Login for your app.
Your database, not ours.

Signet is your login system. People use email, a passkey, or work SSO.

Set up login

We host it. Hobby is $0, one instance each.

SIGNET-CLOUD-TEAM
Hosted production. One instance.
$299/mo
unlimited users
unlimited SSO
card or PO

Unlimited users. Unlimited SSO. Flat price. Hobby is $0, one instance each. Business $999. Scale $15,000/yr. Enterprise quoted. Everything a security review asks for is on one page.

People, services, and agents. One place to switch any of them off.

All three live in the same Postgres, and all three are switched off the same way.
Who signs inWhat they holdHow they arriveHow you cut them off
Peoplea sessionemail, passkey, SSOrevoke
Servicesa tokenminted oncerevoke
Agentsa scoped tokenMCP authrevoke

Your Postgres. Nothing phones home.

Your users are rows in a database dedicated to you. That does not change at renewal.

A sign-in becomes a row in a database that is yours: dump it, leave with it. Hosted, we operate the box and say so on the security page.
The data is yours. So is the way out.
MoveWhat it means
DumpUsers, sessions and secrets are ordinary PostgreSQL rows in a database dedicated to you. Nothing about the format is ours.
LeaveLeaving is a pg_dump. Hosted, we hand you the dump. On your metal, you run it yourself. Restore it. Boot.
Same buildAn enterprise licence runs the same software we host, so your app's code does not change.

No compliance certification is claimed. Hosted signup provisions the instance. On-prem is a licence, not a free download. Every compatibility check we run is published, with the date it ran.

Read the compatibility receipt
Already on better-auth

Change one URL.

The stock client keeps working. Point its baseURL at a Signet instance. The code you ship does not change. We last ran the full check on 2026-07-25.

Holding live users? The cutover is a written runbook: user rows, password hashes and live sessions copy across. Nobody resets a password. If you roll back, every pre-cutover session is still valid.

auth-client.ts
// your existing better-auth client
- baseURL: "https://your-current-auth.example.com"
+ baseURL: "https://auth.yourcompany.com"

// every call you already wrote keeps working
$ bun add better-auth The stock client, unchanged

What ships today.

Email + password Passkeys Magic links Email codes Two-factor with backup codes Social sign-in Organisations + invitations API keys Device codes MCP auth for AI agents Agent tokens that expire in minutes Session + token revocation

All of this works today. Two things are not finished: SAML SSO is proven against a conformance identity provider but not yet against the commercial ones, and the OAuth provider surface ships its core flow only. The full ledger is on the product page.

$299 a month. Same bill.

One enterprise customer or forty. Unlimited users and unlimited enterprise SSO connections are included. The next deal adds revenue, not a line item. Most vendors bill SSO per connection. Signet does not. The price is effective 2026-08-07.

The next deal adds revenue, not a line item.
Hobby
$0
Login for your app: email, passkeys, magic links, codes, two-factor, Google-style sign-in. Teams and invites. A few short-lived agent tokens. Company single sign-on (SSO), machine tokens and always-on agents start on Team. One instance per company. No SLA.
Start on Hobby →
Team
$299/mo
Flat. Unlimited users, unlimited SSO.
Start on Team →
Business
$999/mo
Flat. Staging, priority support.
Start on Business →
Scale · on-prem
$15,000/yr
The same build, on your metal. Standard terms.
What the licence covers →

Enterprise, with air-gap and a named contract, is quoted. The vendor pack is what your reviewer attaches.

Get an instance. Point your client at it.

Signup provisions the instance. On-prem is a licence. The Friday questions are on /faq. The argument is on /friday.