Identity

WorkOS Enterprise Identity APIs

Standalone APIs for adding enterprise SSO and directory synchronization to an existing application identity system.

Editorial verdict

Choose the standalone WorkOS APIs when an application already owns authentication and needs to add enterprise federation or directory provisioning without replacing it.12

Best for

  • Products keeping an existing authentication system
  • B2B teams adding SAML or OIDC enterprise connections
  • Applications that need SCIM or directory-driven lifecycle data
12

Not ideal for

  • New products seeking a complete managed authentication default
  • Teams that do not yet have a validated enterprise identity requirement
  • Applications that need self-hosted federation infrastructure
12
Main trade-off

WorkOS isolates difficult enterprise protocols behind focused APIs, but every production connection creates recurring cost and an operational customer-onboarding surface.123

Product boundary

Decide whether to augment the current authentication system with standalone enterprise SSO and directory APIs.

This entry covers WorkOS Single Sign-On and Directory Sync as standalone Enterprise Identity APIs; it excludes AuthKit's managed sign-in, session, and user-management replacement path.123

For: B2B SaaS teams with an existing authentication layer and validated enterprise federation or provisioning demand

  • The application needs a new authentication system rather than an enterprise add-on
  • Only one protocol is required and the team can support it directly
  • Customer connection volume changes the unit economics
  • No contracted customer requires federation or provisioning yet

Why teams consider WorkOS Enterprise Identity APIs

  • Focused enterprise APIsSSO and Directory Sync can be adopted without moving the application's existing authentication layer.12
  • Protocol normalizationThe application integrates one API surface across supported enterprise identity providers and directories.12
  • Incremental adoptionTeams can add federation or provisioning only when contracted customers require it.12

Pricing

Per-production-connection pricing with published volume discounts for SSO and Directory Sync3

Add SSO

Single Sign-On — $125/connection/month for 1–15 connections

Published volume tiers fall to $100, $80, and $65 per connection as connection count increases.3

Add provisioning

Directory Sync — $125/connection/month for 1–15 connections

Directory Sync uses the same published connection tiers as SSO.3

Production boundary
Production connections are billable; staging connections are free.3
Volume tiers
Published per-connection rates decline at 16, 31, and 51 connections.3
Pricing checked View official pricing

WorkOS Enterprise Identity APIs vs alternatives

WorkOS AuthKit

Choose when
WorkOS should also own sign-in, sessions, users, and organizations.
Compared with WorkOS Enterprise Identity APIs
The integration becomes a full authentication decision rather than an enterprise add-on.56

Auth0

Choose when
Enterprise connections should live inside a broader CIAM platform.
Compared with WorkOS Enterprise Identity APIs
The team adopts a larger platform and its configuration model.78

Frontegg

Choose when
B2B tenant administration and embedded customer-facing management are also required.
Compared with WorkOS Enterprise Identity APIs
The product boundary is broader than focused federation APIs.910

Resources and sources

Official resources

  • WorkOS Single Sign-On
    Open
  • WorkOS Directory Sync
    Open
  • WorkOS pricing
    Open
  • WorkOS security
    Open
  1. 1
    WorkOS Single Sign-On

    WorkOS · Accessed Official

  2. 2
    WorkOS Directory Sync

    WorkOS · Accessed Official

  3. 3
    WorkOS pricing

    WorkOS · Accessed Official

  4. 4
    WorkOS security

    WorkOS · Accessed Official

  5. 5
    AuthKit documentation

    WorkOS · Accessed Official

  6. 6
    WorkOS users and organizations

    WorkOS · Accessed Official

  7. 7
    Auth0 documentation

    Auth0 · Accessed Official

  8. 8
    Auth0 enterprise identity providers

    Auth0 · Accessed Official

  9. 9
    Frontegg documentation

    Frontegg · Accessed Official

  10. 10
    Frontegg SSO overview

    Frontegg · Accessed Official