Business-Oriented Identity Platform
Built by the engineer who led backend development at Tinkoff ID and took it from thousands of users to 50M. We know exactly where that architecture breaks under load — and built Versola without those failure points, so your team ships product instead of an in-house identity provider.
A passkey for +7 707 ••• •• 47 will be used to sign in to versola.kz.
We sent a verification code to +7 707 ••• •• 47
Data residency on your terms — your infrastructure, your database, your signing keys.
Configurable out of the box, with custom development for your requirements built into the contract.
Passwords hashed with Argon2id and a pepper, tokens signed RS256, secrets encrypted AES-256-GCM — nothing to configure by hand.
Sign-in screens ship at 15–20 KB per form, no client framework. Every OAuth endpoint is traced with OpenTelemetry.
Configure everything from the admin UI, or drive it all through the API — sign-in ships in hours, not sprints.
Roles, active sessions, passkeys, and password resets — all from one console.
From single sign-on to fine-grained policy — without building your own auth stack
One account across every app — sessions, passkeys, and roles all visible and revocable from a single admin view.

Wrap any internal API behind edge and describe its endpoints — access to each one is checked independently.

Register web, mobile, and server-to-server clients, define scopes, rotate secrets, and configure the required authentication flow per client — password, OTP, passkey, or a combination of them.

A permission grants baseline access, CEL narrows it with a business rule, and step-up authentication covers the sensitive cases.

Comparison
The same login box on the surface. Very different bills, compliance exposure and engineering hours underneath.
← Scroll the table to see Keycloak, Auth0, and in-house →
| VersolaSelf-hosted · with support | KeycloakSelf-hosted · do it yourself | Auth0 / OktaSaaS · metered | In-houseYour code · your problem | |
|---|---|---|---|---|
| Price | ||||
| What you actually pay for | A flat license fee within your tier — three paid tiers by user count, never per login. | Nothing for the license. Everything for the cluster and the hours. | Every monthly active user, every month. | Salaries. Authentication becomes a product your team ships forever. |
| The bill at 50,000 users | The Starter tier, one affordable flat price — never a per-user meter. | Same license, growing operational load. | Metered by MAU — $35 covers the first 500, then it’s pay-per-user beyond that¹. | No invoice — one or two dedicated engineers at first, and a whole product team once you scale: Tinkoff ID grew that team past 35 people. |
| Who owns the exit | You: the source, the data and the deployment. | You. | The vendor: leaving means re-integrating every application. | You — along with the obligation to maintain it forever. |
| Compliance and control | ||||
| Where personal data is stored | Your data centre — in any jurisdiction: the EU for GDPR, Kazakhstan for Law 94-V on personal data, or wherever you decide. Residency is satisfied by design: the database never leaves the country. | Same: your own infrastructure. | A fixed list: US, EU, UK, Australia, Japan, Canada, India. Residency outside this list is not achievable on standard cloud plans.² | Yours by definition — you host it. |
| Security review | Your security team reads the whole source. | Full source. | Vendor certificates instead of code. | Full access too — but nobody outside your team has ever seen it. |
| Time and engineers | ||||
| Time to a working login screen | We deploy it with you — a working login screen in a few days. | HA cluster, realms, themes — weeks of setup. | The vendor's SDK in every application. | Months of work before it is ready for production traffic. |
| Authorization inside your services | Enforced by the edge proxy: roles, permissions and CEL rules, with no code in your apps. | Your code in every service — the official adapters are retired. | Your code, or a separate paid product. | Your code, in every service, and in every new service. |
| Revoking an access token | Applies at the edge within seconds. | Bounded by token lifetime, unless you introspect on every call. | Bounded by token lifetime, unless you introspect on every call. | Depends on how you designed token revocation. |
| Upgrades and CVE patches | We ship the releases and aim to make upgrades as seamless as possible, you choose the window. | Your team, on the project's release cadence. | On the vendor's schedule, not yours. | You track every CVE in every JWT and crypto library you depend on. |
| Partnership and fit | ||||
| Login screens, brand and language | White-label screens and any language, edited in the console. | Themes exist, but they live in files and deploys, not a console. | Customisation within vendor limits. | Anything, as long as you build the tooling to manage it. |
| A feature you need and nobody has | We build it — custom development is part of the contract. | Fork it and maintain the fork yourself. | A feature request in the vendor's backlog. | You build it yourself — queued behind the rest of the backlog. |
| Who picks up the phone | The engineers who wrote it. | Community forums, or a paid third party. | The support tier you bought. | The engineer who wrote it — if they're still on the team. |
¹ Auth0 B2C Essentials: $35 covers 500 MAU, then per-user overage (the exact rate isn’t published on their site — only through their own calculator). August 2026.² Published Okta and Auth0 public cloud regions, August 2026.
Pricing
Priced by user-count band — never metered by monthly logins
Up to 50 users
Free
Internal, employee-only authentication. Self-hosted, no card required.
Up to 100,000 users
Flat annual license
Unlocks customer-facing authentication, not just internal tools.
Up to 1,000,000 users
Flat annual license
Priority support and white-label onboarding as you scale.
Over 1,000,000 users
Flat annual license
Negotiated flat license, audit logging, a dedicated engineer, custom SLA, and roadmap input for regulated environments.
Self-hosted on your infrastructure · Source open for audit on every tier · 90-day evaluation period · Community license
Documentation
Architecture and RFC compliance
On OAuth, OpenID Connect, and application security
A small team that has already built an identity platform in production.
Founder
Key developer of Tinkoff ID and later Head of backend development for the product, leading a team of 12. Tinkoff ID grew from an internal sign-in into a public identity provider. Versola is built on Tinkoff ID's mistakes scaling from thousands to 50M users — we know exactly where that architecture buckles under load, and built these parts differently from day one.
Tell us about your needs — we'll help you get up and running quickly.