For Authentik, Okta, and Auth0
Your identity provider has no undo button. Now it does.
IdPVault is self-hosted backup, drift detection, and restore for your IdP. Encrypted snapshots of every app, flow, policy, user, and assignment - diffable, restorable, and entirely on your hardware.
Click the screenshot to enlarge and scroll through more of the platform
374 objects across 12 types in a single snapshot · One compose file, any platform (amd64 + arm64) · Open-core on GitHub, full changelog published
Know what changed.
Every backup diffs against the last. A deleted flow, a modified policy, a new admin - it shows up in your events feed and your inbox, not in a postmortem.
Get it back.
Config restore with dry-run preview: see exactly what would change before it changes. Users & Access restore brings back users, group memberships, and app assignments. Or clone a whole tenant into another instance - and every apply is recorded with who, what, and why.
Own your data.
Self-hosted, encrypted at rest, zero telemetry. The only thing IdPVault ever sends us is your license id - never your tenants, never your data. The free tier never talks to anyone at all.
Everything a backup tool owes you
Config backup
Applications, providers, flows, stages, policies, groups, mappings - snapshotted on your schedule, encrypted before they touch disk.
Drift detection
The unbacked-changes counter reads the provider's own event log, so you know about changes before your next backup runs.
Config restore
Selective restore with a dry-run preview of every add, update, and delete. Every apply is recorded: who ran it, what changed object by object, and why.
Clone & promote
Clone a whole tenant into another instance of the same provider - staging to prod, standby seeding, disaster recovery. Previewed first, matched by name, secrets never copied.
Users & Access
Back up and restore users, memberships, and app assignments across all three providers. Business and MSP plans.
Terraform export
Turn any object or a whole snapshot into hand-written-quality Terraform with import blocks, so terraform adopts what exists instead of recreating it. Secrets become variables, never code. Business and MSP plans.
Alerts
Email or webhook on drift, failures, restores, and clones - you choose what is worth waking up for.
Security
Envelope encryption (AES-256-GCM), scrypt passwords, TOTP MFA, server-side sessions, audit log, roles enforced at the API.
Zero-config deploy
One compose file. Linux, macOS, Windows, ARM - amd64 and arm64 images under a single tag.
Up and running in four steps
docker compose up
No config required - keys generate themselves on first boot.
Connect a tenant
Paste an API token. It is encrypted immediately (AES-256-GCM) and never stored in plain text.
Backups run themselves
Schedules run in your timezone; every change is diffed, logged, and alertable.
Restore anything
From any snapshot, selectively. Dry-run first, always.
Clone & promote
One tenant becomes two
Apply any snapshot into a different tenant of the same provider: promote staging to production, seed a warm standby, or rebuild after a disaster - config, Users & Access, or both in one pass. Objects pair by name, never by internal ids, so a clone lands cleanly in an instance that has never seen your source.
Every clone starts with a read-only preview, requires a justification and your password with the write direction spelled out, runs in the background with real progress, and ends with a per-object report in the target's restore history - exactly what applied, what failed, and why. Secrets are never copied; recreated apps get new credentials, listed by name.
We validated it by cloning our own production Authentik - every failure in the report is explained, down to the license-gated provider and two bindings that were already orphaned in the source.
Terraform export
From ClickOps to Terraform in one click
Click any object in Live State and get a Terraform block that reads like a senior engineer wrote it - or export a whole snapshot as a ready-to-run bundle. Every attribute is validated against the official provider schemas for Okta, Auth0, and Authentik, so nothing is invented and nothing is silently dropped.
Import blocks are generated with each resource's real import id, so Terraform adopts what already exists instead of recreating it. Secrets are never written into code - they become typed sensitive variables. References between objects become Terraform expressions, so a block promoted from staging resolves cleanly in production.
We proved it on our own production Authentik: a full-tenant export planned as 365 resources to import, zero to add, zero to destroy. Included with Business and MSP plans.
resource "okta_app_saml" "dynatrace" {
label = "Dynatrace"
status = "ACTIVE"
sso_url = "https://acme.live.dynatrace.com/csp/md"
audience = "https://acme.live.dynatrace.com"
user_name_template = "${source.login}"
#accessibility_error_redirect_url = ""
attribute_statements {
name = "email"
values = ["user.email"]
}
}
import {
to = okta_app_saml.dynatrace
id = "0oa1b2c3d4EXAMPLE"
} For managed service providers
Built for MSPs from day one
Run every client's IdP from one pane of glass. Group tenants into client orgs and give clients scoped logins that see only their own tenants - org admins can back up and restore, org viewers are read-only, and other clients are invisible, not just hidden.
Renewal dates and billing memos live next to the tenants they belong to. Onboard an entire client book with one CSV import.
See MSP pricing
Flat pricing. No per-user math.
Your IdP bills per user. Your backup tool should not.
Community
Free forever
The full binary, one tenant. The trial that never expires.
Deploy from GitHubBusiness
$2,500/yr
+ $500 per additional tenant / year
2 tenants, unlimited users, Users & Access backup and restore. Add tenants any time.
MSP
$3,500/yr
+ $500 per additional tenant / year
Everything in Business plus client orgs, scoped logins, and renewals tracking. 2 tenants included, add more any time.
| Community | Business | MSP | |
|---|---|---|---|
| Tenants | 1 | 2 included, +$500/yr each additional | 2 included, +$500/yr each additional |
| Users | 1 admin | Unlimited | Unlimited + client org logins |
| Providers (Authentik, Okta, Auth0) | Yes | Yes | Yes |
| Config backup + drift detection | Yes | Yes | Yes |
| Scheduled automated backups | Yes | Yes | Yes |
| Snapshot diff + point-in-time restore | Yes | Yes | Yes |
| Dry-run restore preview | Yes | Yes | Yes |
| Selective restore (pick exactly what to restore) | Yes | Yes | Yes |
| Clone / promote a whole tenant (config + Users & Access) | - | Yes | Yes |
| Users & Access backup & restore | - | Yes | Yes |
| Terraform export (per object or whole snapshot) | - | Yes | Yes |
| Encrypted snapshots, no telemetry, your data never leaves | Yes | Yes | Yes |
| Client orgs + scoped roles | - | - | Yes |
| Renewal tracking (per client org) | - | - | Yes |
Licenses activate against our license server; the only thing ever sent is your
license id - never your data. Renewals and added tenants apply automatically,
no new key needed. One license runs one install at a time and moves freely
between installs. Air-gapped? Annual licenses can use an offline license file.
Existing customers: add tenants or manage your subscription here.
The per-user racket, in numbers
Hosted IdP backup services typically charge per user, per month. Your user count has nothing to do with what backup costs to run - but it has everything to do with their invoice. Example at a conservative $2 per user per month:
| Your organization | The other guys (per-user, hosted) | IdPVault Business | IdPVault MSP | You keep (Business / MSP) |
|---|---|---|---|---|
| 500 users, 2 tenants | $12,000/yr | $2,500/yr | $3,500/yr | $9,500 / $8,500 |
| 2,500 users, 3 tenants | $60,000/yr | $3,000/yr | $4,000/yr | $57,000 / $56,000 |
| 10,000 users, 4 tenants | $240,000/yr | $3,500/yr | $4,500/yr | $236,500 / $235,500 |
Users are free here.
IdPVault never counts your end users. 50 or 50,000, the price is the same flat number, and it is published right on this page.
Your data never leaves.
Hosted services hold a copy of your entire identity configuration on their cloud. IdPVault runs on your hardware, encrypts at rest, and sends nothing anywhere.
MSPs: do the math twice.
Per-user pricing across ten clients compounds fast. IdPVault MSP is a flat base plus a flat per-tenant add-on - what you charge your clients is your business, not your vendor's.