# Elchi Docs > Documentation for what Elchi Studios, a web agency in Oberägeri, Switzerland, > makes: EAuth, a free OAuth 2.1 and OpenID Connect provider; EMX, > business mail with an API and webhooks; and the technical standard > every Elchi website is built to. ## Facts - EAuth: free, no paid tier, no user limits; OAuth 2.1, OpenID Connect Core, RFC 9700; authorization code with PKCE S256 only; TOTP second factor; self-hostable single Go binary - EAuth discovery: https://eauth.me/.well-known/openid-configuration - EMX: mail on your own domain, web client and IMAP, API at https://mail.emxmail.app/api, OpenAPI at https://mail.emxmail.app/api/openapi.json, webhooks, sealed mailboxes; Private plan free, Team CHF 4 per mailbox and month - Data location: Switzerland and the EU - Console: https://panel.elchi.dev - Operator: Elchi Studios, Oberägeri, canton Zug, Switzerland, contact@elchi.dev ## Pages ### EAuth Sign-in for your application on the standards everyone uses, with a second factor, organisations and an export that lets you leave. Free, without user limits. - [EAuth](https://docs.elchi.dev/eauth): A free, self-hostable OAuth 2.1 and OpenID Connect provider. No user limits, no paid tier, and an export that lets you leave. - [Login with EAuth](https://docs.elchi.dev/quickstart): Add sign-in to your application in about ten minutes, from registering a client to reading the user's email address. - [Playground](https://docs.elchi.dev/playground): Build a real authorization request from your own client id, with a live PKCE pair and the exact commands for each step. - [JavaScript SDK](https://docs.elchi.dev/sdk): Add EAuth to React, Svelte, Nuxt or any web page, with the checks the specifications require already done. - [Migrating from another provider](https://docs.elchi.dev/migrating): Import your users with their existing password hashes, so nobody has to reset a password to follow you. - [Passkeys](https://docs.elchi.dev/passkeys): Phishing-resistant sign-in with WebAuthn, on for every application, with nothing to configure. - [Organisations](https://docs.elchi.dev/organisations): Group the people who use your product by the company they work for, with a role in each, and read both from the tokens. - [Enterprise SSO with SAML](https://docs.elchi.dev/enterprise-sso): Let your customers' employees sign in through their own identity provider, without your application knowing anything about SAML. - [Webhooks](https://docs.elchi.dev/webhooks): Be told when somebody signs up, signs in or revokes access, with signed deliveries, retries and a stable id for deduplication. - [Security](https://docs.elchi.dev/security): What EAuth does to protect an account, which standards it follows, and what it deliberately does not implement. - [EAuth compared](https://docs.elchi.dev/comparison): An honest comparison against Auth0, Clerk, WorkOS, Stytch, Zitadel, Supabase and others, with their published prices, export rules and data locations, and where EAuth is the weaker choice. - [Changelog](https://docs.elchi.dev/changelog): Every notice to developers about EAuth, the changes to the terms, the sub-processors and to integrations, with the day each takes effect. - [Sub-processors](https://docs.elchi.dev/subprocessors): The companies that process end-user data on our behalf when you use EAuth, what each one sees, where, and how you are told before one is added. ### EMX Mail on your own domain, in the browser and in every mail app, with the API the web client itself uses, signed webhooks and mailboxes that can be sealed. - [EMX](https://docs.elchi.dev/emx): Hosted business mail on your own domain, with the API the web client itself uses, signed webhooks, IMAP for every mail app, and mailboxes that can be sealed so that only the person's own devices can open them. - [EMX quickstart](https://docs.elchi.dev/emx-quickstart): Make a token, read your inbox, send a message, and get told when a reply arrives. Five minutes with curl. - [EMX webhooks](https://docs.elchi.dev/emx-webhooks): Be told when a message arrives or a delivery fails, with signed requests, retries over a day, and a delivery id to deduplicate on. - [EMX in mail apps](https://docs.elchi.dev/emx-mail-apps): IMAP and SMTP settings, app passwords, autoconfiguration for Thunderbird and Outlook, and the Apple profile that sets up an iPhone in one tap. - [EMX API reference](https://docs.elchi.dev/emx-api): Every endpoint of the EMX API, the one the web client uses, with scopes, shapes and the rules behind them. - [EMX error codes](https://docs.elchi.dev/emx-errors): Every code the EMX API answers with, what it means and what to do; the docs link in each error points here. - [EMX compared](https://docs.elchi.dev/emx-comparison): EMX against Infomaniak, Hostpoint, Proton, Fastmail, Google Workspace, Microsoft 365, mailbox.org, Tuta and Migadu, with their published prices, where their mail lives, how you leave, and where EMX is the weaker choice. - [EMX acceptable use and abuse](https://docs.elchi.dev/emx-abuse): What EMX may not be used for, the sending limits of each plan, how to report spam, phishing or malware sent from EMX to abuse@emxmail.ch, and what happens to a report. - [EMX and requests from authorities](https://docs.elchi.dev/emx-authorities): When EMX hands data to Swiss authorities, why foreign authorities must go through mutual legal assistance, which data exists and for how long, and what a sealed mailbox means for a request. ### Web standards The technical standard every Elchi Studios site is built to, with the tools named so each claim can be checked. - [How we build a website](https://docs.elchi.dev/standards): The technical standard every Elchi Studios site is built to, and how each claim on it is measured.