4 ms·
Nice, good luck! My advice would be to offer something very opinionated to limit the chance that something is rolled out incorrectly. That and preventing lock-i
by sjroot 6y ago
Nice, good luck! My advice would be to offer something very opinionated to limit the chance that something is rolled out incorrectly. That and preventing lock-in are two big requirements IMO.
I’m doing something somewhat similar, happy to exchange notes.
- ayewo 6y agoWhat do you think of an open core security product like https://fusionauth.io/ https://fusionauth.io/ that supports those protocols ?
- sjroot 6y agoI’ve never heard of FusionAuth but after a quick glance it seems interesting. Generally, I think these standards are worth knowing even if you do decide to use a managed offering. Also worth mentioning is ORY Hydra.
- taosx 6y agoOpen core..wouldn't that mean the core product being open source..from what I'm seeing on github only some components are open source. By that example I would also call auth0 open core. Anyways, seems interesting.
- mooreds 6y agoI work for FusionAuth. It's not open core. It's the other way around (open shell?), as you see, @taosx. The docs, client libraries, example apps, and some supporting libs are Apache licensed, but the core is not. We do have a forever free community offering[0], but that's free as in beer, not as in speech. I think it's a great product (that's part of why I joined the company) but don't want any confusion about that. [0]: https://fusionauth.io/pricing https://fusionauth.io/pricing has a list of the options.
- gavinray 6y agoI know this has nothing to do with the product, but I hung out with their CEO Brian Pontarelli and one of their lead devs (I think his name was Daniel) for an afternoon many years ago. This was before FusionAuth, when they were running under Inversoft. They came to do a lunch and learn + product feedback at the place I was working at then. We kept in touch for a while after. Really amazing group of people, super genuine.
- user5994461 6y agoThere is no market for that. 1) Most of the work around authentication is integrations (get the app to integrate with whatever authentication protocol/database). Integration is not a product, it's consulting services. 2) There are very established products for authentication servers. See Microsoft ADFS, PingIdentity and ForgeRock on premise. See Okta and auth0 on SaaS. 3) If you're going to roll some authentication as a company, you stick to Microsoft ADFS for internal employees or to Google/Facebook auth for external accounts. You need them anyway so there is absolutely no point in getting something else. (Yes, your company is gonna use microsoft windows internally and your customer will request google auth support). 4) There is absolutely no point for yet another product. What is it gonna do? It's gonna sit on top of google auth so you can integrate with it rather than with google? Pointless, might as well integrate to google/microsoft directly. 5) Where there is money is in consulting services, libraries and plugins. For examples make a plugin for apache/nginx/haproxy to use google auth, so developers can just put that in front of their service (legacy application) and it's mostly plug and play. Or easy library for python/java/whatever to integrate (developer can just configure a google id and URL and can retrieve user info). It's hard though because of customization hell, every use case wants to do things slightly differently. That's my 2 cents working in the industry. For reference I've worked on authentication in startups for customers, in government projects for citizens and in companies for 100k+ employees.