European Sovereign Identity

The EU sovereign alternative to WorkOS and Keycloak.

Fully hosted in the EU. Zero US CLOUD Act exposure. Managed, and live in 5 days.

Enterprise SSOEnabled
Directory Sync (SCIM)Enabled
Admin PortalEnabled
Audit LogsEnabled
RBACEnabled
Cross-org federationEnabled
Hosted in the EUEnabled
Zero US CLOUD Act exposureEnabled

Built by the team that shipped SSO at bol.com

10M+ users in the Netherlands and Belgium

Hosted in the EU GDPR / DSAR-ready NIS2 aligned eIDAS 2.0 Live in 5 days
Building blocks

Everything you need to be enterprise ready.

The same core modules as WorkOS, on open standards, hosted entirely in the EU.

Authentication

Enterprise SSO

One login across every app, over OIDC and SAML.

Learn more
Provisioning

Directory Sync

Users provisioned and removed automatically via SCIM.

Learn more
Self-serve

Admin Portal

Your customer's IT team configures their own SSO.

Learn more
Users

User Management

One source of truth for every user and identity.

Learn more
Governance

Audit Logs

Every access event, logged and exportable.

Learn more
Authorization

RBAC

Role and attribute-based access, down to the resource.

Learn more
Interface

Auth UI

A ready-made, branded login and sign-up flow.

Learn more
Security

Bot protection

Keep automated abuse out of your sign-up and login.

Learn more
Agents

Agent identity

Scoped, auditable identity for AI agents and services.

Learn more
Federation · Thoryn strength

Cross-org Federation

Connect identities across organizations without a shared directory. The layer WorkOS, Ory, and Okta do not have.

Learn more
Compliance

GDPR & DSAR-ready

Handle access, export, and deletion requests natively. Built for European compliance from day one, not with scripts or manual workarounds.

Learn more
Developer experience

Built for developers. Live in five days.

From first call to production in five working days, not a quarter.

A few lines to production identity.

Standard protocols and a clean SDK. Drop SSO, directory sync, and authorization into your app in an afternoon, not a rebuild.

Works over OIDC, SAML, and SCIM.

auth.ts
import { Thoryn } from "@thoryn/sdk";

const thoryn = new Thoryn({ region: "eu-central" });

// Send a user into SSO
app.get("/login", (req, res) => {
  const url = thoryn.sso.authorizationUrl({
    connection: "acme-oidc",
    redirectUri: "https://app.example.eu/callback",
  });
  res.redirect(url);
});

// Exchange the code for a verified profile
app.get("/callback", async (req, res) => {
  const { user } = await thoryn.sso.exchange(req.query.code);
  req.session.user = user; // stored in the EU, always
  res.redirect("/dashboard");
});
Day 1 · Kickoff

Map the stack

We review your apps, identity providers, and requirements.

Day 2 · Connect

Wire up SSO

Single sign-on and directory sync connected to your apps.

Day 3 · Configure

Roles and audit

Policies, fine-grained access, and audit logging in place.

Day 5 · Live

In production

Running on EU infrastructure, ready for your users.

Admin Portal

Enterprise onboarding, self-serve.

Your customers' IT teams configure their own SSO and directory sync in a branded admin portal. Fewer support tickets for you, faster enterprise deals for them.

Self-serve SSO and SCIM setup
Guided SAML and OIDC configuration
Test and verify before going live
Fully branded to your customer
Acme CorpConnected
Identity providerOkta
SAML metadataUploaded
Directory sync (SCIM)Active
Test connectionPassed
Why Thoryn

Everything WorkOS does. None of the US exposure.

01

Sovereign by default

Hosted in Germany. No data leaves the EU. Zero US CLOUD Act exposure.

02

Open standards

OIDC, SAML, and SCIM. No lock-in, works with your stack.

03

Cross-org federation

Connect identities across organizations. Our strongest edge.

04

GDPR and DSAR-ready

Data subject access, export, and deletion are built into the product, not handled with scripts or manual workarounds.

GDPR-nativeNIS2 alignedDORA alignedeIDAS 2.0EU data residency
How Thoryn compares

Sovereign, managed, and fast. In one platform.

Strong Good Limited Weak or absent
Thoryn MicrosoftEntra ID Keycloak WorkOS Ory
European data sovereignty
Managed SaaS, no self-hosting
Onboarding speed
SSO, SAML and OIDC
SCIM directory sync
Fine-grained authorization
Cross-organization federation
NIS2 and DORA alignment
GDPR and DSAR-ready
Open standards, low lock-in

Based on publicly available product information and default managed offerings. Ratings reflect typical EU deployments.

Use cases

Built for how organizations actually work.

Retail

Secure SSO for large-scale retail.

We previously designed and built custom SSO solutions while working at bol.com. That technology has been rebuilt and significantly improved inside Thoryn, now fully EU-sovereign, managed, and live in days.

Enterprise-grade SSO over OIDC and SAML.
Built for complex retail and partner ecosystems.
Fully hosted in the EU, with zero US CLOUD Act exposure.
Live in days instead of months.
Shoppers
Customer accounts
one login
Thoryn SSO
Partners and brands
External
federated
Store staff
Employees
SSO
See the use case
Built environment

Secure file sharing across a project chain.

A single renovation programme runs across municipalities, contractors, engineers, and suppliers. Thoryn gives each partner scoped access to the right files, and nothing else.

No shared login and no central directory anyone has to own.
Access follows the credential. When the project ends, access ends.
Every action logged, ready for audit and procurement review.
Municipality
Project owner
grants access
Thoryn
Contractor
Verified partner
scoped
Supplier
Time-boxed
expires
See the use case
Pricing

Simple, sovereign, transparent.

Startup
Custom
EU-sovereign identity for early-stage companies.
  • SSO over OIDC and SAML
  • SCIM directory sync
  • Hosted in the EU
  • Designed for startups
Get startup pricing
Starter
€15k / year
SSO and directory sync for a single organization.
  • SSO over OIDC and SAML
  • SCIM directory sync
  • Hosted in the EU
  • Email support
Get started
Most chosen
Growth
€32k / year
Full authentication and fine-grained authorization.
  • Everything in Starter
  • MFA and passkeys
  • Fine-grained authorization
  • Audit logs and exports
  • Onboarding in five days
Book a demo
Enterprise
€60k / year
Cross-org federation and enterprise support.
  • Everything in Growth
  • Cross-organization federation
  • Dedicated support and SLAs
  • Private or on-prem deployment
Talk to us

All plans hosted in the EU. Priced per year, billed annually.

Make your app EU-sovereign ready.

See how Thoryn fits your stack in a 30-minute demo.