4 ms·
Would you think that, for an early-stage SaaS startup (enterprise B2B focus), the optimal strategy for implementing AuthN/AuthZ would be to use a managed servic
by ablekh 6y ago
Would you think that, for an early-stage SaaS startup (enterprise B2B focus), the optimal strategy for implementing AuthN/AuthZ would be to use a managed service (e.g., Auth0) for MVP development and after that (perhaps, during pilots phase) migrate to an open source solution (e.g., Keycloak)?
- anderspitman 6y agoDo you need to provide access to third-party apps? If not you probably don't need oauth. Just use session cookies.
- ablekh 6y agoThank you for your comment. Yes, I'm planning to allow running third-party apps on the platform (the exact delivery options and relevant architectural details are still under consideration). My understanding is that using JWTs is the current best practice and much preferred way for authentication vs. the session-based approach. The platform that I plan to build should be both highly scalable and highly secure. I think that session cookies is not the right approach for these requirements, even if I would not need to allow running third-party apps. I'm curious about what people here think about this and hope that they will chime in. (I also would need SSO, external IdP integration, clustering, MFA, maybe passwordless authentication etc., hence my preference for managed services like Auth0. The idea is to focus on my core competencies and outsource important but non-core services to relevant solid providers, based on availability and feasibility, at least, for the near-to-mid term.)
- anderspitman 6y agoPersonally I don't think it's worth worrying about scaling like that until you actually need to. There are other reasons to choose JWTs, but I don't think scalability is a good one early on.
- ablekh 6y agoThank you for sharing your thoughts. I'm not worried about scaling and other aspects, but I do think about them. In my opinion, architectural decisions are the most important ones (across technological dimension) and fixing wrong or suboptimal architectural decisions is costly and/or difficult and sometimes outright not feasible.
- anderspitman 6y agoTrue, but you can further break architectural decisions down into those that are easy to change and those that aren't. If something is easy to change you may as well implement the simple version first.