Versola - OAuth 2.0/OIDC

Business-Oriented Identity Platform

One login and authorization for every app you build

Built by the engineer who led backend development at Tinkoff ID and took it from thousands of users to 50M. We know exactly where that architecture breaks under load — and built Versola without those failure points, so your team ships product instead of an in-house identity provider.

OAuth 2.0OpenID ConnectSSORBACABACSelf-hostedPasskeysSource-available
V

Sign In

+7 707 ••• •• 47
Continue
or
Sign in with Passkey

Use Face ID to sign in?

A passkey for +7 707 ••• •• 47 will be used to sign in to versola.kz.

Continue

Enter Code

We sent a verification code to +7 707 ••• •• 47

Verify

Enter Password

••••••••
Continue

Why Versola

Full control

Data residency on your terms — your infrastructure, your database, your signing keys.

  • Data residency
  • Self-hosted
  • Source-available

Built around your business

Configurable out of the box, with custom development for your requirements built into the contract.

  • White label
  • Localization
  • Custom development

Security by default

Passwords hashed with Argon2id and a pepper, tokens signed RS256, secrets encrypted AES-256-GCM — nothing to configure by hand.

  • Argon2id + pepper
  • RS256
  • AES-256-GCM
  • Brute-force protection

A reliable stack

Sign-in screens ship at 15–20 KB per form, no client framework. Every OAuth endpoint is traced with OpenTelemetry.

  • PostgreSQL
  • OpenTelemetry
  • Docker

Built for developers

Configure everything from the admin UI, or drive it all through the API — sign-in ships in hours, not sprints.

  • Admin UI
  • REST API
  • OAuth 2.0
  • OpenID Connect

User administration

Roles, active sessions, passkeys, and password resets — all from one console.

  • User search
  • Session management
  • RBAC
  • Passkeys

SSO, registries, and access policy — in one panel

From single sign-on to fine-grained policy — without building your own auth stack

SSO & a single user identity

One account across every app — sessions, passkeys, and roles all visible and revocable from a single admin view.

Versola admin: a user's roles, SSO session, and passkey

Protected resource registry

Wrap any internal API behind edge and describe its endpoints — access to each one is checked independently.

Versola admin: protected resource registry

OAuth client registry

Register web, mobile, and server-to-server clients, define scopes, rotate secrets, and configure the required authentication flow per client — password, OTP, passkey, or a combination of them.

Versola admin: OAuth client registry

Layered, dynamic access policies

A permission grants baseline access, CEL narrows it with a business rule, and step-up authentication covers the sensitive cases.

Versola admin: layered CEL and step-up access policy

Four ways to build your identity infrastructure

The same login box on the surface. Very different bills, compliance exposure and engineering hours underneath.

$0 per MAUYour bill grows by tier, not by every login
100% in countryPersonal data never leaves your jurisdiction
Days, not weeksFrom kickoff to a working login screen — with our help

← Scroll the table to see Keycloak, Auth0, and in-house →

VersolaSelf-hosted · with supportKeycloakSelf-hosted · do it yourselfAuth0 / OktaSaaS · meteredIn-houseYour code · your problem
Price
What you actually pay forA flat license fee within your tier — three paid tiers by user count, never per login.Nothing for the license. Everything for the cluster and the hours.Every monthly active user, every month.Salaries. Authentication becomes a product your team ships forever.
The bill at 50,000 usersThe Starter tier, one affordable flat price — never a per-user meter.Same license, growing operational load.Metered by MAU — $35 covers the first 500, then it’s pay-per-user beyond that¹.No invoice — one or two dedicated engineers at first, and a whole product team once you scale: Tinkoff ID grew that team past 35 people.
Who owns the exitYou: the source, the data and the deployment.You.The vendor: leaving means re-integrating every application.You — along with the obligation to maintain it forever.
Compliance and control
Where personal data is storedYour data centre — in any jurisdiction: the EU for GDPR, Kazakhstan for Law 94-V on personal data, or wherever you decide. Residency is satisfied by design: the database never leaves the country.Same: your own infrastructure.A fixed list: US, EU, UK, Australia, Japan, Canada, India. Residency outside this list is not achievable on standard cloud plans.²Yours by definition — you host it.
Security reviewYour security team reads the whole source.Full source.Vendor certificates instead of code.Full access too — but nobody outside your team has ever seen it.
Time and engineers
Time to a working login screenWe deploy it with you — a working login screen in a few days.HA cluster, realms, themes — weeks of setup.The vendor's SDK in every application.Months of work before it is ready for production traffic.
Authorization inside your servicesEnforced by the edge proxy: roles, permissions and CEL rules, with no code in your apps.Your code in every service — the official adapters are retired.Your code, or a separate paid product.Your code, in every service, and in every new service.
Revoking an access tokenApplies at the edge within seconds.Bounded by token lifetime, unless you introspect on every call.Bounded by token lifetime, unless you introspect on every call.Depends on how you designed token revocation.
Upgrades and CVE patchesWe ship the releases and aim to make upgrades as seamless as possible, you choose the window.Your team, on the project's release cadence.On the vendor's schedule, not yours.You track every CVE in every JWT and crypto library you depend on.
Partnership and fit
Login screens, brand and languageWhite-label screens and any language, edited in the console.Themes exist, but they live in files and deploys, not a console.Customisation within vendor limits.Anything, as long as you build the tooling to manage it.
A feature you need and nobody hasWe build it — custom development is part of the contract.Fork it and maintain the fork yourself.A feature request in the vendor's backlog.You build it yourself — queued behind the rest of the backlog.
Who picks up the phoneThe engineers who wrote it.Community forums, or a paid third party.The support tier you bought.The engineer who wrote it — if they're still on the team.

¹ Auth0 B2C Essentials: $35 covers 500 MAU, then per-user overage (the exact rate isn’t published on their site — only through their own calculator). August 2026.² Published Okta and Auth0 public cloud regions, August 2026.

Four tiers, one flat fee each

Priced by user-count band — never metered by monthly logins

Up to 50 users

Community

Free

Internal, employee-only authentication. Self-hosted, no card required.

Up to 100,000 users

Starter

Flat annual license

Unlocks customer-facing authentication, not just internal tools.

Up to 1,000,000 users

Growth

Flat annual license

Priority support and white-label onboarding as you scale.

Over 1,000,000 users

Enterprise

Flat annual license

Negotiated flat license, audit logging, a dedicated engineer, custom SLA, and roadmap input for regulated environments.

Self-hosted on your infrastructure · Source open for audit on every tier · 90-day evaluation period · Community license

From first request to RFC compliance

Architecture and RFC compliance

Blog

On OAuth, OpenID Connect, and application security

Who is behind this

A small team that has already built an identity platform in production.

Georgii Kovalev

Founder

Key developer of Tinkoff ID and later Head of backend development for the product, leading a team of 12. Tinkoff ID grew from an internal sign-in into a public identity provider. Versola is built on Tinkoff ID's mistakes scaling from thousands to 50M users — we know exactly where that architecture buckles under load, and built these parts differently from day one.

Get started with Versola

Tell us about your needs — we'll help you get up and running quickly.

By submitting this form, you agree to our Privacy Policy and Terms of Service

Thank you!

We've received your request and will get back to you shortly.

⚠️

Error

Couldn't send your request. Please try again later or contact us directly.