ZOREAL Identify
Alternatives to Sign in with Google
Sign in with Google lets a person sign in to a website or app with their Google Account and share profile information, through a hosted JavaScript library, native SDKs and an OpenID Connect ID token. ZOREAL Identify is a "Continue with ZOREAL" button on standard OpenID Connect, backed by the ZOREAL ID credential, that returns a pairwise pseudonymous identifier for a human verified against a government document chip, with the assurance of each login stated in the token. This page sets the two side by side: what each token proves, what personal data it carries, how the identifier behaves across services, and what each costs.
Information last reviewed 10 September 2026. Compared: Sign in with Google (Google Identity Services and its OpenID Connect ID token) with ZOREAL Identify. Google Cloud Identity Platform and Firebase Authentication are on their own page; Google Workspace, Google Cloud identity for employees and Alphabet’s group revenue are out of scope.
Where ZOREAL Identify and Sign in with Google differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
Token claims about the person
Google’s ID token carries email_verified, a flag stating whether Google verified the email address, and hd where the account belongs to a Google Workspace domain; the developer pages state nothing about a document, a face or a live capture. ZOREAL’s ID token states per login how the human was authenticated, in acr and amr: a fresh liveness capture face-matched to the enrolled document, a registered hardware-key approval, or a remembered session, on top of the chip verification recorded at enrolment.
Personal data and the identifier
Google’s token returns email, name, given_name, family_name and picture, and its sub is the Google Account ID, which Google’s pages do not describe as pairwise per relying party. ZOREAL’s ID token carries no personal data: a pairwise pseudonym per sector plus the assurance block, with name, birthdate, document fields and email served only from userinfo to a confidential client with a verified domain, and age returned as yes-or-no thresholds.
What the relying party pays
Google’s developer terms state no fee for Sign in with Google and reserve the right to condition usage beyond documented limits on "additional terms and/or charges" (APIs Terms of Service, September 2026). ZOREAL: Free to enrol, free Tier A logins; only Tier B logins charged; current prices are on the ZOREAL price list at zoreal.com/pricing.
Side by side
Comparison of ZOREAL Identify and Sign in with Google, based on public materials reviewed on 10 September 2026.
| Attribute | ZOREAL Identify | Sign in with Google |
|---|---|---|
| How the identity is bound | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | Proof of control of a Google Account. The credential is a JWT ID token whose sub is "The unique ID of the user’s Google Account"; the integrator verifies the signature, aud, iss and exp (JavaScript API reference; Verify the Google ID token). A document read or a liveness check for the person is not stated in the public materials we reviewed. |
| What the token proves | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | Control of a Google Account. email_verified states whether Google verified the email address, and hd names a Google Workspace domain where present; the token also carries name, given_name, family_name and picture (JavaScript API reference; OpenID Connect guide). |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Google’s developer pages describe verification of the email address (email_verified); verification of the person behind the account is not stated in the public materials we reviewed (Verify the Google ID token; OpenID Connect guide). |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | Google issues the ID token for a Google Account the person created; the token’s sub is the Google Account ID and Google advises integrators to "only use sub field as identifier for the user" (OpenID Connect guide). |
| Personal data in the ID token | None, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain. Age is returned as registered yes-or-no thresholds, never an age or a birth year. | sub, email, email_verified, name, given_name, family_name, picture, hd (Google Workspace domain, if present) and locale, plus iss, aud, exp, iat, nbf and jti (JavaScript API reference; OpenID Connect guide). |
| Identifier across relying parties | One ZOREAL ID serves every service: a returning person at a consented sector approves on their phone without a new capture, or silently when the relying party asks for it; the identifier is stable within the relying party’s registered sector and different at unrelated sectors, so the credential is reused without being linkable across services | sub is "The unique ID of the user’s Google Account" (JavaScript API reference); Google’s pages do not describe it as pairwise per relying party, and a person may hold several Google Accounts. One Tap signs a returning person in from the existing Google session in the browser (Sign in with Google overview). |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | A Google Account is created by the person; a fee for the account is not stated in the public materials we reviewed (Sign in with Google overview, OpenID Connect guide, Google APIs Terms of Service). |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | No fee stated in Google’s developer terms as of September 2026. The Google APIs Terms of Service reserve the right to condition usage beyond documented limits on "additional terms and/or charges" (terms last updated 9 November 2021). |
| Protocol and certification | Standard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. | OpenID Connect and OAuth 2.0; Google states its implementation "conforms to the OpenID Connect specification, and is OpenID Certified" (OpenID Connect guide). ISO or SOC attestations for Google Identity Services specifically are not stated in the public materials we reviewed. |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what Sign in with Google offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and Sign in with Google agree
Sign in with Google is a convenient sign-in that costs the person nothing: one button, a Google Account they already hold, and an identifier with a profile handed to the site. ZOREAL Identify takes the same shape on the sign-in page, a "Continue with ZOREAL" button, and is also free for the person from enrolment onward. Both are OpenID Connect providers with discovery and a signed ID token, so an integrator validates each with the same stock library and the same checks on signature, audience, issuer and expiry.
Both tell the integrator to key the account on sub and never on the email address: Google advises "only use sub field as identifier for the user", and ZOREAL’s ID token carries no email at all. Both instruct the relying party to request the minimum: Google’s OAuth policies require "the smallest set of scopes that are necessary", and ZOREAL’s consent screen shows every requested claim before the person approves and returns only the scopes granted. Neither asserts a legal signature, and neither is KYC.
What differs is the assurance behind the identifier. Google’s token proves control of a Google Account and states whether the email address was verified; ZOREAL’s token states that a human was verified against a government document chip and how this particular login was authenticated. A relying party can run both buttons side by side, because they answer different questions.
ZOREAL Identify may fit you if
- You need to know that a real human verified against a government document chip is behind the account, with the strength of each login stated in acr and amr
- You want an identifier that is stable at your service and different at unrelated services, with no personal data in the ID token
- You want age thresholds and nationality as yes-or-no answers without a birthdate, on the free tier
- You want the pricing structure published: Tier A logins free and unlimited, with a charge only on a Tier B login where identity disclosure is requested
Sign in with Google may fit you if
- You want a returning-user prompt from the existing Google session in the browser (One Tap)
- You need email and name at first sign-in without an extra step, as the ID token carries them
- You want an OpenID Connect implementation that Google states is OpenID Certified, with no fee stated in the developer terms
- You do not need any assurance about the human behind the account beyond an email-verified flag
Other alternatives to Sign in with Google
35 more vendors compared under ZOREAL Identify, from their own public materials.
- Facebook LoginFacebook Login (including Limited Login on iOS)
Meta’s account login for apps and websites: a login dialog returning an app-scoped user ID, name, picture and, if granted, email.
- Pricing
- No fee stated in the Meta Platform Terms as of September 2026; the terms say free is not guaranteed.
- Assurance
- Proves control of a Facebook account and returns the profile’s name and picture. No document check, liveness or email-verified flag is stated.
- Reuse
- An app-scoped user ID per app; a person may hold more than one account.
- Sign in with AppleSign in with Apple (native, Sign in with Apple JS and the REST API)
Apple’s account login for apps and websites: a button backed by the Apple Account’s two-factor authentication, with a one-time name and email share and an optional relay email.
- Pricing
- No separate fee stated; requires Apple Developer Program membership at 99 USD per membership year, as listed on developer.apple.com in September 2026.
- Assurance
- Proves control of an Apple Account and returns a three-valued real user status signal. No document check or liveness is stated.
- Reuse
- The same Apple Account is used across apps; Apple’s pages do not state a uniqueness guarantee per person.
- Microsoft Entra IDMicrosoft identity platform: Microsoft account sign-in, Microsoft Entra External ID and Microsoft Entra ID
Microsoft’s identity platform: consumer Microsoft account and Entra work-account sign-in, plus Entra External ID for customer identity with social and enterprise federation.
- Pricing
- External ID is free for the first 50,000 monthly active users, then per-MAU meters listed at $0.03 (Basic) and $0.01625 (Core) in Microsoft’s retail price list; Entra ID P1 is $7.00 per user per month paid yearly, as listed in September 2026.
- Assurance
- Proves control of a Microsoft or Entra account, with a pairwise subject per application. No document check or liveness is stated for sign-in.
- Reuse
- Microsoft accounts and Entra accounts are reused across applications; Verified ID lets organisations issue reusable verifiable credentials to Microsoft Authenticator.
- Auth0Auth0 by Okta (customer identity platform)
Okta’s Auth0 customer identity platform: hosted login, user database, social and enterprise connections, and OpenID Connect tokens for your app.
- Pricing
- Free up to 25,000 monthly active users; paid plans from $35 per month at 500 MAU (B2C Essentials), Enterprise by contact, as listed on auth0.com in September 2026.
- Assurance
- Whatever the upstream connection proves; identity proofing is available through Marketplace partner integrations, not built in.
- Reuse
- Not an identity network; each tenant holds its own users. Upstream social and enterprise identities are reused through connections.
- Amazon CognitoAmazon Cognito user pools
AWS’s hosted user directory and OAuth 2.0 identity provider: local sign-in, social and SAML or OIDC federation, and JWTs for your app.
- Pricing
- 10,000 monthly active users free on Lite and Essentials, then $0.0055 to $0.020 per MAU by tier; federated users $0.015 per MAU above 50, as listed on aws.amazon.com in September 2026.
- Assurance
- Whatever the local credential or upstream provider proves; no document check or liveness is stated.
- Reuse
- Not an identity network; each user pool is the app’s own directory. Upstream identities are reused through federation.
- Firebase AuthenticationFirebase Authentication, with the Identity Platform upgrade
Google’s Firebase Authentication: backend, SDKs and drop-in UI for email, phone, social and, with Identity Platform, SAML and OIDC sign-in.
- Pricing
- No cost up to 50,000 monthly active users, then from $0.0055 per MAU (Tier 1) and $0.015 per MAU for OIDC and SAML users above 50, as listed by Google in September 2026.
- Assurance
- Whatever the credential or upstream provider proves; no document check or liveness is stated.
- Reuse
- Not an identity network; each project holds its own users. Upstream identities are reused through providers.
Common questions
How we compared
This comparison is based on publicly available information from Sign in with Google’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- Google, Sign in with Google overview: product description, One Tap, personalized button Read 2026-09-10
- Google, Sign in with Google landing: platforms Read 2026-09-10
- Google, GIS JavaScript API reference: credential fields, sub Read 2026-09-10
- Google, Verify the Google ID token: signature, aud, iss, exp, email_verified, hd Read 2026-09-10
- Google, OpenID Connect: OpenID Certified, discovery, claim list, sub advice Read 2026-09-10
- Google, Google APIs Terms of Service: charges for usage beyond documented limits Read 2026-09-10
- Google, OAuth 2.0 Policies: minimum scopes Read 2026-09-10
- ZOREAL pricing (our own published claims) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by Sign in with Google. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.