Best European Alternatives to Okta

Looking for a European or self-hosted alternative to Okta? Okta is a US-based identity provider that stores sensitive authentication data on American servers. For organizations with data sovereignty requirements, compliance needs, or those preferring self-hosted solutions, there are excellent alternatives.

We've curated the best open-source and European identity management solutions. These alternatives offer SSO, MFA, user management, and API access while keeping your identity data under your control or within EU jurisdiction.

4 Alternatives
100% Open Source
How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy

Why Choose an Alternative to Okta?

Data Sovereignty

Keep identity data on your servers or in EU data centers under your control.

Open Source

Audit the code, customize features, and avoid vendor lock-in.

Cost Savings

Self-hosted solutions can significantly reduce per-user licensing costs.

GDPR Compliance

European providers and self-hosting ensure full compliance with EU regulations.

Best Alternatives to Okta

We've curated the best open-source and European identity management solutions. Each alternative has been evaluated for features, scalability, and compliance capabilities.

Keycloak

Enterprise-grade open-source identity management by Red Hat

#1 for replacing Okta
Self-hosted

Zitadel

Swiss identity infrastructure with cloud and self-hosted options

#2 for replacing Okta
Switzerland

Authentik

Flexible open-source identity provider for any application

#3 for replacing Okta
Self-hosted

Ory

German open-source identity infrastructure for developers

#4 for replacing Okta
Germany

Feature Comparison: Okta vs Alternatives

Feature Okta Keycloak Zitadel Authentik
Headquarters USA Self-hosted Switzerland Self-hosted
Open Source No Yes Yes Yes
Self-Hosting No Yes Yes Yes
EU Cloud Option Partial Self-host Yes Self-host
Free Tier Limited Unlimited Yes Unlimited
SSO/SAML Yes Yes Yes Yes
MFA Yes Yes Yes Yes

Key takeaways

  • Okta charges per employee per month, billed a year at a time, with a $1,500 minimum annual contract, so there is no way to try it at small scale.
  • Single sign-on and multi-factor start at $6 per user per month; adaptive MFA, lifecycle management and governance sit at $17.
  • European storage exists: orgs in the EMEA cell run on okta-emea.com, which is visible in the org URL.
  • The October 2023 incident involved the support case management system rather than the production service, and Okta says so plainly — the useful lesson is about vendor support channels, not about product security.
  • None of the open-source options on this page replaces access certification campaigns, which is the one Okta capability that has no equivalent here.

Why people leave Okta

Okta is bought by an IT department, not by a developer, and that shapes every complaint about it. It is the directory that employees log into, the place where joiners and leavers are processed, and the thing sitting in front of the forty SaaS products the company already pays for. When it works nobody notices, which is why the objections are almost never about features.

The first objection is the licence. Suites are billed annually with a $1,500 minimum annual contract, starting at $6 per user per month for single sign-on, multi-factor and the directory. The tier that carries adaptive MFA, lifecycle management, privileged access and governance is $17 per user per month. A sixty-person company that decided it wanted adaptive MFA has committed to roughly twelve thousand dollars a year, up front, for a year.

The second is harder to price. On 20 October 2023 Okta disclosed that someone had got into its support case management system and viewed files customers had uploaded to support cases — HAR files, which can carry session cookies and tokens.

Okta’s own account is clear that this system is separate from the production service and that production was unaffected, and that matters: the lesson is not carelessness. It is that when identity is a subscription, the vendor’s help desk is part of your attack surface, and nothing you configure in your own tenant changes that.

  • The security features are in the expensive tier Single sign-on, multi-factor and the universal directory arrive at $6 per user per month. Adaptive multi-factor, lifecycle management, privileged access and access governance arrive at $17. The gap is exactly the set of controls a security team asks for after its first audit, so the upgrade is not optional in practice, and the bill nearly triples for the same headcount doing the same work.
  • You commit for a year before you start Every suite is billed annually, with a $1,500 minimum annual contract for Workforce Identity. That is a floor rather than a fortune, and it still rules out the way most technical decisions now get made: run it for a month, see whether the team adopts it, cancel if it does not. An open-source identity server can be stood up on a Thursday and thrown away on a Friday.
  • Your vendor’s support desk is in scope In October 2023 the files customers had attached to support tickets were readable by an intruder, and HAR captures routinely contain live session material. Okta revoked the embedded session tokens and stated that the production service was separate and untouched. Take that at face value and the structural point survives: outsourcing identity means a second organisation holds artefacts about your logins, and its ticketing system is now part of your threat model.
  • The corporate jurisdiction does not move Okta, Inc. operates from 100 First Street in San Francisco and certifies under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. framework alongside it. There is a European cell, so European storage is real and available. Legal reach follows incorporation rather than hosting, which is why a company with a European establishment requirement ends up on a page like this one regardless of which cell its org runs in.

What you have to replace, not just match

Okta does four separate jobs and the alternatives here cover them unevenly, so the first task is deciding which of the four you are actually paying for.

One is the employee directory and the federation into it, usually Active Directory or Entra ID, which everything on this page can do. Two is single sign-on into third-party SaaS applications, which depends almost entirely on how many of those applications speak SAML or OIDC. Three is lifecycle management: accounts created when someone is hired and removed when they leave, pushed outwards into those SaaS products. Four is governance — access reviews, certification campaigns, privileged sessions.

The honest picture is that jobs one and two are well covered by open-source identity servers, job three is covered thinly and by extension rather than by default, and job four is barely covered at all. If your Okta subscription exists because an auditor asked for quarterly access certification, no tool on this page replaces it, and you should say so internally before starting.

The alternatives compared

European Okta alternatives, in the order this page ranks them, compared on headquarters, pricing and jurisdiction
PositionToolHeadquartersPricingJurisdiction
#1 Keycloak London, United Kingdom Free and open source Self-hosted; project governance is international
#2 Zitadel St. Gallen, Switzerland Free tier / from €100 per month Switzerland (adequacy decision, outside the EEA)
#3 Authentik Hamburg, Germany Free and open source / Enterprise available Self-hosted; German origins
#4 Ory Munich, Germany Free tier / from €29 per month (Ory Network) EU (Germany)

How each alternative compares to Okta

#1

Keycloak

the one that already fits an organisation with a directory

London, United KingdomFree and open source#1 in Identity Management

  • Which law reaches it. Self-hosted; project governance is international. Okta is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Wherever you deploy it.
  • Source code. Open source, where Okta is not: you can read what it does rather than take the description on trust.
  • Independently checked. GDPR — you remain the controller.

Best for: Companies whose Okta tenant is mostly Active Directory plus single sign-on

Keycloak is Apache 2.0 and a CNCF incubating project since April 2023, and it is the only tool here that was designed from the start for the situation Okta sells into: an established organisation with a directory, a mixture of old and new applications, and a compliance function asking about step-up authentication.

Against the Okta licence the comparison is stark. A thousand employees on the Starter Suite is six thousand dollars a month; the same thousand on the Essentials Suite is seventeen thousand. Keycloak has no seat count, no annual minimum and no tier where adaptive policies begin. Whatever you deploy applies to everyone, and the invoice is for hardware.

The two things you will miss are both about convenience rather than capability. Okta’s catalogue of pre-built application integrations means connecting a SaaS product is a search rather than a reading exercise, and Okta ships a first-party push authenticator that employees install and forget. Keycloak supports TOTP and hardware keys and does not hand you a branded phone app.

What Keycloak does better than Okta

  • No per-employee licence at all, against $6 per user per month for the entry suite and $17 for the one with adaptive MFA
  • No minimum annual contract, so it can be trialled for a week and abandoned without a procurement conversation
  • Step-up and conditional authentication policies are available to everyone rather than gated behind the higher tier
  • LDAP and Active Directory federation keeps the existing directory authoritative, which is the whole workforce migration in one feature
  • Nobody outside your organisation holds support artefacts about your login configuration

Where Keycloak is a step down from Okta

  • No catalogue of thousands of ready-made application integrations, so each SaaS connection is mapped by hand
  • No first-party push authenticator app of the kind employees are used to approving on a phone
  • Outbound provisioning into third-party applications is extension work, not the lifecycle product Okta sells
  • Your team owns upgrades and availability for the system every employee logs into every morning

Standout against Okta. Conditional and step-up authentication are simply available, where Okta puts adaptive MFA in the tier that costs nearly three times as much per employee.

keycloak.org Visit Keycloak
#2

Zitadel

the managed option for organisations that want a vendor, just not this one

St. Gallen, SwitzerlandFree tier / from €100 per month#3 in Identity Management

  • Which law reaches it. Switzerland (adequacy decision, outside the EEA). Okta is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Switzerland, or self-hosted.
  • Source code. Open source, where Okta is not: you can read what it does rather than take the description on trust.
  • Independently checked. GDPR-adequate.

Best for: Teams who accept paying a supplier but need the supplier outside American reach

Zitadel is a Swiss company, its code is open source, and its managed service has a free tier with paid plans beginning at €100 a month. It is the answer for an organisation that has concluded, correctly, that it has nobody to run an identity server, but does not want the company running it to be incorporated in California.

Its event-sourced design reads differently after an incident like 2023. Every change to identity state is kept as an immutable event rather than as a row that was updated, so the question auditors ask afterwards — what changed, when, and who caused it — is answered from the store itself instead of from log retention somebody hopes was long enough.

It is not a workforce identity platform in Okta’s sense, and that should decide whether it is on your shortlist. There is no application integration catalogue, no outbound provisioning product, and no governance module. It authenticates people and federates protocols very well, and stops there.

What Zitadel does better than Okta

  • Swiss company under an adequacy decision, with no United States parent in the contract
  • Priced from a monthly plan rather than per employee seat, so hiring does not add licences to an invoice
  • An immutable event record of identity changes, which answers the audit question without depending on log retention
  • Open source, so a managed subscription can become a self-hosted deployment without changing product
  • No annual commitment of the kind Okta requires before the first login

Where Zitadel is a step down from Okta

  • Nothing resembling Okta’s lifecycle management for provisioning accounts into other systems
  • No pre-built integration catalogue, so third-party applications are configured manually
  • Outside the EEA, which is a problem only if your rules demand EU establishment rather than adequacy
  • Aimed at application identity more than at employee directories, so Active Directory synchronisation is not its strength

Standout against Okta. It is the only tool here that keeps the vendor relationship Okta customers actually want while moving the vendor outside American jurisdiction.

zitadel.com Visit Zitadel
#3

Authentik

the one for estates full of software that cannot log in on its own

Hamburg, GermanyFree and open source / Enterprise available#4 in Identity Management

  • Which law reaches it. Self-hosted; German origins. Okta is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Wherever you deploy it.
  • Source code. Open source, where Okta is not: you can read what it does rather than take the description on trust.
  • Independently checked. GDPR.

Best for: Organisations whose Okta bill is mostly about internal tools and legacy applications

Authentik comes out of Hamburg, is free to self-host with an enterprise licence available, and earns its ranking here on one capability: it can put an authentication step in front of an application that has no authentication of its own. For a company whose internal estate includes an old reporting tool, a vendor appliance and three services somebody built in 2016, that is the part Okta was being paid for.

The other reason it belongs on an Okta page is the SSO surcharge. A large share of business software charges extra for SAML, so a company paying per employee for Okta is often also paying per application for the privilege of connecting it. A reverse proxy that authenticates before the request reaches the application sidesteps that entirely for anything you host yourself.

Its login behaviour is assembled from stages rather than chosen from a list, so an unusual requirement — an approval step during enrolment, a different path for contractors — is configuration rather than a support ticket. The price is that you are building the flow yourself, and that there is no managed service to fall back on when you would rather not.

What Authentik does better than Okta

  • A proxy that adds a login to software that never supported one, which no Okta licence tier can do for an application with no federation
  • Free to self-host at any headcount, against an annual per-employee commitment
  • Authentication behaviour assembled from stages, so unusual enrolment and recovery requirements are configured rather than requested
  • German origins and a deployment you place wherever you like, so no supplier holds a copy of your directory or your login configuration
  • Avoids paying a vendor SSO surcharge for internally hosted applications by authenticating in front of them

Where Authentik is a step down from Okta

  • No first-party managed service, so there is no option to pay someone else to run it
  • The project comes out of Hamburg but the enterprise licence is sold by Authentik Security Inc., a company registered in Philadelphia, so buying support puts an American counterparty back in the contract that self-hosting the open-source build keeps out
  • A smaller ecosystem and far fewer worked examples than Okta has accumulated
  • Governance and access certification are absent, which for an audited organisation is the whole reason Okta is there
  • Less depth in fine-grained authorisation than Keycloak, let alone Okta’s privileged access product

Standout against Okta. It solves the applications Okta cannot help with at all — the ones with no federation support — and it does it without a per-employee licence.

goauthentik.io Visit Authentik
#4

Ory

excellent software, aimed at a different problem from the one Okta solves

Munich, GermanyFree tier / from €29 per month (Ory Network)#2 in Identity Management

  • Which law reaches it. EU (Germany). Okta is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Self-hosted, or Ory Network.
  • Source code. Open source, where Okta is not: you can read what it does rather than take the description on trust.
  • Independently checked. GDPR.

Best for: Teams whose Okta contract is really covering a customer-facing product

Ory Corp is in Munich and licences its components under Apache 2.0, with Ory Network available from €29 a month above a free tier. It is composable by design: identity and user management, an OAuth 2.0 and OpenID Connect server, a permissions service and a policy gateway, deployed separately.

It sits last here for an honest reason. Okta is a workforce product — employees, a directory, joiners and leavers, single sign-on into purchased software — and Ory is built for the people who use your own application. There is no employee directory, no application catalogue, no provisioning into SaaS tools, and no governance layer.

Where it becomes the right answer is when the Okta contract turns out to be covering the wrong thing: a customer-facing portal, a partner login, an API that third parties call. That work does not need a workforce licence, and paying an employee seat price for it is how these contracts quietly inflate.

What Ory does better than Okta

  • German company and German law, with no American parent and no annual commitment
  • Licensed under Apache 2.0, so the managed plan at €29 a month is one option rather than the only one, and neither route charges per employee
  • Relationship-based permissions go further than role assignment for customer and partner access
  • You deploy only the components you use, instead of licensing a suite whose upper half is there for the audit
  • Nothing about the pricing changes when your organisation hires fifty people

Where Ory is a step down from Okta

  • Not a workforce identity product: no employee directory, no joiner and leaver handling
  • No catalogue of SaaS integrations, which is most of what an Okta administrator touches
  • No governance, access review or privileged access capability whatsoever
  • Assumes you build the interface, where Okta administrators configure one

Standout against Okta. It is the only tool here that will tell you, by not fitting, that part of your Okta contract was never a workforce problem.

ory.sh Visit Ory

What actually breaks when you switch

Second factors are the visible cost and they land on everyone on the same day. Push approvals, authenticator secrets and registered security keys stay with the identity provider that issued them, so every employee enrols again on the new system.

Run the two providers side by side for a fortnight, enrol people as they arrive, and keep the old tenant alive until the stragglers are through — a single hard cutover produces a queue at the service desk that nobody forgets.

The quieter failure is provisioning. If accounts are currently created in connected applications when somebody is hired and disabled when they leave, that mechanism does not come across, and its absence is invisible until a leaver still has a mailbox three weeks later. Write down every system that is currently provisioned automatically, and decide for each one whether it becomes a script, a separate provisioning tool, or a manual step on a checklist.

Then there is the audit programme. Access reviews, certification campaigns and the reports produced for them are usually built around whatever the incumbent exports, and none of the tools here produces them. Talk to whoever signs off those reviews before the contract renewal date rather than after, because the answer may be that you keep a governance product and replace only the login.

Does self-hosting actually reduce risk, or just move it?

It moves it, and the direction is the whole argument. Running your own identity server removes an external organisation that holds material about your logins, keeps support tickets about your configuration, and has a help desk that can be targeted instead of you. The 2023 incident is the clean illustration: the production service was fine and the support system was the way in.

What you take on instead is patching. An identity server exposed to the internet and left on an old release is a worse outcome than any managed service, and the failure mode is silent. Okta patches on a Tuesday whether or not your team is busy.

The decision therefore rests on one question that has nothing to do with software: is there a named person whose job includes this system, with a deputy. If the answer is no, the subscription is buying something real.

Will I keep single sign-on into all our SaaS tools?

Mostly, with two caveats worth checking before you sign anything. The first is protocol support: any application offering SAML 2.0 or OpenID Connect federates with Keycloak, Authentik or Zitadel without special handling, which today covers the large majority of business software.

The second is the catalogue. Okta ships thousands of pre-built application integrations, so connecting a given product is often a search box and two fields rather than reading its documentation and mapping claims by hand. With an open-source server you do the mapping. It is an hour per application rather than a blocker, but multiply it by the number of applications before you estimate the project.

The applications that genuinely resist are the ones with no federation at all. That is where Authentik’s proxy earns its place, because it puts a login in front of something that never had one.

What about joiners, movers and leavers?

This is where the comparison gets uncomfortable. Okta’s lifecycle management pushes account creation, attribute updates and deactivation outwards into connected applications, and it is a large part of why organisations with real HR churn stay.

Keycloak and Authentik are both strong at the inbound half — reading from LDAP or Active Directory, keeping the existing directory authoritative — and they differ on the outbound half. Authentik speaks SCIM, so pushing accounts into an application that also speaks SCIM is configuration. Keycloak has no equivalent by default, so outbound provisioning is extension work or a separate provisioning tool, and neither of them matches the breadth of connectors Okta sells as lifecycle management.

If someone leaving the company currently loses access to thirty systems automatically, write down what replaces that mechanism before you cancel, because the day this quietly stops working is the day a former employee still has a mailbox.

Is the European cell enough for our compliance team?

It depends which requirement you are answering, and the two are often confused in the same meeting. If the requirement is that employee records are processed in Europe, the EMEA cell answers it, and the org URL on okta-emea.com is the evidence.

If the requirement is that no company outside the union can be ordered to produce those records, the cell does not answer it. Okta, Inc. is in San Francisco and relies on the EU-U.S. Data Privacy Framework for transfers, so the obligation attaches to the company rather than to the data centre.

A useful test: ask whether the rule was written by procurement or by risk. Procurement rules about location are satisfied by the cell. Risk assessments about foreign compulsion are not, and no configuration setting will change that.

Which one to pick

If you have a real directory and a mixed estate of applications, Keycloak is the replacement that was built for your shape of organisation, and the money it saves is the difference between a per-employee suite and a server.

If a meaningful share of what Okta does for you is putting a login in front of internal software that has none, Authentik does that specific job better than anything else here, and it removes the vendor SSO surcharge on anything you host yourself.

If the conclusion is that nobody in the building should be running the identity server, Zitadel keeps the managed relationship and moves the supplier to St. Gallen. That is a smaller change than it sounds and it answers the jurisdiction question honestly.

And if your obligation is quarterly access certification, none of this replaces Okta. Move the authentication if you want to, keep a governance product, and be clear with your auditor that you have split one subscription into two things rather than removed it.

Frequently Asked Questions

Keycloak if you have a real Active Directory and a mixed estate, because it is the one built for that shape of organisation. Authentik if a sizeable part of your Okta bill covers internal applications that were never designed to federate. Zitadel if you want somebody else to run it but not somebody American. Ory is on this page for completeness and is aimed at a different job entirely.

The Starter Suite is $6 per user per month and covers single sign-on, multi-factor and the universal directory. The Essentials Suite is $17 and adds adaptive MFA, privileged access, lifecycle management and access governance, with a Core Essentials option at $14. All suites are billed annually and Workforce Identity carries a $1,500 minimum annual contract.

It can. Okta runs an EMEA cell alongside its American ones, and an org hosted there is visible in its own URL because the domain ends in okta-emea.com rather than okta.com. That settles where records live. The company behind it is still headquartered at 100 First Street in San Francisco, and cross-border transfers still rest on the Data Privacy Framework certification.

On 20 October 2023 Okta disclosed that an intruder had accessed its support case management system and viewed files customers had uploaded to support cases. Those included HAR files, which can contain session cookies and tokens, and Okta revoked the embedded session tokens and contacted affected customers. Okta stated that the support system is separate from the production service and that production was not impacted.

Yes, and they are sold as different products to different buyers. Okta’s privacy policy names Auth0 LLC and Auth0 International LLC among its subsidiaries. Okta is licensed per employee per month on an annual contract; Auth0 is priced by monthly active users on its own site. Replacing one does not tell you much about replacing the other.

Not really, and this is the clearest gap on the page. Periodic access reviews, certification campaigns and segregation-of-duties reporting are what Okta sells as identity governance, and Keycloak, Authentik, Zitadel and Ory all stop short of it. Organisations under that kind of audit obligation usually pair an open-source identity server with a separate governance tool rather than replacing Okta with one product.

Keycloak and Authentik both do, and it matters more than any other feature for a workforce migration, because it means the existing directory stays authoritative and nobody re-creates a thousand accounts by hand. Zitadel federates through standard protocols rather than acting as a directory synchroniser. Check the attribute mapping carefully during a trial; this is where workforce migrations lose their weekends.

Second-factor re-enrolment, and it lands on every employee at once. Push approvals, registered security keys and authenticator secrets do not migrate between identity providers, so each person re-enrols on a date you choose. Add the application integrations you now map by hand, and the provisioning that used to happen automatically when somebody was hired, and the true cost is staff hours rather than licences.

For a company under a hundred people, with a directory to federate and fifteen applications speaking SAML, a month of part-time work plus a re-enrolment week. For an organisation with outbound provisioning into dozens of systems, custom integrations and an audit programme built around Okta reports, plan for two quarters and expect to keep a governance tool in the budget.

Who worked on this review

Three people touch every comparison page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Marta Kowalczyk
Written by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Daniel Brandt
Edited by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Sebastiaan Smits
Fact-checked by

Sebastiaan Smits

Founder & Editor · Netherlands

Selects the tools, writes the reviews, and checks where each company is actually established.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Explore More European Alternatives

Discover privacy-focused European alternatives to other popular US tech services.

1Password Alternatives Authy Alternatives AWS Alternatives Browse All Categories