Auth0 is a developer-centric customer identity and access management (CIAM) platform offering authentication, authorization, and user management for web and mobile applications, now operating as Okta Customer Identity Cloud.
Directory
Identity, access & authentication tools
Compare IAM, SSO, MFA, CIAM, IGA, PAM, SCIM, and AI agent identity vendors. Filter by company size, deployment model, open source status, pricing, and integrations.
51 vendors · page 1 of 3
Clerk provides drop-in authentication UI components and a complete user management platform for React, Next.js, and modern web applications, including B2B organization management and enterprise SSO.
CyberArk is the market-leading privileged access management (PAM) platform, providing credential vaulting, privileged session management, endpoint privilege management, and secrets management for enterprise security programs.
Microsoft Entra ID is Microsoft's cloud-based identity and access management service, providing SSO, MFA, Conditional Access, and identity governance tightly integrated with Microsoft 365 and Azure.
Okta is a leading cloud-native identity and access management platform offering SSO, MFA, lifecycle management, and identity governance for enterprise workforce and customer-facing applications.
Ping Identity provides enterprise IAM with advanced federation, financial-grade API security, and hybrid cloud/on-premises deployment options, commonly deployed in financial services, healthcare, and government.
SailPoint is the leading enterprise identity governance and administration (IGA) platform, providing access certifications, role management, SoD policy enforcement, and lifecycle management for large organizations.
Teleport provides secure, audited access to SSH, Kubernetes, databases, and internal applications using short-lived certificates and RBAC — designed for engineering teams who need infrastructure access without static credentials.
Veza provides a data-centric identity and access visibility platform, mapping what every identity can do across cloud infrastructure, SaaS, data systems, and on-premises applications to enable access governance and least-privilege enforcement.
WorkOS provides a developer API for adding enterprise identity features — SSO, SCIM directory sync, audit logs, and admin portals — to B2B SaaS applications, enabling faster enterprise sales readiness.
1Password Business provides enterprise password and credential management for teams, with 1Password Secrets Automation extending to CI/CD secrets, developer vaults, and service account credentials.
Aembit is a workload identity and access management platform that manages how workloads, services, and AI agents authenticate and access downstream APIs and services — without static credentials.
Akeyless is an established identity security platform delivering secrets management, certificate lifecycle management, encryption/KMS, and secure remote access from a unified SaaS, using patented Distributed Fragments Cryptography (DFC) instead of a self-managed vault. In 2025–2026 it extended the platform to AI-agent identity with ephemeral, task-scoped access.
Astrix Security discovers and secures non-human identities, AI agents, and MCP servers, and provisions secure-by-design agents through its Agent Control Plane with short-lived credentials and just-in-time access. Following its acquisition by Cisco, its capabilities are being integrated into Cisco's identity and zero-trust portfolio.
BeyondTrust is an enterprise PAM platform providing privileged account management, privileged session management, endpoint privilege management, and secure remote access — a leading alternative to CyberArk.
Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Clutch Security is a non-human identity (NHI) security platform that maps service accounts, keys, tokens, and AI agents to their origins via its Identity Lineage graph, then layers on lifecycle management, posture, and threat detection. It added an Agentic AI Governance module for discovering and setting guardrails around AI agents and their credential usage.
Corsha secures machine-to-machine and API communication with trusted machine identities and dynamic, MFA-style authentication (m-MFA) for machines, plus connection discovery and identity-based access control. It is purpose-built for operational technology, defense, and critical infrastructure, deployable as SaaS or self-hosted via hardware and virtual control points.
Defakto (formerly SPIRL, rebranded in 2026) is a non-human identity and access management platform built on the SPIFFE standard. It issues dynamic, cryptographically verifiable identities for services, workloads, CI/CD pipelines, and AI agents in place of static credentials and service accounts.
Privileged access management platform (formed from Thycotic and Centrify) covering secret server, privileged session and remote access.
Descope provides a no-code/low-code authentication platform with a visual flow builder, enabling teams to design and deploy authentication journeys (passwordless, MFA, SSO) without writing authentication logic from scratch.
Widely deployed MFA and zero trust access platform from Cisco, with strong device trust and push-based authentication.
Entro Security is an agentic AI and non-human identity security platform that discovers, classifies, and governs NHIs and secrets across clouds, code, vaults, and collaboration tools, with behavioral threat detection via its NHIDR engine. SailPoint completed its acquisition of Entro in June 2026, making it the NHI and secrets layer of SailPoint's Agentic Fabric.
Enterprise identity platform covering CIAM, workforce access, directory and identity governance, now part of Ping Identity.
Not sure what to pick?
Run the IAM Stack Finder for a guided shortlist tailored to your stack.
