<!-- https://docs.elchi.dev/eauth | EAuth | Elchi Docs -->

# EAuth

Authentication for your application, using the same standards everyone else
uses, without the pricing that starts the day you succeed.

EAuth is an OAuth 2.1 and OpenID Connect provider built and operated by
[Elchi Studios](https://elchi.dev) in Oberägeri, canton Zug, Switzerland.

## What you get

- **The authorization code flow with PKCE.** Nothing else, because RFC 9700
  deprecated the alternatives and we did not implement them.
- **OpenID Connect**, so any standard library configures itself from one
  discovery URL.
- **Two-factor authentication** with recovery codes, included rather than sold
  as an upgrade.
- **[Organisations](/organisations)**, if you sell to companies and need
  employees grouped by employer with per-employer roles.
- **A hosted sign-in page** that carries your name, your colour and your logo.

## What it costs

Nothing. There is no paid tier, no user limit, and no point at which growth
turns into an invoice.

There is also no availability guarantee, and we say so in the
[terms](https://elchi.dev/en/legal/eauth-terms) rather than publishing a number we are
not paid to underwrite. If minutes of downtime are unacceptable to you, run it
yourself.

## Why you could leave

The export includes your users' password hashes in their original form. You can
migrate to another provider without forcing anyone to reset a password.

That is deliberate. The largest switching cost in this market is an export that
omits the hashes, and a provider that keeps you by making leaving painful has
stopped competing on the product.

## Start here

The [quickstart](/quickstart) takes about ten minutes and ends with a working
sign-in. The [playground](/playground) generates a real authorization request
you can paste into a browser.
