Skip to content
Authentication, authorisation and user management — hosted in the EU

Login, sorted this afternoon.

Your users sign in with email and password, a TOTP code or a passkey, on a login page you brand from the console. Free up to 10,000 monthly active users; passkeys and the rest of Pro are $25 per app per month.

Sign in to Acme

Your hosted login page: your colours, your logo, your wording.

Continue

Secured by Kleora

And for the paperwork: Hosted in the EU Export and erase any user Exportable audit log OAuth 2.0 and OpenID Connect
One session

Every way in, one thing to trust.

Password, passkey or TOTP, the result is one session, and the token your API receives says which workspace, which roles and how the person authenticated. Verify one signature and get on with it.

Email & password Passkey TOTP & recovery codes Device authorisation OAuth 2.0 · PKCE
Verified session
user
jakub@acme.app
workspace
acme-eu
roles
admin, billing
mfa
passed

Install the SDK

One package for your stack, plus the issuer URL and a client id from the console. Browser, Nuxt, Node, Python and Django today.

NuxtNodePythonDjango

Point sign-in at Kleora

Send people to your hosted login page. Colours, font, layout, logo, the wording in English and Polish and your own CSS are set in the console — nothing to redeploy.

Ship, then add the rest

Sessions, refresh and sign-out are handled for you. TOTP, passkeys, a required-MFA policy or multiple workspaces can be switched on later, from the console rather than from a deploy.

Capabilities

What ships today.

Email & password

Sign-up, email verification, password reset and progressive lockout. On every plan.

Passkeys

WebAuthn, either as a second factor after a password or as the whole sign-in. Pro and up.

Multi-factor

TOTP and recovery codes on every plan. The policy is set per environment: off, optional, or, on Pro, required for everyone.

OAuth 2.0 & OIDC

Authorisation code with PKCE, rotating refresh tokens, discovery and JWKS, and the device grant for CLIs and agents.

Workspaces & roles

Workspaces, invitations and roles scoped to one workspace. The roles ride in the access token, so your API reads them there instead of asking.

Audit log

Every sign-in, role change and admin action. Filter it, export it as NDJSON, and keep it for 7, 90 or 365 days depending on the plan.

Data residency

Your users' data never leaves the EU.

Every data store, message broker and backup, and the email provider, run in EU regions. That is the default on every plan, not an add-on.

Databases and backups
EU regions · backups encrypted
EU
Brokers and the email provider
EU regions
EU
Pricing

Free to 10,000 users. Then $25 per app.

You pay per production app. Not per workspace, not per environment, not per sign-in method. Every app has a sandbox next to production, and sandbox never counts.

Monthly active users10,000

One app. The free allowance is pooled across your account; Pro is measured per app.

Free
$0
10,000 MAU pooled across every app
Start free
  • Unlimited apps
  • TOTP and recovery codes
  • 5 workspaces per environment
  • 7 days of audit history
  • 3 account members
  • “Secured by Kleora” in the footer
Pro Most start here
$25/app/mo
10,000 MAU · $25 per app, then $0.010 per MAU
Choose Pro
  • Everything in Free
  • 25,000 MAU per app
  • Passkeys
  • Require MFA across an environment
  • 50 workspaces per environment
  • 90 days of audit history
  • 10 webhook endpoints per environment
  • Unlimited account members
Scale
$299/mo
10,000 MAU · $299 for the account, then $0.006 per MAU
Choose Scale
  • Everything in Pro
  • 250,000 MAU pooled across the account
  • Unlimited workspaces
  • Unlimited webhook endpoints
  • 365 days of audit history
  • 100 rps on the management API

A billing problem never locks out your users.

Sign-in, token refresh and MFA keep working whatever is owed, and so do reads and export. The one thing we withhold is management-API writes, and only from day 15.

Compare the plans

Annual billing is ten times the monthly price — two months free: $250 per app per year on Pro, $2,990 a year on Scale.

Every price is net of tax. VAT or sales tax is added at checkout, and the currency you are billed in follows your billing country, not the language of this page.

Why we built it
“We needed a European identity provider, and everything we found was either expensive or hard to work with. So we built our own.”

Kleora signs us in to Kleora: the console is an app registered on the platform like any other, on the same servers. Nothing here is something we are not already depending on ourselves.

Jakub, Founder

Questions

The ones people actually ask.

What counts as a monthly active user?
A distinct user in a production environment who signs in at least once in the calendar month, counted per app. Someone who signs in forty times is one. Sandbox never counts: charging for testing teaches people to test in production.
Where is our data stored?
In the EU. All data stores, message brokers, backups and the email provider run in EU regions.
Can we customise the login page?
Yes: colours, font, corner radius, one of two layouts, logo, the wording in English and Polish, and your own CSS. All of it from the console, none of it a redeploy.
Do you sell our user data?
No. Subscriptions are the only thing we charge for. Any user can be exported as JSON or erased, on any plan and in any billing state.

Free to 10,000 users. Sign in to your own app today.

Create an account, add the SDK and sign in to your own app before you decide anything.