XID Cloud
Operated by XID on xid.dev.
Free today
- Every feature
- An organization for your company, and one for each of your customers
- Hosted pages on your organization's subdomain of xid.dev
No plans, no tiers, no paid features. If XID Cloud ever charges, it bills only for monthly active users. Self-hosted XID has the same features, with billing off unless you turn it on.
Operated by XID on xid.dev.
Free today
Run it in your own Cloudflare account.
Free, MIT licensed
A monthly active user is a person who signs in at least once in a calendar month (UTC). Each person counts once per month across your organization and all of its sub-organizations, however often they sign in. Guest sessions don't count. Your console overview shows the number as Monthly active users.
| Feature | XID Cloud | Self-hosted | Status |
|---|---|---|---|
| Sign-in | |||
| Email code and magic link | Included | Included | Production |
| Passkeys | Included | Included | Integration-tested |
| MFA: authenticator app, SMS, backup codes, passkey | Included | Included | Integration-tested |
| Password with breach checks, social sign-in | Included | Included | Integration-tested |
| Hosted pages and organizations | |||
| Hosted sign-in page | Included | Included | Production |
| Account page, eight interface languages | Included | Included | Integration-tested |
| Switch organizations in one console | Included | Included | Production |
| Sub-organizations, members, roles, branding, domain verification | Included | Included | Integration-tested |
| Enterprise and developers | |||
| Inbound SAML and OIDC SSO, inbound SCIM 2.0, XID as identity provider | Included | Included | Verified end to end, local |
| OpenID Connect: authorization code, PAR, DPoP | Included | Included | Verified end to end, local |
| Management API | Included | Included | Production, core paths |
| Signed webhooks, hash-chained audit log | Included | Included | Implemented |
| SDKs | Included | Included | Not yet published to npm |
Status comes from the public evidence matrix in the repository. Only rows marked Production are verified on xid.dev. Self-hosted deployments also get the instance console for every organization on the deployment.
No. There are no plans or tiers. Every feature is available on XID Cloud and when you self-host.
XID is pre-1.0. Hosted sign-in, the console and the Management API core paths are verified in production on xid.dev. Enterprise identity providers, social sign-in and SMS are verified locally only.
It is free today. If it ever charges, it bills only per monthly active user, and no feature is reserved for paying customers.
None by default. If one is set, it only stops creating new sub-organizations or SSO connections. No limit stops sign-in, sign-up, SSO or SCIM provisioning, or token refresh.
It's the same code. You can export users with the Management API; password hashes are not exported, and passkeys need to be registered again on the new domain. There is no one-step migration tool.
Nothing to XID. You pay Cloudflare for what your account uses, and sending email to any recipient needs the Workers Paid plan. You also need a domain whose DNS you control.
In XID's Cloudflare account, on D1, KV, R2 and Durable Objects. Choosing a data region isn't available.
Not yet.
Pre-1.0. Core paths of hosted sign-in, the console and the Management API are verified in production on xid.dev. Everything else is verified locally.