Identity & Access Management

Enterprise IAM for SaaS.
At a fraction of the cost.

Passport is a white-label Identity & Access Management platform that gives your SaaS product enterprise-grade authentication, RBAC, and SSO — without the Auth0 price tag.

A BizFirstAi product · 5 apps included · Deploy in 1–2 weeks

5 Apps Included
630+ Unit Tests
95% Pass Rate
2,000+ Requests / Sec

How Passport compares.

Stop paying enterprise SaaS tax for IAM you can own outright.

Auth0 / Okta

$2,000 – $10,000+ / month

Cost $2K–$10K+/month, scales with MAUs
Time to Market Days to integrate, weeks to customise
White-Label Limited — provider branding visible
Multi-Tenant Available at higher tiers
Maintenance Vendor-controlled, breaking changes
Customisation Constrained by vendor limits
Security Audit Vendor audited — you trust their report

DIY Solution

4–12 weeks to build

Cost High eng cost upfront + ongoing overhead
Time to Market 4–12 weeks minimum, often longer
White-Label Fully yours — if you build it
Multi-Tenant Requires careful architecture, easy to get wrong
Maintenance Your team owns security updates forever
Customisation Unlimited — you wrote it
Security Audit Your responsibility, high risk if missed

Passport

<$500/month hosting

Cost Under $500/month hosting, one-time licence
Time to Market 1–2 weeks to deploy & customise
White-Label Built-in — your brand throughout
Multi-Tenant Native — TenantId enforced at every layer
Maintenance Clean architecture, easy to extend
Customisation Full source code, no vendor limits
Security Audit 630+ tests, SOLID principles, GDPR controls

Five applications. One complete platform.

Passport ships 5 purpose-built frontend applications — every screen your users and admins need, already built and tested.

Admin Dashboard

Complete user and tenant administration with RBAC configuration and audit logging.

  • User management — create, suspend, bulk import
  • Role & permission management
  • RBAC configuration per tenant
  • Full audit log viewer
  • Security policy settings

Login Portal

White-label authentication screens with every login method your users expect.

  • Email / password with bcrypt hashing
  • OAuth 2.0 social — Google, GitHub, Microsoft
  • CSRF protection built-in
  • Rate limiting & brute-force prevention
  • Customisable to your brand

User Portal

Self-service account management so users can stay in control without raising support tickets.

  • Profile & display name management
  • Password change flow
  • Active session viewer & revoke
  • Connected apps overview
  • 2FA setup & recovery

Security Dashboard

Real-time threat monitoring and compliance reporting for your security team.

  • Real-time login monitoring
  • Suspicious activity alerts
  • Device fingerprinting & IP reputation
  • VPN / proxy / datacenter detection
  • Compliance reports — GDPR, SOC2, HIPAA

SSO Management

Register and manage external applications and debug SSO integrations from one console.

  • Register external apps for SSO
  • Configure role mappings per app
  • Monitor live SSO request traffic
  • Discourse Connect debugging tools
  • SAML & OIDC configuration (roadmap)

Works with your existing IAM. Or replace it.

Passport implements 6 provider interface contracts. Swap your IAM backend with a single config line — no changes to any controller or business logic.

AWS Cognito

Cloud-managed

Connect to an existing Cognito user pool. Leverage AWS infrastructure with Passport's UI and RBAC layer on top.

Azure AD

Enterprise directory

Integrate with Microsoft Entra ID for enterprise customers who already live in the Microsoft ecosystem.

Okta

Federated identity

Delegate authentication to Okta while retaining Passport's white-label screens, RBAC, and audit trail.

BizFirst Passport Native

2,000 – 3,000 req/sec

Self-hosted, local SQL, maximum performance. 4–6× faster than cloud IAM. Full data ownership — nothing leaves your infrastructure.

Swap provider with a single config line — no code changes in controllers or business logic. All four providers implement the same 6 interface contracts.

Everything IAM should include.

Every critical IAM capability built-in from day one — not bolt-on add-ons you pay extra for.

Multi-Tenant by Default

TenantId is enforced at the database, API, and UI layers. Cross-tenant data leaks are architecturally impossible, not just policy-controlled.

Role-Based Access Control

Hierarchical roles with fine-grained permission assignment. A permission resolver pattern with 5-minute cache and fail-secure design.

Full Audit Trail

Every authentication and authorisation event is logged with timestamp, actor, outcome, and context. Non-repudiable records for compliance.

Protocol Flexibility

Discourse Connect live now. SAML 2.0 and OIDC on the roadmap. OAuth 2.0 social providers (Google, GitHub, Microsoft) included.

Self-Service Portals

5 purpose-built frontend applications covering every user and admin workflow — login, profile, admin, SSO, and security. Zero custom dev for standard flows.

GDPR & Compliance

Data export and deletion tooling, consent management hooks, and compliance reports covering GDPR, SOC2, and HIPAA controls.

How SaaS companies use Passport.

Three common deployment patterns — each live in production weeks, not quarters.

SaaS Authentication Layer

A B2B SaaS platform needs enterprise-grade auth — SSO, RBAC, audit logs — but can't justify the Auth0 bill as they scale past 10,000 MAUs.

Outcome: Deploy and customise Passport in 1–2 weeks. Full white-label. Multi-tenant ready for the next enterprise customer on day one.

~$500/month vs. $2–10K

Internal SSO Platform

An enterprise with 15 internal tools needs single sign-on. Employees manage separate passwords for each app, causing support overhead and security risk.

Outcome: One Passport deployment, 15 apps registered via SSO Management. Users log in once. RBAC determines which apps each team accesses.

Zero password sprawl

Federated Provider Migration

A team needs to migrate from AWS Cognito to Azure AD after an acquisition — without downtime or a re-authentication event for users.

Outcome: Change one config line in Passport. The provider interface contract means zero disruption to controllers, business logic, or end users.

Zero disruption migration

Protocol support.

Open standards coverage for every integration scenario — current and future.

Discourse Connect Live OAuth 2.0 Social Live — Google, GitHub, Microsoft SAML 2.0 In Roadmap OIDC In Roadmap

Ready to add enterprise IAM to your SaaS?

Talk to us about licensing Passport for your platform.