Migration & portability

Switch without the fear.
Migrate in, export anytime.

Move off Auth0, Okta, Cognito or Firebase without forcing a single password reset. Built on open standards, so you're never locked in — and a one-click export means your data is always yours to take back.

import APIs + guided migration · no proprietary formats · own your data

Import from anywhere

Bring your users with you. No reset required.

Our import APIs and guided migration move users, password hashes, connections, roles and groups across — so the day you cut over feels like nothing changed.

Auth0
User export + tenant config
Okta
Users, groups, SAML apps
Cognito
User pools + identity providers
Firebase
Auth users + hash params

Password-hash passthrough

We import bcrypt, scrypt and argon2 hashes as-is and verify against them on first login. Your users never see a forced reset.

User profiles + metadata

Emails, names, verified status, custom attributes and app metadata map straight into AuthFI user records.

SAML & OIDC connections

Re-create enterprise SSO connections — IdP metadata, ACS URLs, claim mappings — as standard SAML 2.0 / OIDC.

Roles & groups

Existing roles and group membership import into AuthFI RBAC, ready for JIT provisioning on day one.

SCIM directories

Keep your IdP-driven provisioning — SCIM in continues pushing creates, updates and deactivations as before.

MFA enrollments

TOTP seeds carry over where the source exposes them; passkeys are re-enrolled on first sign-in (they're bound to the authenticator and cannot be transferred between vendors).

hash_algo: bcrypt | scrypt | argon2id  →  verify-on-login  →  rehash transparently

Standards-first

Open protocols mean no proprietary lock-in.

AuthFI speaks the same standards everyone else does — so the integrations you build are portable by construction. Nothing about your setup is trapped behind an AuthFI-only format.

  • SAML 2.0 — Enterprise SSO with any IdP. SP and IdP initiated, signed assertions.
  • OIDC — OpenID Connect for apps and APIs. Standard discovery and JWKS.
  • SCIM 2.0 — Provisioning in and out. Standard schema, standard endpoints.
  • OAuth 2.1 — PKCE-required flows. No proprietary auth dance to reimplement.
The portability test
Can you re-point SSO at another vendor?
Yes — it's standard SAML / OIDC metadata.
Can your provisioning survive a move?
Yes — SCIM 2.0 is the same everywhere.
Do your apps need rewriting to leave?
No — OAuth 2.1 / OIDC tokens are standard.
Is anything in an AuthFI-only format?
No — open standards in, open standards out.

Full export

Your data is never held hostage.

Anti-lock-in isn't a promise — it's an export button. Your users, roles and audit trail are yours, available on demand, in standard formats.

JSON / CSV

Users & profiles

Full user records with attributes and metadata. Hashes export so you can keep the no-reset promise on your way out too.

JSON

Roles & groups

Your complete RBAC model — roles, permissions, group membership — exported as portable structured data.

JSON / SIEM

Audit log

The tamper-evident Merkle audit trail is yours. Export every decision, or stream live to your SIEM.

One-click export, anytime From the console or the Management API. No support ticket, no waiting period, no exit fee.
POST /v1/export

White-label

Your brand stays yours.

Migration shouldn't mean your users notice a new vendor. With white-label login, portal and emails, AuthFI runs entirely under your name and your domain — there's no third-party logo for anyone to see.

  • Your domain — login. and accounts. on your own custom domain, your own TLS.
  • Your branding — Logo, colors and copy across login, the user portal and email.
  • Your users' trust — Familiar experience through the cut-over — nothing looks rebadged.

The path

A calm, three-step migration.

No big-bang weekend. Import, run both side by side until you trust it, then flip the switch.

1 Import

Bring users, hashes, connections, roles and SCIM across with the import APIs and guided migration. No password resets.

users + hashes + config
2 Dual-run & verify

Run AuthFI alongside your current IdP. Route a slice of traffic, compare results, watch the audit log — until you trust it.

side-by-side · verify
3 Cut over

Flip DNS / app config to AuthFI. Users keep their passwords and sessions feel seamless. Old vendor goes dark.

flip · done

rollback at any step — you never burn a bridge until cut-over

The only lock-in is wanting to stay.

Migrate in without a single reset. Export everything whenever you like. Start free, or let our team plan the move with you.