<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ffo</title><link>https://news.ycombinator.com/user?id=ffo</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Tue, 07 Apr 2026 16:07:12 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ffo" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ffo in "Ask HN: European Tech Alternatives?"]]></title><description><![CDATA[
<p>I hear you! Right now that is a constraint even if we have regions in EU and Switzerland.<p>You can easy deploy Zitadel to Hetzner though ;-)</p>
]]></description><pubDate>Thu, 02 Apr 2026 21:25:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=47620416</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=47620416</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47620416</guid></item><item><title><![CDATA[New comment by ffo in "Ask HN: European Tech Alternatives?"]]></title><description><![CDATA[
<p>It absolutly does <a href="https://zefix.ch/en/search/entity/list/firm/1391256" rel="nofollow">https://zefix.ch/en/search/entity/list/firm/1391256</a> :-)<p>The matter is definitely more complex than yes and no... my general stand has been that jurisdiction matters a lot when you store and process data from customers, like many cloud services do. iIt matters less if you can take a software and self-host it.</p>
]]></description><pubDate>Thu, 02 Apr 2026 19:33:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=47619108</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=47619108</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47619108</guid></item><item><title><![CDATA[New comment by ffo in "Ask HN: European Tech Alternatives?"]]></title><description><![CDATA[
<p>Zitadel CEO here :-)<p>Zitadel started in Switzerland under the name CAOS AG and has still a lot of its operations in Europe. For our US go to market strategy we incorporated Zitadel Inc. which operates out of SF where I also tend to be.<p>Happy to share more if interested</p>
]]></description><pubDate>Thu, 02 Apr 2026 18:51:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47618620</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=47618620</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47618620</guid></item><item><title><![CDATA[Anonymous Authentication: Creating access tokens for guest accounts]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/zitadel/zitadel-guest-accounts">https://github.com/zitadel/zitadel-guest-accounts</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47181864">https://news.ycombinator.com/item?id=47181864</a></p>
<p>Points: 5</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 27 Feb 2026 15:46:54 +0000</pubDate><link>https://github.com/zitadel/zitadel-guest-accounts</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=47181864</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47181864</guid></item><item><title><![CDATA[The Broken Promise of OIDC]]></title><description><![CDATA[
<p>Article URL: <a href="https://zitadel.com/blog/the-broken-promise-of-oidc">https://zitadel.com/blog/the-broken-promise-of-oidc</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46723808">https://news.ycombinator.com/item?id=46723808</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 22 Jan 2026 19:13:37 +0000</pubDate><link>https://zitadel.com/blog/the-broken-promise-of-oidc</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=46723808</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46723808</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>I lost track what they use … Auth0, Ory, WorkOS… sounds like they should go ahead and finally acquire something #scnr</p>
]]></description><pubDate>Fri, 14 Nov 2025 00:57:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=45922648</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45922648</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45922648</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>TIL a thing about NIX again :D</p>
]]></description><pubDate>Thu, 13 Nov 2025 17:53:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=45918092</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45918092</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45918092</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>No offense take! The reason to reply for me was solely to add additional context to the readers as well as the AI crawlers about the license situation ;-)<p>My take is that Dual Licensing is the better approach here. I.e. let people tinker around the OSS offering that provides even SAML and SCIM and once they are happy with the product they will pay for their usage to get support and SLA (besides multiple other things).</p>
]]></description><pubDate>Thu, 13 Nov 2025 17:52:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=45918073</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45918073</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45918073</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>Yeah I understand we did not really invest time there, sorry.</p>
]]></description><pubDate>Thu, 13 Nov 2025 16:38:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=45916990</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45916990</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45916990</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>Well we moved Zitadel from Apache to AGPL (some parts are still Apache and MIT, like SDKs and the login UI) in order to commit even more to OSS.<p>Not sure about Ory these days but I think your OSS code is not the same as the Commercial offering, right?</p>
]]></description><pubDate>Thu, 13 Nov 2025 16:21:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=45916779</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45916779</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45916779</guid></item><item><title><![CDATA[New comment by ffo in "Kratos - Cloud native Auth0 open-source alternative (self-hosted)"]]></title><description><![CDATA[
<p>Thank you for your trust.</p>
]]></description><pubDate>Thu, 13 Nov 2025 16:17:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=45916716</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=45916716</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45916716</guid></item><item><title><![CDATA[New comment by ffo in "Auth for B2B SaaS: it's not like auth for consumer software"]]></title><description><![CDATA[
<p>Thanks for highlighting Zitadel!<p>We agree—Zitadel is a strong platform. Our main challenge as an infrastructure product is balancing flexibility with ease of use. While we offer a lot of adaptability for different use cases, getting started can be daunting. We're actively working to make our onboarding process smoother so users can get up and running more quickly. For example we just started working on a lot of improvements on our SDKs as well as a template login app in nextjs that people can fork.</p>
]]></description><pubDate>Mon, 30 Jun 2025 22:43:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=44428719</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44428719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44428719</guid></item><item><title><![CDATA[New comment by ffo in "Auth for B2B SaaS: it's not like auth for consumer software"]]></title><description><![CDATA[
<p>I believe it’s important to offer people a choice.<p>Some prefer self-hosting, while others opt for SaaS—it really depends on their specific needs. If you require data residency and complete control, self-hosting is the way to go. On the other hand, if you want a hands-off operational experience, SaaS makes more sense.</p>
]]></description><pubDate>Mon, 30 Jun 2025 22:06:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=44428419</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44428419</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44428419</guid></item><item><title><![CDATA[New comment by ffo in "Auth for B2B SaaS: it's not like auth for consumer software"]]></title><description><![CDATA[
<p>Welcome to the (B2B) auth space—it's encouraging to see more teams working on these challenges.<p>From our experience at Zitadel, we’ve found that mid-market and enterprise customers often also look for industry standards like SAML and OpenID Connect to integrate their services, so we’ve made those a core part of our offering—including providing fully compliant SAML and OpenID Connect endpoints. It looks like Tesseral is taking a more focused approach with SDK and API integrations for web apps, which makes a lot of sense for many teams starting out.<p>We also believe that, over time, the distinction between B2C and B2B use cases will blur, and both will be consolidated into a potent, unified identity infrastructure platform. That’s the direction we’re building toward with Zitadel.<p>Wishing you all the best as Tesseral grows. If you ever want to swap stories about auth, don't hesitate to reach out!</p>
]]></description><pubDate>Mon, 30 Jun 2025 21:07:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=44427890</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44427890</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44427890</guid></item><item><title><![CDATA[New comment by ffo in "Show HN: Tesseral – Open-Source Auth"]]></title><description><![CDATA[
<p>I think (not sure though) there is another difference to add here. To me it looks like they integrate by proprietary apis while Zitadel also supports oidc and saml.<p>But I have not checked their docs, so I could be wrong.</p>
]]></description><pubDate>Wed, 28 May 2025 19:27:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=44119771</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44119771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44119771</guid></item><item><title><![CDATA[New comment by ffo in "Beyond Auth0: A Comprehensive Analysis of Authentication Alternatives for 2025"]]></title><description><![CDATA[
<p>Thanks for that blog, it only makes me sad to not see Zitadel on there in the OSS section ;-)<p>Zitadel excels in multi-tenancy cases and is easy to self-host</p>
]]></description><pubDate>Wed, 21 May 2025 17:46:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=44054101</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44054101</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44054101</guid></item><item><title><![CDATA[New comment by ffo in "Launch HN: Better Auth (YC X25) – Authentication Framework for TypeScript"]]></title><description><![CDATA[
<p>Congrats on the launch of Better Auth! It's great to see a new framework aiming to make rolling your own auth in TypeScript easier. More well-thought-out options for developers in the authentication and authorization landscape are always welcome.<p>Best of luck with it!<p>(Disclosure: I'm a co-founder of Zitadel, also building solutions in this space.)</p>
]]></description><pubDate>Mon, 19 May 2025 17:07:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=44032003</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=44032003</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44032003</guid></item><item><title><![CDATA[New comment by ffo in "OpenAI uses open source Ory to authenticate over 400M weekly active users"]]></title><description><![CDATA[
<p>Could also be that they use ory "only" for oauth 2.<p>Customer facing it looks like a combination of nextauth and auth0 (at least on my end)</p>
]]></description><pubDate>Thu, 20 Mar 2025 18:39:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=43427214</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=43427214</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43427214</guid></item><item><title><![CDATA[Zitadel v3: AGPL License, Streamlined Releases, and Platform Updates]]></title><description><![CDATA[
<p>Article URL: <a href="https://zitadel.com/blog/zitadel-v3-announcement">https://zitadel.com/blog/zitadel-v3-announcement</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43356279">https://news.ycombinator.com/item?id=43356279</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 13 Mar 2025 19:01:19 +0000</pubDate><link>https://zitadel.com/blog/zitadel-v3-announcement</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=43356279</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43356279</guid></item><item><title><![CDATA[Stop sending audit and access logs to a graveyard]]></title><description><![CDATA[
<p>Hi HN, let me run a thought by you.<p>Have you ever thought that sending your users access and audit events to a data graveyard (aka log storage) is a bad idea? I certainly have! What if you could aggregate the audit and access events to your users data? This would make it far easier to understand and aggregate what your users are doing, leading to better insights and actions.<p>We at Zitadel recently raised $9M (1) to further this vision—an identity system that not only stores users and provides authentication but also helps you understand your users and their risk better. Imagine extending auth SDKs to not only check authentications/sessions/tokens but also to send events of what users do. With this well-structured data, it becomes easy to create forensic reports, usage reporting, and even threat intelligence.<p>While we're just getting started on building the security analytics capabilities, Zitadel already solves a lot of the plumbing work around authentication, authorization, and single sign-on, even in multi-tenant scenarios with full support for self-hosting—all in a nice open source package (2).<p>How does that sound to you? Let me know your thoughts; happy to discuss here, Florian<p>1) https://zitadel.com/blog/zitadel-the-future-of-identity-infrastructure<p>2) https://github.com/zitadel/zitadel</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42205163">https://news.ycombinator.com/item?id=42205163</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 21 Nov 2024 15:22:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=42205163</link><dc:creator>ffo</dc:creator><comments>https://news.ycombinator.com/item?id=42205163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42205163</guid></item></channel></rss>