v1.0 · 341 commands · production-ready

Auth, payments, licensing.
All of it. None of the BS.

The auth platform that doesn't make you choose between Auth0, Clerk, WorkOS, Stripe, Paddle, Twilio, and SendGrid. Bastionary ships them all behind one API, one binary, one bill — and beats every one of them on price, speed, and security.

Start free → Read the docs
341
Commands
55+
Admin pages
5
Payment PSPs
6
SMS Providers
6
Email Providers
0
Vendor Lock-in
Production: 1700 req/s · 0.6 ms p50 · 0 failed · measured live
Features

Everything. In one binary.

No assembling 7 SaaS subscriptions. No glue code between Auth0 and Stripe. Just one API.

🔐

Authentication

JWT (RS256/ES256/EdDSA), WebAuthn passkeys, TOTP MFA, SMS auth, social OAuth (Google, GitHub, Discord, Slack, GitLab, LinkedIn), magic links, guest tokens.

🏢

Enterprise SSO

SAML 2.0, OIDC, SCIM provisioning, LDAP sync. Self-serve enterprise connections — no sales call required to flip on Okta.

💳

Multi-PSP Payments

Stripe, Paddle, Lemon Squeezy, PayPal, Coinbase Commerce. Switch processors without rewriting checkout. One license model. Never get stuck on one rail again.

🛡️

Adaptive Risk Engine

Every login scored. New device, new geo, no MFA, weird hours — composite score forces step-up before the bad guys are inside.

📜

FGA / ReBAC

Zanzibar-style relation-based access control. Plus RBAC + ABAC + role hierarchies + nested orgs. Pick your poison — they all compose.

📨

Notifications, Unbundled

SMS via Twilio, Vonage, AWS SNS, MessageBird, Plivo. Email via SendGrid, Postmark, Mailgun, AWS SES, Resend, SMTP. One API, six vendors each.

⚖️

OPA-Style Policy Engine

Namespace-scoped authorization rules evaluated at runtime. POLICY.EVAL returns allow/deny/challenge per request context. No external policy server needed.

🔄

Subscription Lifecycle

Pause, resume, downgrade, cancel — with prorations. Dunning management, grace periods, overdue suspension. Full billing lifecycle without Stripe Billing lock-in.

🔑

Signing Keys & Secrets

JWK lifecycle (create, rotate, revoke, JWKS endpoint). Vault-style secret leasing and rotation. TLS cert issuance via ACME/Let's Encrypt. DPoP support built in.

🌐

Service Mesh & Infra

Service registry, health checks, canary deployments, config management, LB strategies, network isolation. The infra primitives you'd otherwise bolt on separately.

📦

Products, Downloads & Licenses

Define products (one-time, subscription, usage). Gate downloads by license. Manage installs per device. Floating licenses. Entitlements. Update channels.

🖥️

Full Admin Dashboard

55+ built-in admin pages covering all 341 commands: users, teams, billing, audit, webhooks, feature flags, DPoP bindings, JIT provisioning, threat intel, session management, app registry, auth methods, and more — no custom dashboard to build.

Developer Experience

One API. Every feature.

A single /api/v1/execute endpoint runs all 341 commands. Or use the typed SDK. Or the CLI.

# Switch payment processor at runtime — no code changes
$ bastionary providers set-default payments paddle

# Score a login attempt
$ bastionary exec RISK.ASSESS --params '{"is_new_device": true, "mfa_enabled": false}'
{
  "score": 35,
  "band": "medium",
  "reasons": ["no_mfa_enrolled", "new_device"]
}

# Or hit the API directly — same surface
$ curl -X POST https://your-instance/api/v1/execute \
    -H "Authorization: Bearer $TOKEN" \
    -d '{"command": "PAYMENT.CHECKOUT", "params": {"product_slug": "pro"}}'
Providers

Switch vendors in one command.

Lock-in is theft. Bastionary speaks every major provider so you can change your mind on Tuesday.

Payments

  • • Stripe
  • • Paddle Billing v2
  • • Lemon Squeezy
  • • PayPal
  • • Coinbase Commerce

SMS

  • • Twilio
  • • Vonage
  • • AWS SNS
  • • MessageBird
  • • Plivo
  • • HTTP webhook

Email

  • • SendGrid
  • • Postmark
  • • Mailgun
  • • AWS SES
  • • Resend
  • • SMTP
vs The World

One bill. Six tools. Zero glue.

BastionaryAuth0ClerkWorkOSStripe
Authentication
SAML / SCIM✓ (Enterprise)✓ (Pro)
Multi-PSP Payments✓ 5 vendorsStripe only
Multi-vendor SMS✓ 6 vendors
FGA / ReBAC✓ (FGA addon)
Adaptive Risk Engine✓ Built-in✓ (Enterprise)
Policy Engine (OPA-style)
Subscription lifecycle✓ Full
Signing key management✓ JWK+ACME✓ (managed)✓ (managed)✓ (managed)
Software licensing✓ Built-in
Admin dashboard✓ 50+ pages
Self-hostable
One bill

Ship in an afternoon.

Not a six-week vendor evaluation.

Start free → Read the docs