Stytch

Stytch

Unclaimed verified 6 oct 2026
[  score · 44  ]

A better way to build auth

Pricing: Freemium - $0 / Month Company: Stytch (acquired by Twilio) Founded: 2020 Last verified: 2026-10-06
Visit Website
Updated

TL;DR

Stytch is a developer-first identity platform for consumer and B2B applications, covering authentication, authorization, SSO, MFA, passwordless login, fraud prevention, organizations, and machine-to-machine access. Its key differentiator is the combination of flexible APIs and SDKs with enterprise identity features, multi-tenant organization support, OAuth-based connected applications, and emerging support for AI-agent workflows.

What Users Actually Pay

No user-reported pricing yet.

Our Take

Stytch occupies a developer-first position between traditional enterprise IAM suites such as Okta/Auth0 and more opinionated authentication platforms. It provides APIs, SDKs, prebuilt UI, sessions, organization models, SSO, authorization, and fraud tools while allowing engineering teams to retain control over application architecture and user experience. The strongest review signal is developer experience. G2 reviewers generally praise the API design, documentation, SDKs, test and live environments, migration support, and responsive customer-success team. The available G2 sample is strongly positive, although the public review base is modest and several reviews are dated, so it should not be treated as a complete representation of the customer base. Stytch is particularly well suited to products that need both consumer and enterprise identity capabilities. Its feature set spans passwordless authentication, passkeys, MFA, SAML SSO, OAuth, organization management, SCIM, M2M authentication, fraud prevention, connected applications, and delegated access workflows. This breadth can reduce the need to combine several specialized identity products. The main limitations are maturity, product complexity, and flexibility. Reviewers mention that Stytch can be more opinionated than a homegrown implementation, that certain APIs or customization options have limits, and that the separation between B2C and B2B product models may be confusing for applications evolving from individual users into organizations. It is best suited to engineering-led startups and SaaS companies; teams seeking a purely no-code IAM product or maximum implementation freedom may prefer alternatives.

Pros

  • + Strong developer experience, including well-regarded APIs, SDKs, documentation, and implementation workflows.
  • + Responsive customer support and migration assistance cited by multiple reviewers.
  • + Broad coverage across passwordless authentication, MFA, SSO, OAuth, passkeys, organizations, fraud prevention, and machine-to-machine authentication.
  • + Useful support for incremental migration from homegrown or legacy authentication systems.
  • + Combines B2C and B2B identity capabilities, including multi-tenancy and enterprise SSO.

Cons

  • - Some reviewers find Stytch less flexible than a fully homegrown authentication system.
  • - Review feedback identifies limitations in parts of the API and frontend SDK behavior.
  • - Customization options, including email templating and dashboard capabilities, may not satisfy every use case.
  • - The separate B2C and B2B product paths can create conceptual and implementation friction for mixed-account products.
  • - Independent review volume outside G2 is limited, reducing confidence in broad market representativeness.

Agent Readiness

55/100

Stytch is well suited to engineering teams building secure applications with AI-agent or integration workflows. Its public REST APIs, SDKs, OAuth/OIDC Connected Apps, scoped access, session JWTs, organization-level authorization, webhooks, Terraform provider, sandbox environments, changelog, status page, and official MCP server provide a strong foundation for agent-enabled systems. The main gaps are the lack of a clearly surfaced official OpenAPI specification, no confirmed first-party Make or n8n connectors, plan-dependent webhook functionality, and complexity created by separate B2C and B2B product models. Its strongest agent use case is enabling applications to authenticate users, authorize delegated agent actions, issue scoped credentials, and maintain auditable access boundaries rather than allowing agents to operate with broad unrestricted credentials.

API Surface85
Public APIRESTJSONFree Tierunknown
Protocol Support0
SDK Availability70
npm: stytch (official)npm: @hono/stytch-auth (official)npm: @cloudflare/pages-plugin-stytch (official)npm: @stytch/core (official)npm: @stytch/nextjs (official)npm: @stytch/react (official)npm: @stytch/vanilla-js (official)npm: @utdk/stytch (official)npm: @stytch/headless-client (official)npm: @stytch/react-native (official)pypi: stytch (official)
Integration Ecosystem25
WebhooksOAuth 2.0 and OIDC Connected AppsOfficial remote MCP server for Management API workflowsTerraform providerDatadog integrationGeneric HTTP integration support for automation platforms such as Make and n8n
Developer Experience100
Docs: excellentSandboxVersioningChangelogStatus Page

Last checked Oct 2, 2026

Screenshot

Stytch screenshot

[ features ]

Geostrategic Position

Information on which part of the world this product / vendor belongs to, i.e. the country of their headquarters primarily, but also their hosting options etc.

Headquarter Region

Find which geostrategic world region the headquarter is located in. Relevant for compliance questions (e.g., CLOUD Act) or risk of cut-off in case of conflicts. For example, some EU companies are worried about the US and would definitely not host their customer with Chinese or Russian companies.

United States
Hosting Provider

The hosting provider that is used to host this product, if any.

[  Other  ]
Hosting Locations

The available hosting locations, if you can choose

[  United States  ]

Compliance & Security

Security certifications, compliance features, and access control capabilities.

SOC 2

SOC 2 Type I or Type II certification.

Type II
ISO 27001

ISO 27001 information security certification.

[  yes  ]
GDPR Tools

Built-in tools for GDPR compliance (data export, deletion, consent).

no
Audit Trail

Complete audit log of all data changes.

[  yes  ]
Role-Based Access Control

Granular permissions based on user roles.

[  yes  ]
SSO Support

Single Sign-On integration support.

Both

Developer Experience

Tools and abstractions easing agent development and iteration.

Visual Builder

No-code/low-code UI for designing agent workflows.

no
OpenAI Compatibility

OpenAI API-compatible endpoints or SDKs.

no
Open Source

Available as open-source with community contributions.

no
SDK Languages

Programming languages with official SDK support.

[  Python  ] [  JavaScript/TypeScript  ] [  Other  ]
Pre-built UI Components

Ready-to-use, customizable UI elements for auth flows.

[  yes  ]
Admin Portal

Self-service admin dashboard for customers to manage users/orgs.

[  yes  ]
Framework Integrations

Supported frontend frameworks with dedicated guides/components.

[  React  ] [  Next.js  ]

Authentication Methods

Core authentication flows and options supported by the platform.

Passwordless Auth

Supports passwordless authentication via magic links, passkeys, or biometrics.

[  yes  ]
Social Providers

Supported third-party social login providers.

[  Google  ] [  Facebook  ] [  GitHub  ] [  Apple  ] [  Discord  ] [  GitLab  ] [  LinkedIn  ]
MFA Methods

Supported multi-factor authentication methods.

[  SMS  ] [  TOTP  ] [  WebAuthn/Passkeys  ] [  Email  ] [  Push  ]
Bot Detection

Built-in protection against bots and automated attacks during auth.

[  yes  ]

Enterprise Integrations

Protocols and tools for integrating with enterprise identity systems.

SCIM Provisioning

Supports SCIM for automated user provisioning and deprovisioning.

[  yes  ]
Directory Sync

Supports syncing users/groups from directories like HRIS or IdPs.

[  yes  ]
Supported IdPs

Compatible identity providers for federation.

[  Okta  ] [  Entra ID/Azure AD  ] [  OneLogin  ] [  Google Workspace  ]
JIT Provisioning

Just-In-Time user provisioning from SAML/OIDC assertions.

[  yes  ]

Pricing & Free Tier

Free tier limits and overall pricing structure.

Free Tier MAU Limit

Maximum Monthly Active Users allowed on the free tier.

10000
Billed Metrics

Key usage metrics that incur costs.

[  MAU  ] [  Connections  ] [  Fingerprints  ]

Reviews

0 reviews
Write a Review

No reviews yet. Be the first to review Stytch!