Licence and edition advice
Starter, Business or Enterprise based on your number of client applications, user stores and federations. Subscription or perpetual, with a redistribution licence if you ship ProAuth with your product.
Exclusively distributed by dotNET lab in the Benelux
For organisations with many applications, many users and strict requirements. ProAuth runs with you; dotNET lab delivers the licence, implementation and support.

Why ProAuth
Every customer their own login
Their own Entra ID, Active Directory, passkeys or a dedicated account, with their own branding and MFA policy, configured in the management portal.
One login for all your applications
Single sign-on across all your applications and APIs via OpenID Connect, whatever they are built in.
Security that passes audits
Passkeys and MFA as standard; tokens bound to the client and a signed audit trail for regulated sectors.
Three editions, also to ship with your product
Starter, Business or Enterprise, as a subscription or perpetual, with a redistribution licence for software that runs at your customer.
Why an identity provider
As soon as customers, partners and APIs come together, login becomes a domain of its own: duplicate accounts, permissions that linger, different logic per application. An identity provider centralises that. ProAuth does it as a finished product you host yourself, with a fixed price and a support team you can call.
The three other routes
Auth0, Entra External ID
Keycloak, authentik
Duende IdentityServer, OpenIddict, Better Auth

Why not just Auth0?
What you get with a cloud service, with building or managing it yourself, and with ProAuth.
| Question | Cloud (Auth0, Entra External ID) | Yourself (Keycloak, Better Auth, IdentityServer) | ProAuth |
|---|---|---|---|
| Data with you | With the vendor (US) | Yes | Yes, offline too |
| Price at 100,000 users | Grows per user | Free, costs hours | Fixed price |
| Updates and patches | Vendor | You | Vendor |
| New customer with their own login | Pricier plans | Build it yourself | One setting |
| Ship inside your product, offline | No | Support it yourself | Yes |
| Security for regulated APIs | Paid add-on | Build it yourself | Standard |
| Best choice when | Small, no data requirements | Strong platform team | Scale, control, a vendor |
Sources: the pricing and product pages of Auth0, Microsoft, Keycloak, Duende and 4tecture, September 2026.
How it fits your landscape
ProAuth sits in between: authentication, federation, claims and audit in one place.
Where identities come from
What relies on that one login
Customers, applications, user sources, permissions and MFA policy are managed in the portal or automated, without a release of your software.
Recognisable situations
Login, single sign-on and MFA come with every identity provider. These are the situations where the ProAuth delivery model counts: self-hosted, licensed per installation and with a support team you can call.

Per customer a tenant with its own user store or federation to their Entra ID, own branding and MFA policy, created in the management portal without a new release. With the Enterprise edition unlimited tenants, without a cost per tenant or user.

A cloud service is out here. ProAuth ships inside your product under a redistribution licence, runs fully offline and is installed and updated at every customer in the same automated way.

Auth0, Entra External ID and authentik Enterprise bill per active user. ProAuth costs per installation, however many members or citizens sign in, with passkeys and MFA included.

Every Keycloak major version or .NET upgrade is your work and your risk. ProAuth delivers updates and patches as a product, with a support desk in the Benelux.

Tokens bound to the client via DPoP or mTLS, the FAPI 2.0 profile and a signed audit trail are a setting in ProAuth, not a project. For financial APIs, government and healthcare.
Want ProAuth to run on European infrastructure and have us manage it? See Sovereign EU cloud & management.
What you get
As the exclusive distributor in the Benelux we do not only deliver the licence. We make sure ProAuth lands correctly in your architecture and keeps working.
Starter, Business or Enterprise based on your number of client applications, user stores and federations. Subscription or perpetual, with a redistribution licence if you ship ProAuth with your product.
Which customers get their own user store and which federate, which claims each application needs, which MFA policy applies per tenant. Captured as configuration we repeat per environment.
Installation on your infrastructure or on our European cloud, connected to your monitoring, and making your applications and APIs sign in through ProAuth.
Users from IdentityServer, Keycloak or a home-grown login module migrated automatically, application by application, with the old login as a transition so nobody registers again.
First line in the Benelux, backed by the 4tecture support tiers, up to Enterprise Managed with a two-hour response time, 24/7. On request we manage your ProAuth environment.
ProAuth is a product of 4tecture GmbH from Volketswil, Switzerland. dotNET lab is the exclusive distributor for Belgium, the Netherlands and Luxembourg.
Developer
Exclusive Benelux distributor
Behind the implementation: a team that has been building software for 25+ years, with development, security, cloud and identity under one roof.
How we work
Installing ProAuth is the smallest part of the work. The value sits in a tenant and permission model that is right and a migration that hinders nobody.
Which applications become an OIDC client, which customers get their own user store and which federate to their Entra ID or Active Directory, which claims does each application need?
Starter, Business or Enterprise, and where ProAuth runs: your own infrastructure, offline at your customer or our European cloud.
Repeatable per environment, from test to production: user stores, federations, MFA policy per tenant or application, branding and the claims each application receives.
Existing users migrated automatically, with the old login as a transition, so nobody has to register again.
Connection to your monitoring, the audit trail where your auditor wants it, and agreements on who manages customers and policy. 4tecture counts on one to three weeks for a SaaS onboarding, depending on integration depth and branding.
Under the bonnet
ProAuth 3 follows the open standards, so every application or API that speaks OpenID Connect can sign in through it, whatever technology it is built in.
Passkeys (FIDO2/WebAuthn) for user stores and federated users, TOTP, SMS and email as factors, configurable per tenant or client. No password grant.
Per tenant its own user store (SQL Server, Azure SQL or PostgreSQL) or federation to Entra ID, Active Directory and other OIDC providers; SCIM keeps users and groups in sync.
The Claims Rule Engine shapes tokens per client; roles, groups and tenants as the basis for your permission model.
FAPI 2.0 profile, DPoP, mTLS-bound tokens, PAR and JAR, token exchange for API chains, reference tokens and token encryption where needed.
A signed, tamper-evident audit trail for management changes and sign-ins; logs, metrics and traces via OpenTelemetry.
Tenants, clients, user stores, federations, claim rules and factors are managed through the portal, the Management API or YAML with the CLI. A new customer takes no release of your software.
Data sovereignty
ProAuth runs with only local dependencies: no call-home, no external service that has to be online to sign a user in.
ProAuth runs where you choose: your own infrastructure, a European cloud under Belgian management, or fully offline at your customer.
With PostgreSQL as the user store, the full stack, database included, runs autonomously in your Kubernetes cluster.
Editions
No price per user or per tenant. You choose an annual subscription or a perpetual licence with maintenance.
Who it is for
ProAuth fits organisations where many people have to sign in, customers, members, citizens or partners, across several applications, and where requirements apply around MFA, audit and the place where identity data lives.
Where it runs today, according to the 4tecture references: at a pension fund with multi-tenant customer authentication and MFA enrolment, in an industrial platform that gives resellers access through the public cloud, and shipped inside lab management software at the customer.
Software companies that deliver a platform or an on-premises product also use ProAuth to avoid solving identity anew per customer, whatever technology they build in.

FAQ
ProAuth is an identity provider (IdP) based on OpenID Connect 1.0 and OAuth 2.0, developed by 4tecture GmbH in Switzerland and today at version 3. You host it yourself as a container and use it as the central login, single sign-on, multi-factor and federation for all your applications, APIs and customers. The object model: tenants, clients, user stores, federations, claim rules and factors.
dotNET lab is the exclusive distributor of ProAuth in Belgium, the Netherlands and Luxembourg. We sell the licences, design the tenant and access model, install and integrate ProAuth into your software and are your first point of contact for support. For product defects we work directly with 4tecture, which delivers the Basic, Enterprise Standard, Premium and Managed support tiers.
ProAuth is licensed per installation, without a cost per user or per tenant. You choose an annual subscription or a perpetual licence with annual maintenance, in the edition that fits your number of client applications, user stores and federations. 4tecture publishes list prices; we prepare a proposal tailored to edition and support level.
Anywhere containers run: on Kubernetes in your own data centre, in a private or public cloud, or fully offline without external dependencies. User stores run on SQL Server, Azure SQL or PostgreSQL; with PostgreSQL you need no external database and ProAuth runs fully autonomously in your Kubernetes cluster. If you do not want to manage it yourself, we host and manage ProAuth on European infrastructure.
No. ProAuth is an OpenID Connect and OAuth 2.0 server; federation to external identity providers runs through OIDC. If you have SAML integrations with older systems, we look in the first conversation at whether a bridge is enough or another choice fits better.
Keycloak and authentik are open source: powerful, but maintenance, upgrades and hardening are yours, unless you take a support contract with Red Hat. Duende IdentityServer, OpenIddict and Better Auth are libraries you use to build and maintain the login yourself; good when identity is the core of your product, expensive when it should be a side matter. Auth0 and Entra External ID are cloud services with a price per user and identity data outside your own environment. ProAuth is a finished product you host yourself, with a fixed price per installation and a vendor that delivers updates, security patches and support. Which choice fits depends on your situation; we look at that together in a first conversation.
Yes, often especially then. Entra ID manages your employees; ProAuth becomes the identity provider for your applications, customers and partners and federates to Entra ID or Active Directory for whoever has an account there. Users and groups synchronise via SCIM.
Yes. Because ProAuth follows the standard protocols, little changes for your applications beyond the identity provider configuration. Existing users move to user stores via the User Store API or SCIM, application by application, with federation to the old login as a transition.