ZOREAL Identify
Alternatives to Auth0
Auth0 describes itself as "A flexible, drop-in solution to add authentication and authorization services" to applications: it hosts the login page, the user database and token issuance, and signs people in from its own database, from social providers or from enterprise connections. ZOREAL Identify is a "Continue with ZOREAL" button on standard OpenID Connect, backed by the ZOREAL ID credential, that returns a pairwise pseudonymous identifier for a human verified against a government document chip, with the assurance of each login stated in the token. This page sets the two side by side: where each sits in the stack, what each token proves about the person, how identity proofing enters, and what each costs.
Information last reviewed 10 September 2026. Compared: Auth0 by Okta, the customer identity platform, with ZOREAL Identify. Okta Workforce Identity (employee SSO), Auth0’s Marketplace partners as products in their own right, and Okta’s group revenue are out of scope.
Where ZOREAL Identify and Auth0 differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
Different layers of the stack
Auth0 is the relying party’s authentication server: it authenticates against its own database or an upstream connection (social, SAML, OIDC, ADFS, LDAP, Entra ID, Google Workspace, Okta, PingFederate) and issues its own tokens, so what the token proves is what the upstream connection proved. ZOREAL is an upstream OpenID Connect provider: a relying party on Auth0 can add "Continue with ZOREAL" as a custom OpenID Connect connection, keep Auth0’s session and user store, and receive ZOREAL’s assurance claims in the upstream token.
Where identity proofing lives
Auth0 states that "Identity Proofing services offered by our partners are implemented as Auth0 Rules": a Marketplace partner (the 2022 post names ID DataWeb, Persona, Incognia, Onfido and Vouched) redirects the person and returns a result that is stored on the profile. ZOREAL builds the document chip read, the face match and the liveness capture into enrolment, and states per login in acr and amr whether a fresh capture, a registered hardware key or a remembered session authenticated this session.
Per user, or only when disclosing
Auth0’s Free plan covers "Up to 25,000" monthly active users with "Unlimited Social Connections"; Essentials B2C is "from $35/month" at 500 MAU, Professional B2C "from $240/month", Enterprise by contact (auth0.com/pricing, USD, September 2026). ZOREAL: Free to enrol, free Tier A logins; only Tier B logins charged; there is no per-MAU meter, and current prices are on the ZOREAL price list at zoreal.com/pricing.
Side by side
Comparison of ZOREAL Identify and Auth0 by Okta, based on public materials reviewed on 10 September 2026.
| Attribute | ZOREAL Identify | Auth0 |
|---|---|---|
| Role in the stack | An upstream OpenID Connect identity provider at id.zoreal.com; the relying party redirects, the holder approves on their phone, and a stock OIDC library validates the ID token against ZOREAL’s JWKS. ZOREAL is not an authentication server for the relying party’s own users. | The authentication server for the relying party’s users: "A flexible, drop-in solution to add authentication and authorization services to your applications", hosting the login page, the user database and token issuance (Auth0 overview). |
| How the identity is bound | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | Auth0 authenticates a user against its own database (username and password, passwordless) or an upstream connection (social, or enterprise: SAML, OpenID Connect, ADFS, LDAP, Entra ID, Google Workspace, Okta, PingFederate) and issues its own tokens to the application (Auth0 overview; Enterprise identity providers). A first-party document check or liveness is not stated in the public materials we reviewed. |
| What the token proves | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | Whatever the upstream connection proved: a password, a social account, an enterprise SSO session. Where a Marketplace proofing partner is wired in, its result is returned through an Auth0 Rule at login (Auth0 overview; Marketplace identity proofing post). |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Not stated as Auth0’s own in the public materials we reviewed; "Identity Proofing services offered by our partners are implemented as Auth0 Rules" (Marketplace identity proofing post, 21 March 2022, still live September 2026). |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | Auth0 issues its own OpenID Connect tokens for the relying party’s users, from its database or an upstream connection; any proofing credential comes from the Marketplace partner that ran the check (Auth0 overview; Marketplace identity proofing post). |
| Identity proofing | Built into enrolment (document photographed, machine-readable zone read, chip read over NFC and verified server-side, flash-plus-zoom liveness capture face-matched 1:1 to the chip portrait) and, on request through acr_values, into a login: a live floor requires a presence attestation minted after scoring a fresh capture, and a pairing that cannot meet its floor is denied, never downgraded. | Through Marketplace partner integrations (ID DataWeb, Persona, Incognia, Onfido and Vouched named in the 2022 post), run as Auth0 Rules at login; not a built-in Auth0 feature (Marketplace identity proofing post). |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | The relying party’s users are created in Auth0’s database or arrive through a connection; the Free plan covers "Up to 25,000" monthly active users at $0 with no credit card required (auth0.com/pricing, USD, September 2026). Any Marketplace proofing partner’s fee is not stated on the Auth0 pages we reviewed. |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | Priced per monthly active user, not per sign-in. Free up to 25,000 MAU; Essentials B2C "from $35/month" and Essentials B2B "from $150/month" at 500 MAU; Professional B2C "from $240/month" and Professional B2B "from $800/month" at 500 MAU; Enterprise "Contact us". Yearly billing is eleven times monthly (auth0.com/pricing, USD, self-service, September 2026). |
| Standards and compliance | OpenID Connect and OAuth 2.0 from the provider at id.zoreal.com. Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. | OAuth 2.0, OpenID Connect and SAML (Auth0 overview; Enterprise identity providers). The overview states Auth0 helps organisations maintain compliance with "SOC 2, GDPR, PCI DSS, HIPAA"; ISO 27001 and OpenID Certified status are not stated in the public materials we reviewed. |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Auth0 offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and Auth0 agree
Auth0 gives a relying party a hosted, convenient sign-in for its users at no cost up to 25,000 monthly active users, with the identities of Google, Apple, Facebook and enterprise directories reused through connections and an identifier plus profile handed to the app. ZOREAL Identify is also free for the person from enrolment onward and free for basic sign-ins on every plan. Both are OpenID Connect and OAuth 2.0, and both hand the relying party a signed token to validate with a stock library.
The two are not rivals for the same slot. Auth0 is the authentication server; ZOREAL is an identity provider that Auth0 can consume as a custom OpenID Connect connection, next to the social and enterprise connections it already hosts. A relying party that adds ZOREAL keeps Auth0’s session, user database and MFA and gains ZOREAL’s assurance claims in the upstream token. Neither asserts a legal signature, and neither is KYC.
What differs is the assurance behind the identifier and where it comes from. Auth0’s token carries whatever the upstream connection proved, and identity proofing is a Marketplace partner step whose result is stored on the profile; ZOREAL’s token states that a human was verified against a government document chip and how this particular login was authenticated.
ZOREAL Identify may fit you if
- You need to know that a real human verified against a government document chip is behind the account, with the strength of each login stated in acr and amr rather than a one-time proofing result stored on a profile
- You want a pairwise identifier per sector and no personal data in the ID token
- You want age thresholds and nationality as yes-or-no answers without a birthdate, on the free tier
- You want Tier A logins free without limit and a charge only on a Tier B login where identity is disclosed, rather than a per-MAU plan
Auth0 may fit you if
- You need a hosted authentication server with a user database, MFA and enterprise SSO (SAML, OIDC, ADFS, LDAP, Entra ID, Google Workspace, Okta, PingFederate) in one product
- You want unlimited social connections and up to 25,000 monthly active users on the free plan
- You already run Okta for the workforce and want customer identity from the same vendor
- You want identity proofing as an optional partner step at login rather than as the identity provider itself
Other alternatives to Auth0
35 more vendors compared under ZOREAL Identify, from their own public materials.
- Sign in with GoogleSign in with Google (Google Identity Services)
Google’s account login for websites and apps: a button, One Tap, and an OpenID Connect ID token carrying the Google Account ID, email, name and picture.
- Pricing
- No fee stated in Google’s developer terms as of September 2026; usage beyond documented limits may carry additional terms or charges.
- Assurance
- Proves control of a Google Account; the token flags whether Google verified the email address. No statement about the person behind the account.
- Reuse
- The same Google Account ID is presented to every relying party; a person may hold several accounts.
- Facebook LoginFacebook Login (including Limited Login on iOS)
Meta’s account login for apps and websites: a login dialog returning an app-scoped user ID, name, picture and, if granted, email.
- Pricing
- No fee stated in the Meta Platform Terms as of September 2026; the terms say free is not guaranteed.
- Assurance
- Proves control of a Facebook account and returns the profile’s name and picture. No document check, liveness or email-verified flag is stated.
- Reuse
- An app-scoped user ID per app; a person may hold more than one account.
- Sign in with AppleSign in with Apple (native, Sign in with Apple JS and the REST API)
Apple’s account login for apps and websites: a button backed by the Apple Account’s two-factor authentication, with a one-time name and email share and an optional relay email.
- Pricing
- No separate fee stated; requires Apple Developer Program membership at 99 USD per membership year, as listed on developer.apple.com in September 2026.
- Assurance
- Proves control of an Apple Account and returns a three-valued real user status signal. No document check or liveness is stated.
- Reuse
- The same Apple Account is used across apps; Apple’s pages do not state a uniqueness guarantee per person.
- Microsoft Entra IDMicrosoft identity platform: Microsoft account sign-in, Microsoft Entra External ID and Microsoft Entra ID
Microsoft’s identity platform: consumer Microsoft account and Entra work-account sign-in, plus Entra External ID for customer identity with social and enterprise federation.
- Pricing
- External ID is free for the first 50,000 monthly active users, then per-MAU meters listed at $0.03 (Basic) and $0.01625 (Core) in Microsoft’s retail price list; Entra ID P1 is $7.00 per user per month paid yearly, as listed in September 2026.
- Assurance
- Proves control of a Microsoft or Entra account, with a pairwise subject per application. No document check or liveness is stated for sign-in.
- Reuse
- Microsoft accounts and Entra accounts are reused across applications; Verified ID lets organisations issue reusable verifiable credentials to Microsoft Authenticator.
- Amazon CognitoAmazon Cognito user pools
AWS’s hosted user directory and OAuth 2.0 identity provider: local sign-in, social and SAML or OIDC federation, and JWTs for your app.
- Pricing
- 10,000 monthly active users free on Lite and Essentials, then $0.0055 to $0.020 per MAU by tier; federated users $0.015 per MAU above 50, as listed on aws.amazon.com in September 2026.
- Assurance
- Whatever the local credential or upstream provider proves; no document check or liveness is stated.
- Reuse
- Not an identity network; each user pool is the app’s own directory. Upstream identities are reused through federation.
- Firebase AuthenticationFirebase Authentication, with the Identity Platform upgrade
Google’s Firebase Authentication: backend, SDKs and drop-in UI for email, phone, social and, with Identity Platform, SAML and OIDC sign-in.
- Pricing
- No cost up to 50,000 monthly active users, then from $0.0055 per MAU (Tier 1) and $0.015 per MAU for OIDC and SAML users above 50, as listed by Google in September 2026.
- Assurance
- Whatever the credential or upstream provider proves; no document check or liveness is stated.
- Reuse
- Not an identity network; each project holds its own users. Upstream identities are reused through providers.
Common questions
How we compared
This comparison is based on publicly available information from Auth0’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- Auth0, Pricing: plans, MAU, add-ons, yearly billing Read 2026-09-10
- Auth0, Overview: what it is, standards, compliance statement Read 2026-09-10
- Auth0, Social identity providers: Marketplace category Read 2026-09-10
- Auth0, Enterprise identity providers: connection types Read 2026-09-10
- Auth0, Add Identity Proofing through Auth0 Marketplace (21 March 2022) Read 2026-09-10
- ZOREAL pricing (our own published claims) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Auth0. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.