EN
Get started free

Identity provider for small and medium businesses

Manage identities with simplicity

BreezeAuth gives your team centralized authentication, single sign-on and user management for every application you use. Connect any SAML 2.0 or OIDC app in minutes, not weeks.

Free plan · No credit card required

  • Single Sign-On for your applications
  • Built-in multi-factor authentication
  • Real-time audit logs

Works with any application that speaks SAML 2.0 or OpenID Connect

  • SAML 2.0
  • OpenID Connect
  • OAuth 2.0
  • TOTP
  • Passkeys (WebAuthn)

Features

Everything an identity provider should do. Nothing you don't need.

Enterprise-grade access control, packaged for teams that don't have an identity department.

  • Single sign-on via SAML 2.0 and OIDC

    Register any application as a SAML 2.0 or OpenID Connect service provider, assign it to people or groups and let your team sign in once.

  • Managed and guest users

    Verify your domains with a DNS record. Accounts on a verified domain become managed and follow your policies; partners and vendors stay as guests with more autonomy.

  • Groups, nested groups and assignments

    Organize people into groups, nest groups inside other groups and assign applications once for everyone underneath.

  • MFA and passkeys

    Built-in TOTP multi-factor authentication and passkeys. Make MFA mandatory for the whole organization with a single switch.

  • Password and session policies

    Set minimum length, expiration, blocked reuse and rejection of breached passwords. Tune maximum session duration and idle timeout to fit your risk.

  • Network and country restrictions

    Limit access to authorized CIDR blocks, and allow or block entire countries based on the IP address of whoever is connecting.

  • Incident response

    End every active session, force a password change on the next sign-in or lock access to all applications at once, in a single click.

  • Full audit log coverage

    Every sign-in, configuration change, assignment and access attempt is recorded in real time, so you always know who did what, and when.

  • Administrative roles

    Delegate with Owner, Administrator, Helpdesk, Auditor and Billing roles. Owner assignment and removal carry extra confirmation and password checks.

  • Service users and API access

    Dedicated, non-human accounts that call the BreezeAuth API from your own scripts and systems, so user creation, group changes and audit exports run inside the integrations you already operate.

  • SCIM 2.0 provisioning

    Coming soon

    Keep identities in sync automatically. Outbound SCIM pushes users and groups to connected applications; inbound SCIM lets an HR system or upstream directory create, update and deactivate accounts in BreezeAuth.

  • Webhooks

    Coming soon

    Notify your own systems whenever an event happens in BreezeAuth, so they can react immediately — user changes, sign-ins, configuration updates and more, without polling the API.

Beyond the basics

Serious SSO, without the enterprise price tag

The details that usually force an upgrade to an enterprise plan are part of BreezeAuth from day one.

  • Attribute and claim mapping

    Decide exactly which SAML attributes and OIDC claims each application receives. Map user fields, add constant values or compute values with CEL expressions.

  • Derived attributes

    Build attributes from membership and assignment data, so each application gets the shape of identity it expects without changing your user records.

  • Entitlements and assignment attributes

    Send roles and per-assignment attributes along with the identity, so the application knows not only who signed in but what they are allowed to do.

  • Custom signing certificates

    Bring your own signing certificate per application, rotate it when you need to and require signed SAML AuthnRequests for stricter integrations.

How it works

Up and running in three steps

No consultants, no week-long onboarding. If you can add a DNS record, you can run BreezeAuth.

  1. 1

    Create your organization

    Sign up, create your organization and verify your domain with a simple TXT record.

  2. 2

    Add your people

    Invite users, organize them into groups and set your security policies: MFA, passwords and session limits.

  3. 3

    Connect your applications

    Register each app as a SAML 2.0 or OIDC service provider, assign it to groups and you're done.

Why BreezeAuth

Built for the way small businesses actually work

We took the controls large enterprises rely on and removed everything that made them slow, expensive and hard to run. The enterprise-grade parts stay, so nothing has to be replaced when your team grows.

  • Simple by design

    A clean admin console and an end-user portal that need no training. Sensible defaults everywhere.

  • Three languages

    Admin console, end-user portal and support in Portuguese, English and Spanish.

  • Security that scales down

    Mandatory MFA, network restrictions and incident response, packaged so a five-person company can turn them on in an afternoon.

  • Ready when you grow

    The same protocols, policies and audit trail large organizations require are already here. Add people and applications and you grow inside BreezeAuth instead of migrating away from it.

Pricing

Start free. Grow when you're ready.

Simple, transparent plans. No hidden fees.

Grow

Get a quote

Contact us

For growing teams that need more seats, more applications and priority support.

  • Everything in Start
  • SCIM 2.0 provisioning
  • Service users
  • API access
  • Unlimited users and applications
  • Priority support
  • Unlimited audit log retention
  • Billing in Brazilian reais

FAQ

Frequently asked questions

What is an identity provider?

An identity provider (IdP) is the central place where your people sign in. Instead of every application keeping its own passwords, applications trust BreezeAuth to authenticate users and tell them who has signed in.

Which applications can I connect?

Any application that supports SAML 2.0 or OpenID Connect as a service provider. That covers most SaaS products as well as internal applications built with standard libraries.

What is the use case for a service user?

A service user is a dedicated, non-human account that lets your systems call the BreezeAuth APIs without using a person's credentials. You can create and update users, manage groups and application assignments, or pull audit data from scripts, internal tools and the platforms you already run — so BreezeAuth can sit alongside an HR system, a custom admin portal or any other service in your stack, instead of becoming another console your team has to operate by hand.

What are SAML, OIDC and SCIM?

SAML 2.0 and OpenID Connect (OIDC) are the standard protocols applications use to trust an identity provider for single sign-on. SAML is widely used by enterprise SaaS; OIDC is built on OAuth 2.0 and is common in modern web and API applications. SCIM 2.0 is a separate standard for provisioning: it lets connected applications automatically create, update and deactivate user accounts so identity stays in sync without manual work.

Is the Start plan really free?

Yes. The Start plan doesn't require a credit card and doesn't expire. If you need more, talk to us about the Grow plan.

Do I need to be in Brazil to use BreezeAuth?

No. BreezeAuth is built in Brazil and offered in Portuguese, English and Spanish, but organizations from anywhere can sign up.

What is the difference between managed and guest accounts?

Managed accounts belong to a verified organization domain and follow your password, MFA and session policies. Guest accounts, such as partners and vendors, keep more autonomy and are not subject to those policies.

Can I make MFA mandatory?

Yes. Turn on mandatory MFA in the organization's security settings and every member will be required to enable it before continuing.

Ready to simplify sign‑in for your team?

Create your organization in minutes. Free plan, no credit card required.