Migration & portability
Switch without the fear.
Migrate in, export anytime.
Move off Auth0, Okta, Cognito or Firebase without forcing a single password reset. Built on open standards, so you're never locked in — and a one-click export means your data is always yours to take back.
import APIs + guided migration · no proprietary formats · own your data
Import from anywhere
Bring your users with you. No reset required.
Our import APIs and guided migration move users, password hashes, connections, roles and groups across — so the day you cut over feels like nothing changed.
Password-hash passthrough
We import bcrypt, scrypt and argon2 hashes as-is and verify against them on first login. Your users never see a forced reset.
User profiles + metadata
Emails, names, verified status, custom attributes and app metadata map straight into AuthFI user records.
SAML & OIDC connections
Re-create enterprise SSO connections — IdP metadata, ACS URLs, claim mappings — as standard SAML 2.0 / OIDC.
Roles & groups
Existing roles and group membership import into AuthFI RBAC, ready for JIT provisioning on day one.
SCIM directories
Keep your IdP-driven provisioning — SCIM in continues pushing creates, updates and deactivations as before.
MFA enrollments
TOTP seeds carry over where the source exposes them; passkeys are re-enrolled on first sign-in (they're bound to the authenticator and cannot be transferred between vendors).
hash_algo: bcrypt | scrypt | argon2id → verify-on-login → rehash transparently
Standards-first
Open protocols mean no proprietary lock-in.
AuthFI speaks the same standards everyone else does — so the integrations you build are portable by construction. Nothing about your setup is trapped behind an AuthFI-only format.
- SAML 2.0 — Enterprise SSO with any IdP. SP and IdP initiated, signed assertions.
- OIDC — OpenID Connect for apps and APIs. Standard discovery and JWKS.
- SCIM 2.0 — Provisioning in and out. Standard schema, standard endpoints.
- OAuth 2.1 — PKCE-required flows. No proprietary auth dance to reimplement.
Full export
Your data is never held hostage.
Anti-lock-in isn't a promise — it's an export button. Your users, roles and audit trail are yours, available on demand, in standard formats.
Users & profiles
Full user records with attributes and metadata. Hashes export so you can keep the no-reset promise on your way out too.
Roles & groups
Your complete RBAC model — roles, permissions, group membership — exported as portable structured data.
Audit log
The tamper-evident Merkle audit trail is yours. Export every decision, or stream live to your SIEM.
White-label
Your brand stays yours.
Migration shouldn't mean your users notice a new vendor. With white-label login, portal and emails, AuthFI runs entirely under your name and your domain — there's no third-party logo for anyone to see.
- Your domain — login. and accounts. on your own custom domain, your own TLS.
- Your branding — Logo, colors and copy across login, the user portal and email.
- Your users' trust — Familiar experience through the cut-over — nothing looks rebadged.
The path
A calm, three-step migration.
No big-bang weekend. Import, run both side by side until you trust it, then flip the switch.
Bring users, hashes, connections, roles and SCIM across with the import APIs and guided migration. No password resets.
Run AuthFI alongside your current IdP. Route a slice of traffic, compare results, watch the audit log — until you trust it.
Flip DNS / app config to AuthFI. Users keep their passwords and sessions feel seamless. Old vendor goes dark.
rollback at any step — you never burn a bridge until cut-over
The only lock-in is wanting to stay.
Migrate in without a single reset. Export everything whenever you like. Start free, or let our team plan the move with you.