Auth0 is an identity management platform for developers and application teams. It gives users a platform to authenticate and authorize, providing secure access to applications, devices, and users. Auth0 aims to provide the simplicity, extensibility, and expertise to scale and protect any application, for any audience. Integrate Auth0 into any app, written in any language, and any framework.
$23
per month
Oracle Entitlements Server
Score 4.0 out of 10
N/A
Oracle Entitlements Server is an authorization solution.
N/A
Pricing
Auth0
Oracle Entitlements Server
Editions & Modules
1,000 External Active Users
$23
per month
2,000 External Active Users
$57
per month
5,000 External Active Users
$114
per month
500 External Active Machines
$130
per month
10,000 External Active Users
$228
per month
20,000 External Active Users
$455
per month
50,000 External Active Users
1,138
per month
Over 50,000 External Active Users
Contact for quote
Enterprise
Contact for quote
No answers on this topic
Offerings
Pricing Offerings
Auth0
Oracle Entitlements Server
Free Trial
Yes
No
Free/Freemium Version
Yes
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
Optional
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Auth0
Oracle Entitlements Server
Features
Auth0
Oracle Entitlements Server
Identity Management
Comparison of Identity Management features of Product A and Product B
Auth0 is very well suited for situations where a JSON web token can be used for authorizing APIs, websites, and mobile devices. It's especially useful if the JWT validation can happen at a gateway layer. It's especially useful if you only need to verify the user's email address or mobile number as the passwordless login is easy to implement.
Could be suited for cases where authorization policies change extremely frequently and unpredictably. For all other scenarios, I would avoid this product!
Auth0 can be somewhat limiting if you want a lot of control over the design of your authentication flow. Custom branding can be done, but it may be limited depending on how you plan to integrate.
The Auth0 API documentation has proven confusing at times; a single API endpoint's behaviour will change based on inputs and configured settings (e.g. offline_access). Consequently fields that are advertised as being returned in a response might not be there or have different values if you miss a key detail and it can be difficult to debug when this happens. All information required is available in the documentation but requires some digging.
The toggle to switch tenants feels a bit odd, it works, but I've had a few instances where I didn't realize I was on a staging tenant looking for something that was on the production tenant. Not a big deal, just something to watch out for.
Horrible administration web UI - had to spend months with our database team to make an application's entitlements show up in < 30 seconds, difficult to navigate UI. It has sliders that make you think you can expand certain portions of the UI, but they do nothing. Many operations that must be done in day-to-day administration require 3 clicks per application, so this makes policy creation and distribution extremely time-consuming. A variety of random errors would occur and instead of friendly messages, full exceptions were shown to the user, including a stack trace. Often, this stack trace was so long, the box would overflow the screen and the user would be unable to close the popup box.
The built in Policy Decision Point's web service only supported returning a SINGLE entitlement at a time. This was completely inadequate (would have crippled our apps' performance) and somewhat laughable given this is an 'enterprise product'. We ended up having to write our own web-service which could check multiple entitlements at once using the Java API
Horrible Support - we opened at least 20 support cases and the majority were classified as bugs or product enhancements, and then nothing was done on them. I am pretty sure this product has no full-time developers, given the lack of progress seen on their product in over 2 years. A variety of issues went back and forth between the OES and Weblogic teams, both blaming each other, and never got resolved. When we tried to escalate, various Oracle manager folks claimed to be exerting pressure, but ultimately everything fell back on us (sorry, can't reproduce it on our end) and made no progress. Almost every support person we got did not speak fluent English, writing back in incomplete sentences, and confusing basic pronouns (he vs she), etc.
Lack of product documentation. It took us about a month of working with support to enable LDAPS binds for users logging into the admin UI (by default, it only worked with unsecure LDAP binds). All of such configuration was undocumented and we had to rely on support giving us explicit instructions. There was also a bevy of patches that had to be applied to 3 different components of the product in a specific order to work properly. Some patches caused regressions and broke functionality that previously had been corrected by a prior patch. They also released an entire new version (Patch Set 1 I believe) and forgot to increment the build number in the UI, causing much confusion. Any development house with basic build/release practices in place would have avoided this.
- integration and ease of implementation - great over all product support specially for passkey biometric authentication -Auth0 is very reliable to use their API integration for security verification. It provides best API to integrate our website and application with Single Sign In option and two step verification option. Sales and technical teams are always there to provide support
There isn't a clear method to get a hold of support when trouble arises if you're on their standard plan. You can file a support ticket and they generally are responsive. I've often been able to find similar questions to the questions I've had when it comes to support in their ticket history, however, some have been closed without a satisfactory conclusion for the original poster.
Auth0 is non-evasive and does not require software download. It is user friendly, seamless, and doesn't require additional actions on the part of the user. IBM Trusteer is none of these things and is based on a technology stack that cannot scale in the same way as Auth0. We believe Auth0 provides a superior solution and is well suited for our own technology stack.
I saw one other competitor at a trade show, but unfortunately their product didn't seem much better. It forced administrators to dig through horribly complex expressions with lots of ANDs and ORs to debug a basic policy. I didn't think it would be easy enough to use.
Development time has been allocated to the more core parts of our business.
We are confident in the security of our user's accounts and their data.
Auth0's login flows are customizable which means that we don't have to worry about users being confused when logging in/changing their passwords, and we didn't event have to spend that much time configuring this. (Full in-house development for login could take weeks to get right.)