Auth0® is an identity solution that provides secure access to any application, for any user. Safeguarding, according to the vendor, billions of login transactions each month, Auth0 delivers convenience, privacy, and security so customers can focus on innovation. Auth0 lets users integrate authentication and authorization for web, mobile, and legacy applications, with new Fine Grained Authorization (FGA) that goes beyond role-based access control. It can authenticate users…
$0
per month
Yubico YubiKeys
Score 9.1 out of 10
N/A
Yubico YubiKeys make the internet safer with phishing-resistant multi-factor authentication (MFA) by providing simple and secure access to computers, mobile devices, servers, and internet accounts. The Yubico YubiKey stops account takeovers at scale by mitigating phishing and ransomware attacks, and delivers users authentication with a simple touch or tap.
Compared to Firebase Authentication and Amazon Cognito, it offers better security and easier integration with SPA applications. Firebase Authentication was easy to set up and worked well for simple Authentication use cases, mainly for Firebase-based applications. But it had …
As I already mentioned, role- and resource-based access can be easily provided via drag-and-drop options in this application. If AI is integrated into this tool, it would become even more user-friendly. Excellent tool to consume for security access.
We evaluated Okta as an alternative. While Okta is strong for large enterprises, we found Auth0 more flexible and easier to integrate for our use case. Auth0’s developer experience, customization options, and faster setup made it a better fit for our applications without adding …
Evaluated Okta, Keycloak, and Pingone for multi-tenant SaaS and global customer scenarios, but Auth0 offered the best balance of ease of use, security, and multi-tenant support.
Amazon Cognito was the most cost effective, but it required a lot more manual setup, and the documentation wasn’t as user-friendly for customizing login flows thatswhy chossed Auth0
These all solutions were costly and require more time to deploy in the production. The pingone solution have a very hard login flow and require re login for each solution which is quite hard to use. Entra ID requires a AD to run and doesn't works for our use case. We require …
Superior sales and technical support. Excellent documentation which is ideal for product led team who want to go live in quick time. Adaptability to complex workflows and scalable for future growth and integrations
From a personal standpoint, I chose Google Authenticator over Auth0; however, from a business standpoint, Auth0 has more flexibility as it is hardware/software agnostic and allows for more controls from an IT stand point. It would be nice to have an app that would allow for the …
It was long ago , cognito was in its early days and had critical bug about email case sensitive. Okta Developer lack the separation in model we wanted ,meaning modeling our tenants to their model . we didn't want to create an App per tenant , and wanted some shared …
We noticed the marketplace and crm integration was excellent, besides that there were other factors such as team management tools was also vital, global compliance standard and provide highly secure login access, which was necessary for important clients, and team members. …
Firebase: Pricing is too high and the efficiency and store option is not an ROI point. Okta: Too high pricing. Lack of secure code not good for mobile application auth.
Great product and large user base, easier to integrate. We used Auth0 to take care of single sign-on from all of our clients' auth domains. After initial development to integrate Auth0 with our systems, our client onboard has been very much simplified. The SSO integration …
Auth0 is one of the best login solutions for any website or application. The pricing is more considerable than other similar software. It is easy to use and does not require much effort in deploying. However, the deployment process is not so simple for drag and drop websites or …
Auth0's documentation, framework support, large community, and overall developer experience make the cost trade-off worthwhile. Auth0's developer experience makes it significantly easier for our firm to quickly develop apps that require user accounts, even if we use an SPA or a …
Auth0 is non-evasive and does not require software download. It is user friendly, seamless, and doesn't require additional actions on the part of the user. IBM Trusteer is none of these things and is based on a technology stack that cannot scale in the same way as Auth0. We …
We didn’t do a deep comparison with a lot of other vendors, mostly just used built‑in MFA options (like authenticator apps and SMS) before this. Compared to those, YubiKeys are just way harder to phish or bypass. That’s the main reason we went with them. Hardware-based auth …
We also use 1password for day to day business in our company, thought we do not expose that to any customers, as opposed to the YubiKeys. The advantage: the YubiKeys dont' require any support after. Software always does. The disadvantage (in the end an advantage): you can't …
We've tried several OTP and USB devices, not found above. YubiKeys are just easier to use and integrate with the service we have. We're familiar with them, and they continue to improve, so we continue to lean towards them.
We used to use something from Okta that has I think a passwordless authentication or readily get a notification that's an alternative, but it's software, not hardware. That's the other thing I would say. We have tried nothing else on the hardware side. Its hardware token, ease …
Yubico YubiKeys has been a leader in the security key market, and I think they have a new product we just read about two days back and they can store up to a hundred private keys now. So I think this is what it distinguishes them from the market, apart from this, whatever …
If you compare it to authenticator apps, I'd say it's much more easy to set this up for the individual user. Well, it's Swedish. It's also very well documented. There are a lot of guides on how to use them and I have a lot of faith in the security posture of Yubico and how the …
I've never really used any other physical keys, I mean I've used multifactor authentication from Google Authenticator or Duo, but never another physical key, so this is my first experience with that.
I have used the tokens that display a little six-digit code that rotates, but I feel that's just like my phone does that, so why would I have a separate device for that? This at least provides a physical thing I have to either insert or tap to use. I think they're not …
I have tested the Google Titan Keys. I found Yubico YubiKeys to be a bit more durable and last longer. I've already had a few Google Titan Keys that have just gone out. They just stopped working. So the Yubico YubiKeys are a bit more lightweight and easier to fit on a key ring. …
I prefer Yubico YubiKeys because sometimes logging in with pass keys on an iPhone you have to do kind of two handshakes. One is the QR code and then doing a face ID. So that's an extra step versus the Yubico YubiKeys, which I can just put in and scan with my finger.
We have thought about just trying another competitor for due diligence but have not explored that option yet. We went with Yubico YubiKey due to hearing about it at a conference and decided to start experimenting with the solution. We are pretty decided on what we are going …
They offer ways to store passwords or MFA support, but most need a root password. In addition, LastPass and 1Password do not have much support for MFA. This results in a lack of MFA support. For Okta, although it offers MFA and SSO, the OTP can be very annoying to have as I do …
Auth0 is very well suited for situations where a JSON web token can be used for authorizing APIs, websites, and mobile devices. It's especially useful if the JWT validation can happen at a gateway layer. It's especially useful if you only need to verify the user's email address or mobile number as the passwordless login is easy to implement.
When it comes to authentication and securing access, I recommend Yubico YubiKeys. It comes with phishing-proof MFA that is fast and reliable. In addition, the tap-and-go option ensures fast, secure access, which adds up to a good user experience. The tool reduces the risk of account takeovers and significantly enhances business security.
So as I said, the second-factor authentication that it does is really well. The response time is really good and all you have to do is just enter the second factor code and that's about it. Right? So that's the good part about using Yubico YubiKeys.
Auth0 can be somewhat limiting if you want a lot of control over the design of your authentication flow. Custom branding can be done, but it may be limited depending on how you plan to integrate.
The Auth0 API documentation has proven confusing at times; a single API endpoint's behaviour will change based on inputs and configured settings (e.g. offline_access). Consequently fields that are advertised as being returned in a response might not be there or have different values if you miss a key detail and it can be difficult to debug when this happens. All information required is available in the documentation but requires some digging.
The toggle to switch tenants feels a bit odd, it works, but I've had a few instances where I didn't realize I was on a staging tenant looking for something that was on the production tenant. Not a big deal, just something to watch out for.
It can be about access control because either right now it's just you have access or you don't have access. I think there can be a use case where you are allowed a particular set of servers and not a particular set of servers. I think maybe it's there or we don't use it, but I haven't seen that. I think I've used Yubico YubiKeys at two companies and I haven't seen that. Maybe that's something that can be added.
As for implementing YubiKey its simple so I don't see us using anything else as we have experienced no issues so fare. Adding these to our environment is still new for us currently but in the transition phase I only see us buying YubiKey. It is highly rated and well known and cost is reasonable so no need to find another solution.
Like in my case, it helps me build a better business by requiring authentication and better login features, as they are needed quickly. It helps me save time by not having to create it from scratch and provides better role-based login and access. One of my most helpful features is SSO (Single Sign On). If the user wants Microsoft-able SSO, Auth0 provides an all-in-one.
I give slightly better than average rating because of the complexity in using a Yubikey. It is not as easy as native push notifications for 2FA products, however, it provides much better strength. Rating this higher or lower would be a disservice to people reading this review. If you are in the market for a hardware 2FA tool, Yubikey will be a great asset in your toolbox.
We have not experienced any issues with availability which is very important when you are dealing with a company that holds the keys to the gate. We have had more issues with availability from our SaaS providers before with authentication but that was on their end. YubiKey has worked every time for us over the course of the last 6 or so months we began testing phase.
We have not seen any lag in loading pages and getting into systems or sites. In comparison to other 2FA and MFA options it is actually faster most of the time to authenticate due to not having to type in. We require users to have long passwords and when there is an option given for password less they jump on it with excitement. As we explore going password less on their PC's the YubiKey is going to make their lives a lot easier to access the resources they need.
There isn't a clear method to get a hold of support when trouble arises if you're on their standard plan. You can file a support ticket and they generally are responsive. I've often been able to find similar questions to the questions I've had when it comes to support in their ticket history, however, some have been closed without a satisfactory conclusion for the original poster.
I figured it all out on my own with the excellent product documentation provided by Yubico. I even managed to produce a backup YubiKey in case I lost my frequently used one. This was crucial when I temporarily lost the original.
Auth0 is non-evasive and does not require software download. It is user friendly, seamless, and doesn't require additional actions on the part of the user. IBM Trusteer is none of these things and is based on a technology stack that cannot scale in the same way as Auth0. We believe Auth0 provides a superior solution and is well suited for our own technology stack.
We didn’t do a deep comparison with a lot of other vendors, mostly just used built‑in MFA options (like authenticator apps and SMS) before this. Compared to those, YubiKeys are just way harder to phish or bypass. That’s the main reason we went with them. Hardware-based auth felt like a better fit for higher-risk accounts, even if it’s a bit less convenient for users.
For us I feel like the ease of deployment has made this product very appealing, overall this will make the scalability very easy for us to push out once we roll out to our users and the management tools that we have looked at will make the admins like me happy as it is clear and easy to use. The rollout process looks to be very straight forward from the demos that we have looked at regarding the enterprise tools.
Development time has been allocated to the more core parts of our business.
We are confident in the security of our user's accounts and their data.
Auth0's login flows are customizable which means that we don't have to worry about users being confused when logging in/changing their passwords, and we didn't event have to spend that much time configuring this. (Full in-house development for login could take weeks to get right.)
WebAuthn is an automatic security win, adding hardware keys where your security model calls for it is a natural choice. The automatic support for this makes this easy to integrate into your existing strategy at a reasonable cost/key for the quality.
For privileged scenarios, the risk reduction opportunity is significant. You can leverage hardware keys for privileged access that integrate well within existing identity platforms (like Microsoft) so roll-out is a simple matter of config.
The 6 Ps apply here, deployments must be planned carefully to ensure the impacted users are ready. Else you will see key loss, helpdesk demand, etc. Plan the deployment well so that users know what they are doing on day 1.