Exclusively distributed by dotNET lab in the Benelux

ProAuth: self-hosted identity provider, the European alternative to Auth0 and Keycloak

  • Unlimited users, you pay per installation.
  • Runs where you want: in Europe or self-hosted, offline too.
  • A support team you can call, more than a chat message or an e-mail.

For organisations with many applications, many users and strict requirements. ProAuth runs with you; dotNET lab delivers the licence, implementation and support.

Illustration: a receptionist hands a light blue badge to a visitor at a desk; behind them hang four application windows with an open padlock, and a small European flag stands on the desk.

Why ProAuth

  • Every customer their own login

    Their own Entra ID, Active Directory, passkeys or a dedicated account, with their own branding and MFA policy, configured in the management portal.

  • One login for all your applications

    Single sign-on across all your applications and APIs via OpenID Connect, whatever they are built in.

  • Security that passes audits

    Passkeys and MFA as standard; tokens bound to the client and a signed audit trail for regulated sectors.

  • Three editions, also to ship with your product

    Starter, Business or Enterprise, as a subscription or perpetual, with a redistribution licence for software that runs at your customer.

Why an identity provider

Login should not be rebuilt in every application

As soon as customers, partners and APIs come together, login becomes a domain of its own: duplicate accounts, permissions that linger, different logic per application. An identity provider centralises that. ProAuth does it as a finished product you host yourself, with a fixed price and a support team you can call.

The three other routes

  • Cloud service

    Auth0, Entra External ID

    • The invoice grows with every user
    • Data with a US vendor
  • Open source

    Keycloak, authentik

    • Every upgrade and security advisory is your work
    • No support desk, only forums
  • Build it yourself

    Duende IdentityServer, OpenIddict, Better Auth

    • Every login screen and MFA flow is development work
    • So is every new customer
Illustration: on the left someone struggles under a wobbly stack of door panels each with a keyhole, on the right someone relaxed shows a single panel with one keyhole.

Why not just Auth0?

At a glance

What you get with a cloud service, with building or managing it yourself, and with ProAuth.

QuestionCloud (Auth0, Entra External ID)Yourself (Keycloak, Better Auth, IdentityServer)ProAuth
Data with you With the vendor (US) Yes Yes, offline too
Price at 100,000 users Grows per user Free, costs hours Fixed price
Updates and patches Vendor You Vendor
New customer with their own login Pricier plans Build it yourself One setting
Ship inside your product, offline No Support it yourself Yes
Security for regulated APIs Paid add-on Build it yourself Standard
Best choice when Small, no data requirements Strong platform team Scale, control, a vendor

Sources: the pricing and product pages of Auth0, Microsoft, Keycloak, Duende and 4tecture, September 2026.

How it fits your landscape

One identity provider between your identity sources and all your applications

ProAuth sits in between: authentication, federation, claims and audit in one place.

Where identities come from

  • Own user stores (SQL Server, Azure SQL, PostgreSQL)
  • Entra ID and Active Directory
  • External OIDC identity providers
  • Users and groups via SCIM

What relies on that one login

  • SaaS tenants with their own login and branding
  • Customer and member portals
  • APIs with DPoP- or mTLS-bound tokens
  • Products that run at the customer, offline too

Customers, applications, user sources, permissions and MFA policy are managed in the portal or automated, without a release of your software.

Recognisable situations

Where ProAuth makes the difference

Login, single sign-on and MFA come with every identity provider. These are the situations where the ProAuth delivery model counts: self-hosted, licensed per installation and with a support team you can call.

  • Illustration: someone slides a light blue card next to three identical cards into one large application window.

    You sell a SaaS platform to dozens of customers

    Per customer a tenant with its own user store or federation to their Entra ID, own branding and MFA policy, created in the management portal without a new release. With the Enterprise edition unlimited tenants, without a cost per tenant or user.

  • Illustration: someone kneels next to a server tower and plugs a cable with a light blue plug into the front.

    Your product runs at the customer, sometimes without internet

    A cloud service is out here. ProAuth ships inside your product under a redistribution licence, runs fully offline and is installed and updated at every customer in the same automated way.

  • Illustration: someone holds a large door open with a light blue key in hand, while a row of small figures in the distance walks towards the door.

    Your portal counts tens of thousands of users

    Auth0, Entra External ID and authentik Enterprise bill per active user. ProAuth costs per installation, however many members or citizens sign in, with passkeys and MFA included.

  • Illustration: someone sits relaxed on top of a server tower with a phone to the ear, a hand on a light blue lifebuoy.

    You maintain Keycloak or IdentityServer yourself today

    Every Keycloak major version or .NET upgrade is your work and your risk. ProAuth delivers updates and patches as a product, with a support desk in the Benelux.

  • Illustration: someone holds a large shield in front of them with both hands, with three small tokens above it, the middle one light blue.

    Your APIs fall under strict rules

    Tokens bound to the client via DPoP or mTLS, the FAPI 2.0 profile and a signed audit trail are a setting in ProAuth, not a project. For financial APIs, government and healthcare.

Want ProAuth to run on European infrastructure and have us manage it? See Sovereign EU cloud & management.

What you get

Licence, implementation and follow-up from one hand

As the exclusive distributor in the Benelux we do not only deliver the licence. We make sure ProAuth lands correctly in your architecture and keeps working.

Licence and edition advice

Starter, Business or Enterprise based on your number of client applications, user stores and federations. Subscription or perpetual, with a redistribution licence if you ship ProAuth with your product.

Tenant and access design

Which customers get their own user store and which federate, which claims each application needs, which MFA policy applies per tenant. Captured as configuration we repeat per environment.

Installation and integration

Installation on your infrastructure or on our European cloud, connected to your monitoring, and making your applications and APIs sign in through ProAuth.

Migration of existing logins

Users from IdentityServer, Keycloak or a home-grown login module migrated automatically, application by application, with the old login as a transition so nobody registers again.

Support and management

First line in the Benelux, backed by the 4tecture support tiers, up to Enterprise Managed with a two-hour response time, 24/7. On request we manage your ProAuth environment.

ProAuth is a product of 4tecture GmbH from Volketswil, Switzerland. dotNET lab is the exclusive distributor for Belgium, the Netherlands and Luxembourg.

Developer

4tecture GmbH

  • Develops and maintains the product
  • Delivers updates and security patches
  • Second line for product defects

Exclusive Benelux distributor

dotNET lab

  • Licences and pricing proposal
  • Design, installation and integration into your software
  • First point of contact for support and management

Behind the implementation: a team that has been building software for 25+ years, with development, security, cloud and identity under one roof.

How we work

First the tenant model, then the installation

Installing ProAuth is the smallest part of the work. The value sits in a tenant and permission model that is right and a migration that hinders nobody.

  1. 01

    We map applications, customers and identity sources

    Which applications become an OIDC client, which customers get their own user store and which federate to their Entra ID or Active Directory, which claims does each application need?

  2. 02

    We choose the edition and where it lands

    Starter, Business or Enterprise, and where ProAuth runs: your own infrastructure, offline at your customer or our European cloud.

  3. 03

    We capture tenants, applications, permissions and MFA policy as configuration

    Repeatable per environment, from test to production: user stores, federations, MFA policy per tenant or application, branding and the claims each application receives.

  4. 04

    We switch over, application by application

    Existing users migrated automatically, with the old login as a transition, so nobody has to register again.

  5. 05

    We take care of management and evolution

    Connection to your monitoring, the audit trail where your auditor wants it, and agreements on who manages customers and policy. 4tecture counts on one to three weeks for a SaaS onboarding, depending on integration depth and branding.

Under the bonnet

From sign-in to audit: what ProAuth brings as standard

ProAuth 3 follows the open standards, so every application or API that speaks OpenID Connect can sign in through it, whatever technology it is built in.

  1. Authentication

    Passkeys (FIDO2/WebAuthn) for user stores and federated users, TOTP, SMS and email as factors, configurable per tenant or client. No password grant.

  2. Federation and user stores

    Per tenant its own user store (SQL Server, Azure SQL or PostgreSQL) or federation to Entra ID, Active Directory and other OIDC providers; SCIM keeps users and groups in sync.

  3. Authorisation

    The Claims Rule Engine shapes tokens per client; roles, groups and tenants as the basis for your permission model.

  4. Tokens and API security

    FAPI 2.0 profile, DPoP, mTLS-bound tokens, PAR and JAR, token exchange for API chains, reference tokens and token encryption where needed.

  5. Audit and observability

    A signed, tamper-evident audit trail for management changes and sign-ins; logs, metrics and traces via OpenTelemetry.

Tenants, clients, user stores, federations, claim rules and factors are managed through the portal, the Management API or YAML with the CLI. A new customer takes no release of your software.

Standards, objects and tooling

  • OpenID Connect 1.0 and OAuth 2.0
  • Authorization code with PKCE, client credentials, device flow, token exchange
  • FAPI 2.0, DPoP, mTLS, PAR, JAR
  • Passkeys (FIDO2/WebAuthn), TOTP, SMS, email
  • User stores on SQL Server, Azure SQL or PostgreSQL
  • Federation to Entra ID and AD, SCIM provisioning
  • Claims Rule Engine per client
  • Management API, User Store API, SDKs
  • CLI with idempotent YAML
  • Helm charts, rolling and blue-green upgrades
  • OpenTelemetry, health checks
  • Signed audit trail, encryption at rest

Data sovereignty

Your login process runs where your data runs

ProAuth runs with only local dependencies: no call-home, no external service that has to be online to sign a user in.

ProAuth runs where you choose: your own infrastructure, a European cloud under Belgian management, or fully offline at your customer.

With PostgreSQL as the user store, the full stack, database included, runs autonomously in your Kubernetes cluster.

Editions

Three editions, one price per installation

No price per user or per tenant. You choose an annual subscription or a perpetual licence with maintenance.

  • Starter: 5 client applications (expandable to 15), 1 user store, 1 federation; passkeys and TOTP
  • Business: 15 client applications (up to 30), 2 user stores, 2 federations (up to 5); plus email as a factor
  • Enterprise: unlimited, plus SMS, Claims Rule Engine, audit trail, SCIM from Entra ID or AD, tenant-specific login screens, a test environment and a redistribution licence
  • All editions: the highest token security for APIs (FAPI 2.0, DPoP, mTLS)
  • Support: Basic included; Enterprise Standard, Premium or Managed (2 hours, 24/7)

Who it is for

For organisations with many users or complex requirements

ProAuth fits organisations where many people have to sign in, customers, members, citizens or partners, across several applications, and where requirements apply around MFA, audit and the place where identity data lives.

Where it runs today, according to the 4tecture references: at a pension fund with multi-tenant customer authentication and MFA enrolment, in an industrial platform that gives resellers access through the public cloud, and shipped inside lab management software at the customer.

Software companies that deliver a platform or an on-premises product also use ProAuth to avoid solving identity anew per customer, whatever technology they build in.

Request a demo
Illustration: three professionals from different organisations side by side; the middle one holds a single key with both hands to the chest.

FAQ

Frequently asked questions

What exactly is ProAuth?

ProAuth is an identity provider (IdP) based on OpenID Connect 1.0 and OAuth 2.0, developed by 4tecture GmbH in Switzerland and today at version 3. You host it yourself as a container and use it as the central login, single sign-on, multi-factor and federation for all your applications, APIs and customers. The object model: tenants, clients, user stores, federations, claim rules and factors.

What is the role of dotNET lab?

dotNET lab is the exclusive distributor of ProAuth in Belgium, the Netherlands and Luxembourg. We sell the licences, design the tenant and access model, install and integrate ProAuth into your software and are your first point of contact for support. For product defects we work directly with 4tecture, which delivers the Basic, Enterprise Standard, Premium and Managed support tiers.

How does the licence work and what does ProAuth cost?

ProAuth is licensed per installation, without a cost per user or per tenant. You choose an annual subscription or a perpetual licence with annual maintenance, in the edition that fits your number of client applications, user stores and federations. 4tecture publishes list prices; we prepare a proposal tailored to edition and support level.

Where does ProAuth run?

Anywhere containers run: on Kubernetes in your own data centre, in a private or public cloud, or fully offline without external dependencies. User stores run on SQL Server, Azure SQL or PostgreSQL; with PostgreSQL you need no external database and ProAuth runs fully autonomously in your Kubernetes cluster. If you do not want to manage it yourself, we host and manage ProAuth on European infrastructure.

Does ProAuth support SAML?

No. ProAuth is an OpenID Connect and OAuth 2.0 server; federation to external identity providers runs through OIDC. If you have SAML integrations with older systems, we look in the first conversation at whether a bridge is enough or another choice fits better.

Why ProAuth and not Keycloak, Duende IdentityServer or Auth0?

Keycloak and authentik are open source: powerful, but maintenance, upgrades and hardening are yours, unless you take a support contract with Red Hat. Duende IdentityServer, OpenIddict and Better Auth are libraries you use to build and maintain the login yourself; good when identity is the core of your product, expensive when it should be a side matter. Auth0 and Entra External ID are cloud services with a price per user and identity data outside your own environment. ProAuth is a finished product you host yourself, with a fixed price per installation and a vendor that delivers updates, security patches and support. Which choice fits depends on your situation; we look at that together in a first conversation.

We already use Entra ID or Active Directory. Is ProAuth still useful?

Yes, often especially then. Entra ID manages your employees; ProAuth becomes the identity provider for your applications, customers and partners and federates to Entra ID or Active Directory for whoever has an account there. Users and groups synchronise via SCIM.

Can we migrate from IdentityServer or a home-grown login module?

Yes. Because ProAuth follows the standard protocols, little changes for your applications beyond the identity provider configuration. Existing users move to user stores via the User Store API or SCIM, application by application, with federation to the old login as a transition.

First step

Curious whether ProAuth fits your architecture?

Tell us which applications, customers and identity sources exist today.

We show ProAuth in a demo on your situation and give a concrete estimate of edition, where it lands and the implementation.