APIs, programmable workflows, and multi-tenancy for developers.
ZITADEL is an open-source identity infrastructure platform that combines the flexibility of self-hosting with the convenience of a managed cloud, bridging enterprise authentication and developer-friendly APIs in a single product.
The platform handles the full identity lifecycle: login pages, social logins, SSO, MFA, passkeys, RBAC, machine identities, and multi-tenancy, all configurable through gRPC and REST APIs. ZITADEL Actions let teams run custom workflows after any auth event without writing a custom server.
Key features:
- Authentication with hosted login UI, social logins, passkeys, MFA, and SSO
- Authorization via role-based access control with fine-grained permission management
- Multi-tenancy to add new organisations, delegate admin rights, and isolate data per tenant
- Machine identities covering service accounts and API key management for non-human actors
- Extensible through ZITADEL Actions that execute serverside logic after any auth event
- APIs built on modern gRPC and REST, with SDKs for Go, Angular, React, Next.js, Flutter, and Python
- Compliance spanning OpenID certification, ISO 27001, GDPR, and SOC 2 Type II
Open source with 4,000+ GitHub stars and 50+ contributors. Deploy to your own infrastructure or use ZITADEL Cloud with EU data residency.
-
Modular open-source identity stack — CIAM, B2B IAM, workforce, and AI agent identities — with trillion-scale stateless architecture and a managed SaaS option.
Ory is an open-source identity and access management platform built for modern, cloud-native architectures. Its modular, headless design lets teams compose exactly the identity stack they need, from customer login flows to B2B delegated access to machine identities for AI agents.
The Ory ecosystem includes Kratos (identity management), Hydra (OAuth 2.0/OIDC server), Keto (permissions), and Oathkeeper (reverse proxy). Each can be deployed independently or combined via Ory Network, the fully managed SaaS. With stateless horizontal scaling, the platform is proven at 2.5+ billion identities.
Key features:
- CIAM, B2B IAM, Workforce IAM, and Agent IAM with purpose-built flows for each use case
- Headless architecture that lets you bring your own UI and integrate into any stack
- Modular OSS components spanning Kratos, Hydra, Keto, and Oathkeeper (Apache 2.0)
- Ory Network, a fully managed cloud with zero-ops deployment
- Trillion-scale stateless horizontal scaling with full observability
- AI agent identities purpose-built for securing non-human actors
- Enterprise license for on-premises deployment with premium support
Used by OpenAI, Société Générale, Mistral AI, Axel Springer, and commercetools. The full stack is open source, auditable, and self-hostable, with Ory Network for teams that want a managed option.
-
German cloud IAM for customers, employees, and machines — SSO, passwordless, MFA, identity verification, and consent management on one platform supporting 1B+ identities.
cidaas (Cloud Identity and Access Service) is a German-built IAM platform from the Widas Group, designed to unify identity management for customers, employees, partners, and IoT devices, all from a single European cloud.
Spanning CIAM, workforce IAM, and API security, cidaas covers the full identity lifecycle with SSO, passwordless authentication, MFA, AI-powered identity verification, and GDPR-native consent management. Its integration layer connects to the cnips iPaaS platform, and the platform is built on open standards for interoperability.
Key features:
- Single Sign-On for seamless cross-application access with OIDC and OAuth 2.0
- Passwordless authentication via passkeys, magic links, and biometric login
- Adaptive MFA, risk-based multi-factor with multiple authenticator options
- AI identity verification covering document validation and liveness checks
- Policy-based authorisation for dynamic, role-driven access control
- Consent management with GDPR-compliant data handling and audit trails
- API security through access management and token governance
- 1B+ identity scale deployed across 182+ countries
Made and hosted entirely in Germany. Customers include Kaufland, Europa-Park, ProSiebenSat.1, EWE AG, and Creditplus Bank.
-
German CIAM platform with passwordless auth, passkeys, social login, and multi-tenancy — GDPR-compliant, cloud-managed, with breached password detection built in.
Engity is a European Customer Identity and Access Management (CIAM) platform built for developers who need secure, flexible user authentication without the overhead of running identity infrastructure. Headquartered in Munich, Germany, the platform is fully managed, GDPR-compliant, and architected for multi-tenancy.
The platform supports the full spectrum of modern auth: classical username/password, social logins, enterprise SSO, magic links, biometrics, passkeys, and MFA, with real-time push notifications and breached password detection baked in.
Key features:
- Passwordless options spanning magic links, passkeys, and biometrics
- Social and enterprise login via social OAuth and enterprise SSO connectors
- Multi-factor authentication with TOTP, push notifications, and hardware keys
- Multi-tenancy through isolated tenant databases with full per-tenant customisation
- DeviceAuth for keyboardless login in device-constrained environments
- Breached password detection running real-time checks against compromised credential lists
- Serverside webhooks to customise flows and integrate with existing systems
- GDPR compliant with European data sovereignty and EU hosting
Open to open source: Engity maintains Bifröst, an SSH server connector contributed back to the community. Suitable for SaaS platforms, digital products, and regulated industries needing flexible identity flows.
-
Swedish enterprise identity server for APIs, AI agents, and human users — OAuth 2.0, OIDC, FAPI compliance, decentralised identity, and SOC 2 / ISO 27001 certified.
Curity is a Swedish identity server built for securing APIs, web apps, AI agents, and human users on a single platform. Positioned at the enterprise end of the market, Curity is used by financial services, healthcare, government, and telco organisations that need standards-compliant, high-assurance identity.
The platform combines authentication, intelligent token issuance, user lifecycle management, and API security in a deployable package, available on-premises, in the cloud, or as hybrid. A free Community Edition makes it accessible for teams evaluating enterprise identity architecture.
Key features:
- Authentication spanning passwordless, passkeys, SSO, MFA, social logins, and adaptive flows
- Token Service offering intelligent OAuth 2.0 and OIDC token issuance with fine-grained policy
- API Security that provides high-grade API and SPA protection with token introspection
- AI agent identities purpose-built for securing non-human actors in agentic workflows
- Decentralised identity with digital wallets and verifiable credentials support
- User Journey Orchestration for adaptive authentication with branding controls
- Compliance backed by SOC 2 Type 2 and ISO/IEC 27001 certification, plus FAPI conformance
Customers include Dun & Bradstreet, ICA, Santander, Volvo Finans, and PagerDuty. Multiple deployment options with a Community Edition available for evaluation.