Stytch vs Authalla
Both of us build passwordless authentication and neither of us charges you to get started. The differences that actually decide this are who owns the company, whether a password exists anywhere in the product, and what you pay on the day you need enterprise SSO.
Read from Stytch’s own public pages on . Prices change; check theirs before you decide.
| What | Stytch | Authalla |
|---|---|---|
| Who owns it | Twilio Inc., San Francisco. Twilio completed the acquisition on 14 November 2025; Stytch’s privacy policy now serves Twilio’s notice. | Authalla Oy, Finland. Owned by founders. No outside investors, no parent company. |
| Where your users’ data sits | United States. Their compliance documentation: “Stytch operates exclusively out of U.S. servers.” EU transfers rely on the Data Privacy Framework. | Hetzner in Helsinki, Finland. Sign-in email goes through Brevo (France), which stores it in Belgium. |
| Passwords | Passwordless-first in the marketing, and a Password product in the docs, with breach checking against HaveIBeenPwned. | None. There is no password option in the product, and no code that could create one. |
| Enterprise SSO and SCIM | Five SSO or SCIM connections included, then $125 per connection per month. | Included in every plan, including the free one. No per-connection fee. |
| Removing their branding | $99, one-off. | Nothing to remove. White-label is in every plan. |
| This scenario: 10,000 users, 3 SSO connections, custom domain, no vendor branding | $0 a month (the free tier covers it, plus a $99 one-off to remove their branding). They are cheaper here and we say so. | €99 a month. |
| Who answers when it breaks | Support plans, escalating with spend. | The founders. Our phone numbers are on this site. |
Stytch is now part of Twilio
Twilio completed its acquisition of Stytch on 14 November 2025. Stytch’s own changelog announced it as a new chapter, and Twilio said what the chapter is for: Stytch would help them “build an intelligent identity layer that anchors the entire Twilio Platform”.
Read that as a customer. The authentication product you are evaluating is now a layer inside a communications platform, sold beside messaging, voice and email. That is Twilio’s stated plan rather than our speculation, and you can see it in the plumbing already: open Stytch’s privacy policy and you land on Twilio’s privacy notice, which gives Twilio Inc., 101 Spear Street, San Francisco as the worldwide headquarters.
Authalla is built the other way round. Authentication is the whole company, and the company is owned by the people who write the code. There is no parent above us that could decide identity should become a feature of something else.
Who can be compelled to hand over your users
There is no EU option to fall back on either. Stytch’s compliance documentation says so itself: “Because Stytch operates exclusively out of U.S. servers”, data localisation within a region is not possible with their service, and transfers out of the EU rely on the Data Privacy Framework. That framework is in force, and under appeal at the EU’s top court. We do not depend on it either way.
A US parent company can also be ordered by a US court to produce data its group controls, wherever that data physically sits. Region settings do not change who receives the order. Authalla has no US parent, no US investors and no US entity. We are a Finnish company, and your users’ identity data is stored on EU-owned servers in Finland. The detail, including the one place data leaves Finland, is on our European page and subprocessor list.
Passwordless, and no passwords
Stytch markets itself on passwordless authentication, as we do, and it also ships a password product. Their own documentation describes it plainly: “Stytch’s Password product allows you to offer a familiar authentication option to your end users”, with breach checking against HaveIBeenPwned for the passwords it stores.
That is what “passwordless” usually means across this industry: passkeys and magic links available alongside the password system. The endpoints exist, the hashing runs, and a setting somewhere decides whether they are used.
We never wrote any of it. Authalla has no password storage, no hashing and no reset flow, and no code path that could add them. We hate the damn things, and the strongest way to say so was to not build them. What that buys you is covered in why we never built passwords.
What you pay, and when
Stytch’s free tier is generous: 10,000 monthly active users and five SSO or SCIM connections, no card. Their pricing page leads with “No feature gating”. The add-on table further down the same page prices each SSO or SCIM connection past the fifth at $125 a month, removing their branding at $99, and device fingerprints past 10,000 at half a cent each.
Ours is €0 up to 1,000 users, €99 to 10,000 and €199 to 20,000, and every product feature is in every plan, free included. Enterprise SSO, SCIM, custom domains, white-label and audit logs cost nothing extra, at any size, because support depth is the only difference between our tiers.
So compare the two on the day you need something, as well as the day you sign up. At 10,000 users with three enterprise connections and your own domain, Stytch is free and we are €99 a month. At the same size on Clerk it is around $175, on WorkOS $474 and on Auth0 $2,100. The full scenario is on our pricing page, priced from each vendor’s own page.
Set up by your agent, backed by the founders
Connect our MCP server and your coding agent configures the tenant, clients, domains and branding while you describe what you want. There is no API key to paste into a .env file: the agent signs in through the browser with OAuth, and your first sign-in creates the account.
When you need help, the people who wrote it answer. Our phone numbers are on this site.