8 ms·
Show HN: Kinde – auth, feature flags and billing (Q3) in one integration
- connorkinde 3y agoHey HN - excited to share Kinde with all of you. We're building a one stop shop for new SaaS products. Integration takes a few minutes and our current record time is 1 minute 52 seconds for a first time user. Current features: - ISO certified secure auth - Connected apps (Drive, Github, Gitlab) - Custom branding + domains - 14 SDKs (incl. react, nextjs, etc.) - Azure + 8 social SSO options - Organizations and multi-tenanting (b2b2b & b2b2c support) - MFA w/ OTP generators or SMS - Passwordless sign in - Basic feature flags (full release management suite coming) - Completely customizable flows - Request access forms Also on the way - Billing (Q3) - Release management suite - Experimentation - Marketing and lead gen There's heaps on the way. Check it out and let us know what you think
- seveibar 3y agolooks pretty cool :) nice work! Some things we find missing at Seam (we use both Clerk and Auth0 on different apps): 1. Inability to change email or reset password without using "privileged" API, would love to redirect users to a Kinde/Clerk/Auth0 page to manage their profile 2. Ability to store secure secrets into a user with auditable access 3. Difficult in-app login
- dave_kinde 3y agoThat's great to know, we're looking at offering hosted profiles for both end users and organizations (tenants). Could you expand on what you mean by difficult in-app login with Clerk/Auth0?
- inezk 3y agoI don't mean it in a bad way but I scrolled through the website, watched the video, and still don't really know what is the product/service/offering and when would I need it.
- connorkinde 3y agoNo problem - we're relaunching the website in the next few months so hopefully that'll be a bit clearer. At this stage the closest comparison would be clerk.dev!
- notlive 3y agoIt's a drop in authentication system. You would need it to have users and logins for your app. Or you have to write and maintain your own. They say billing is coming so I guess it crosses the line into subscription management. I'm using auth.js with extra code for the same thing. That's been a revolution compared to wiring it all from scratch. Without subscription revenue (i.e. Just using this for accounts and auth) I couldn't justify the $75/mo needed for active directory SSO. But watching the demo video, I'd love to have a project with the financials to justify using Kinde
- connorkinde 3y agoThanks! That's a perfect explanation. Exactly right with the subscription management on the way, similar to linking up Auth0 with Chargebee in one product.
- vertis 3y agoWithout criticising the current Show HN, there are a bunch of existing Auth services that are free or close to free. - Auth0 (up to 7000 users, if I can read the comparison page right) - Supabase Auth (50,000 MAU).
- connorkinde 3y agoYep, but you'll find with a lot of them the features are incredibly limiting on free plans. It's the same virtually anywhere in terms of having a free tier, so the issue becomes pricing on higher plans. We come in significantly lower for the same feature sets The driving factor we're pushing for going forward is to bring all of these dev products (auth, release management, billing, experimentation) under one roof. You'll only have to integrate once and from there on out every other feature is a single line of code. That way you can manage your users in the same place that you manage your subscriptions, release beta products to a very specific set of users etc. all in one place.
- krzyk 3y agoIsn't the name too similar to Kindle? At first I thought it was some software for Kindle.
- connorkinde 3y agoWe have had numerous sign ups from people thinking we were Kindle, although a little late for a name change
- tough 3y agoNever too late if it makes sense, although it's different enough if you ask me
- vertis 3y agoDisagree. You definitely need to reconsider the name. It was my first reaction as well.
- lapser 3y agoIf not for the brand difference, it should be done to avoid Amazon's lawyer from coming after you.
- stevoski 3y agoThis very much tells me you need to change the name. It might be difficult now, but it will only get more difficult as time passes.
- criddell 3y agoIn another comment you said you are relaunching your website soon. That’s a perfect time to either rename or pivot to ereader tools. :)
- fastball 3y agoI too clicked thinking this was something for Kindle.
- sakopov 3y agoI was looking at the docs and kept seeing a lot of similarities with Auth0. Looks very promising and fully featured. Perhaps I missed it, but I was looking at the .NET SDK and didn't see much plumbing for verifying JWT with Kinde (in the context of a web API request). Is this not baked into the SDK?
- dave_kinde 3y agoHey, thanks for digging in. The backend SDKs are really geared towards calling the management API, handling the auth flows and providing helpers for things like permissions / feature flags. We haven't baked in JWT verification just because there are already so many libraries which already handle this side of things. Although, it's definitely something we could extend the SDKs to include.
- zaldrian 3y agoWow, you guys made it work — my company zalter.com didn't reach this level of Kinde as of yet. What's a marketing strategy you made it work? You do B2B outreach?
- connorkinde 3y agoA little bit but trying to primarily drive growth through referrals from existing customers. If we can continue to build based on their requests and keep them happy, hopefully they talk about us in the future to other people looking for auth
- simantel 3y agoThey raised a $10M seed round.
- connorkinde 3y agothat did help
- deleted 3y ago[deleted]
- cleverfoxy 3y ago[dead]
- fennakinde 3y agoVery exciting :) Lots more to come
- aweheel 3y agoCongrats on the launch, building a product in this space is incredibly difficult. I took a look at the stack, here are a few observations: - "ISO certified secure auth": What does that mean? I could not find proof of your ISO certification. Can you please share? - 10k M2M tokens for $250/month sounds like a really bad deal if I can just spin up https://github.com/ory/hydra https://github.com/ory/hydra that can easily handle 10k requests per second. - Looks like you're using OAuth2 as the primary "login" and "session management". What compelled you to do this? - It looks like you're using some open source technology under the hood for the OAuth2 flows - which one are you using (out of curiosity)? And finally, what sets you apart? It looks like the same solution for the known problem that big players (such as Okta and Auth0 - publicly traded) have already mastered. Ory (github.com/ory) for example has it's global network approach where you no longer need datacenter locations and is Open Source. Clerk is targeting React devs. What's your niche? Doing everything from auth to billing is, in my experience, way too much for a small team with little resources. Just getting Auth right is a mammoth task.
- lapser 3y ago> 10k M2M tokens for $250/month sounds like a really bad deal if I can just spin up https://github.com/ory/hydra https://github.com/ory/hydra that can easily handle 10k requests per second. Spinning one up is easy, sure. Making sure it's production ready, is not so much.
- dave_kinde 3y agoThanks so much for the detailed feedback and great questions! You can find details of our ISO and other certifications on our compliance page: https://kinde.com/docs/important-information/compliance-certifications/ https://kinde.com/docs/important-information/compliance-cert... we're also happy to provide a copy of the certificate if you reach out to support@kinde.com. In terms of pricing, 10k M2M tokens are included on our $25/month plan (as well as many other features) so no need to spend $250 :) We feel this is a fair value exchange for everything being offered on the plan. Of course, there is always the roll-your-own option and great open source solutions like Hydra and that's awesome too for people that are confident going down that path - but it's not for everyone. The great thing we have found about going the OAuth2 route is that you are free to use Kinde with any library that supports OAuth2. We also have SAML available as an auth option. There is no denying there are a number of great players in the auth space but this is really only the start for us. We’re an experienced team aiming to help create a world with more founders by bringing together the fundamentals of product development. The fact that we’re small means we’re able to move quickly. We’ve just shipped v1 of feature flags and have more exciting offerings to come!
- presentation 3y agoI'm going to be building out a SaaS soon, and expect to be doing a lot of SAML and OIDC auth. The field of auth services seems to be super crowded, between the incumbents like Auth0, Okta, Cognito, etc and a ton of startups all offering nice DX and lower pricing, like Clerk, Stytch, WorkOS, Supabase Auth, and so on (putting aside the options of rolling it yourself). After reading the homepage I'm not really sure why Kinde would be better suited for our use case than any of those other startups, since everyone says they're secure/have transparent pricing/are nice to use, but maybe just gotta try it to find out?
- zaldrian 3y agoI co-founded zalter.com bootstrapped and kind of failed to grow it — mainly because of the market saturation IMHO. Did a lot of PoCs and unfortunately most companies are vendor locked-in.
- connorkinde 3y agoUnder the hood you often find a lot of differences in terms of what you get for the cost, limitations in user management depending on which company, and a few other factors. For us we've built out auth, and now the next step is billing and release management. Once you have these different factors in one place you should see heaps of benefits
- nickmyersdt 3y agoOne of the things my business needs, but I cannot find a SaaS solution for is: Multi-tenant (each of my customers gets a fully separate directory, with access to all tenants for our admins) SAML and OAuth (customers can set up SAML themselves via the SaaS interface, or we set the SP up for them) Rule based group assignment based on SAML attribute evaluation (e.g. assign users to this group if the attribute X = Y) APIs to manage users, groups, organisations (tenants) We've built something using Okta, but all our customer users are in one Directory/Tenant. Auth0 nearly gets there with Organisations but can't help with the sub-groups and rule based management. For context, we have an education product and customers are districts or schools, and the sub-groups are typically schools and/or classes or groups of users (e.g. seniors or juniors). We also need to support SAML Federations like InCommon, OpenAthens, UK Access Management Federation which makes the challenge harder (these federations want a single SP to which many IDPs authenticate) for Universities. None of the modern platforms support this. If anyone has found an out of the box solution for this, I'd love to hear about it.
- hden 3y agoAuth0's Fine Grained Authorization is in developer preview. https://auth0.com/developers/lab/fine-grained-authorization https://auth0.com/developers/lab/fine-grained-authorization
- nickmyersdt 3y agoThank you, will keep an eye on it. Auth0 is definitely the closest I've seen to what my business needs (and I've spent waaay to much time one trials and demos of too many products so far). If it would: a.) Perform group assignment based on SAML attributes (like Okta's group rules), and, b.) "natively" support SAML Federations used in the Higher Education space (which Shibboleth appears to be the only thing that supports) I'd sign up tomorrow and start migration of my 150k users.
- jhogendorn 3y agoWould fusionauth meet all these needs?
- gtsteve 3y agoI have a question, although it's not about this product in particular. I started building web apps before Auth0, Okta and friends arrived on the scene so I never considered until recently having someone else manage my authentication concerns. Identity is very important in most web applications so I was wondering what value a CTO gets from allowing someone else to manage it. For example, I would be concerned about prices suddenly being increased or what happens if the business we relied on failed, lost accreditations, or suffered a serious security incident. Presumably there isn't a migration workflow away from these products, save for asking your customers to perform a manual action. While clearly these services are very useful and popular, I just can't shake the feeling that it could be a very good way to get started, but a long term strategic mistake. I was wondering if anyone from Kinde or with experience using these services long-term has any thoughts on this?
- mkl 3y agoI agree, it seems like a strange risk. How easy is it to change authentication provider? How disruptive is that for customers? I have no experience with this sort of thing, but would like to understand.
- dave_kinde 3y agoIt varies from provider-to-provider. With Auth0 you have to install a plugin from their marketplace to get an export. If you want the hashed passwords exported you have to email their support team and they pull it together for you - usually takes about 2 weeks. Kinde has a self-serve export tool baked in as we believe it is important for people to be able to change provider freely and not have vendor lock-in. We also have a self-serve import tool for organizations and users including hashed passwords so there is no disruption to the end customer
- gtsteve 3y agoThat's really good and thanks for responding to the question. I think I could be tempted to try a service like this for a future project. I'm guessing the password hash format is something like bcrypt2? Is there an API for that? The feature quite nicely mitigates a situation where prices are unreasonably raised, but to mitigate a rug-pull event such as a business failure, malicious action or serious technical failure I'd probably want to automate this. If that sounds like I'm sort of paranoid, it's probably because I am. I do this with all my company's cloud data.
- sanat 3y agoLoved the product video. How did you make it?
- connorkinde 3y agoThanks! Worked with an awesome animation company called Fox&Co based in NZ
- xyst 3y agoI have been using open source tooling for authentication and authorization. So far I have had good experience with Ory ecosystem and self managing (they have a managed version as well). It’s missing “billing” compared to Kinde but that’s something I can add with another open source tool — Lagos. Good luck. I can see the value in startups using this in the short term to quickly get something to market without burning their capital but in the long run it would be better to manage it yourself with good open source tooling.
- KomoD 3y agoHonestly, I found it to be unusable in EU, trying to navigate the dashboard is extremely slow and the only regions you seem to be offering are AU and US. Also I keep reading the name as Kindle
- connorkinde 3y agoAny chance you could email me? Connor@kinde.com Obviously a bit of a concern for us if you were struggling, would be keen to hear more