Quick answer

The SSO tax - charging extra for single sign-on, named by sso.tax, with SaaS entries back to 2018 - has reached self-hosted software: PLANKA removed OIDC from its free Community edition in v2.2.0 (August 9, 2026), and updating deactivates every SSO-based user. This tracker lists 11 self-hostable apps gating SSO behind a paid tier, six keeping it free - verified August 25, 2026.

On August 9, 2026, PLANKA shipped version 2.2.0 and removed OIDC single sign-on from its free Community edition, which meant anyone who updated a working board found every SSO-based user on it deactivated, admins included. Three days after the announcement, the thread on GitHub was closed and locked, sitting at 86 thumbs-down. That thread is why this page exists.

The practice has a name. sso.tax, whose entries go back to 2018, tracks SaaS vendors that treat single sign-on as a luxury add-on, and its fork ssotax.org carries the same torch. Both lists measure per-user cloud pricing, which is the right lens for SaaS and the wrong one for software you run yourself. Neither covers what hit self-hosters this year: an app that runs on your hardware, under an open license or close to one, where the login method is still the feature behind the paywall.

Nobody was keeping the list for self-hosted software. So I built it. I verified every row on this page against the vendor’s own pricing pages and repositories on August 25, 2026, and each row links its receipt. A row I could not verify that day did not ship.

What is the self-hosted SSO tax?

The SSO tax is the practice of charging extra for single sign-on. In SaaS it shows up as an enterprise tier priced far above the plan you wanted. In self-hosted software it shows up as an open-core split, where the code is free to run while SAML or OIDC login sits in a paid edition, behind a license key, or inside a subscription that can cost more per month than the hardware under it. Same tax, new venue.

Why it stings more at home than in the office is worth spelling out. Once you run five or six services, an identity provider such as Keycloak or Authentik is what turns them into one system. One account per person. One password policy, one place to enforce two-factor, one switch to cut a user off everywhere. An app that paywalls SSO opts out of that system unless you pay, and the price is usually set for companies, not for a family of four. That gap is the tax.

What counts, and what does not

A tracker like this earns links only if its rules are stated before its accusations. Here are mine.

Class A, retroactive removal. A feature that shipped in the free edition moves behind a paywall, and existing free users lose it on update. The community calls this a rug-pull. It is the most serious class because it converts deployed users into hostages of their own upgrade path, people who picked the app in good faith on the feature set it shipped with and now get to choose between paying up and rebuilding somewhere else. PLANKA’s OIDC removal is the 2026 example.

Class B, gated from day one. SSO was never free in the self-hosted edition. This is a defensible business model and most rows below sit in this class. It still belongs on the tracker, because you should price it in before you adopt the app, and because the free alternatives column exists.

Class C, the quote wall. No published price at all. You cannot know the tax without talking to sales. The original sso.tax maintains a separate list for these vendors, and the same pattern appears in self-hosted pricing.

Three things deliberately do not count. Paid support or hosting around a fully free feature is the fair way to fund open source, and the free-side table below names projects doing exactly that. Gating in a vendor’s hosted cloud while the self-hosted build stays free is a SaaS matter, already covered by sso.tax. And a free evaluation edition does not make a feature free. Mattermost’s “Entry” edition includes SAML, and Mattermost’s own pricing page describes it as a limited-use edition of Enterprise Advanced for technical evaluation.

One more fairness rule. Where a vendor grandfathers old versions, the row says so. PLANKA does not disable anything remotely, and older releases keep working. That matters, and a tracker that hides it is a rant.

SAML, OIDC, LDAP: not the same thing

Every row below names the exact protocol, because “SSO” without a protocol name is how wrong accusations happen.

  • SAML 2.0. The XML-based enterprise standard. Common in corporate identity systems, heavier to implement, and the single most frequently paywalled protocol on this page.
  • OIDC (OpenID Connect). The modern JSON/OAuth2-based standard. What Keycloak, Authelia, and Authentik speak natively, and what most homelab setups want.
  • LDAP / Active Directory. Not SSO at all. A directory the app checks credentials against. Users still type a password into each app, and there is no single session. Several vendors sell “LDAP sync” as a separate paid feature.
  • Social login. OAuth2 against Google, GitHub, or similar. Convenient, and not the same as bringing your own identity provider.
  • Forward-auth. A reverse proxy asks an authenticator before passing traffic. Guards the front door without the app’s cooperation. More on its limits below.

The tracker: self-hosted apps that charge for SSO

Every row verified against the linked source on 2026-08-25. Prices are the vendor’s published numbers on that date, in the currency they publish. “Moved” means the feature left a free edition on the stated date. “Gated” means it was paid from the start as far as the vendor’s current material shows, with no claim about earlier history.

AppWhat is paidCheapest tier with it (2026-08-25)ClassFree route that remainsReceipt
PLANKA (kanban)OIDC SSO, removed from Community in v2.2.0 (2026-08-09); updating deactivates SSO-only usersPro, self-hosted €36/mo (€432/yr)Moved (Aug 2026)Password login; TOTP 2FA now free; stay on ≤2.1.1 unsupported; Vikunja has free OIDCIssue #1754 · pricing
Mattermost (team chat)SAML and OpenID Connect for production use sit on paid plans (the SAML docs list “Entry” too — an evaluation-only edition, see the free-route cell)Professional and up, quote-based (“prepaid annual subscriptions”)Gated + quote wallFree “Entry” edition includes SAML but is “a limited-use edition … for technical evaluation” per the pricing page; Zulip ships SAML/OIDC freeSAML docs · pricing
Grafana (dashboards)SAML — “Available in Grafana Enterprise and Grafana Cloud”Enterprise, quote-basedGated + quote wallGeneric OAuth stays in the OSS build — its docs carry no edition banner, unlike SAML’sSAML docs · OAuth docs
Metabase (BI)SAML — “only available on Pro and Enterprise plans (both self-hosted and on Metabase Cloud)”Pro, $575/moGatedOpen-source edition, without SSOSAML docs · pricing
Teleport (infra access)SSO via OIDC, SAML, or Active Directory — Enterprise versions only, per vendor FAQEnterprise, quote-basedGated + quote wallCommunity edition (the FAQ does not enumerate its auth methods)FAQ
Passbolt (passwords)SSO (Microsoft, Google, OpenID) and LDAP provisioning at Pro; AD FS at EnterprisePro, $4.90/user/mo billed annually, 10-user minimumGatedCommunity edition, without SSO/LDAP; Vaultwarden documents free OIDCPricing
Bitwarden (passwords)“Passwordless SSO integration” at Enterprise; Teams lacks itEnterprise, $6/user/mo billed annuallyGatedVaultwarden, unofficial, free OIDCBusiness pricing
n8n (automation)“SSO, SAML and LDAP” at Business tierBusiness, €667/mo billed annuallyGatedFree self-hosted Community build, email loginPricing
Plane (project mgmt)SAML and OIDC implementations — the pricing table marks both Enterprise Grid onlyEnterprise Grid, quote-basedGated + quote wallCE self-host auth is passwords and magic links; Vikunja has free OIDCPricing · self-host docs
OpenProject (project mgmt)SSO providers (CAS, SAML, OpenID Connect, Kerberos, Okta), reserved for paid Enterprise plansEnterprise plans, from €10.95/user/mo billed annually with 25-seat minimumsGatedCommunity edition (password logins)Pricing table
Seafile (file sync)SAML 2.0 / ADFS, manual-labeled “(Pro)”Pro edition (per-user pricing not published on checked pages)GatedCE keeps OAuth, Shibboleth, and remote-user; Nextcloud has an official free SSO appManual · SSO overview

Two notes on reading it. The seat minimums matter more than the per-user price, because SSO on Passbolt starts at 10 paid seats — $49 a month at its listed rate even if only three people ever log in — and OpenProject’s plans carry 25-seat minimums on top of the per-user number. And a quote wall is itself data. Five of eleven rows publish no number at all.

The table is honest about what it does not know. Portainer folklore says Business Edition gates OAuth, and Portainer’s current documentation shows OAuth providers with no edition restriction, so there is no Portainer row. The same discipline removed a Rocket.Chat row from a draft of this page: their plan matrix lists basic SAML, LDAP, and custom OAuth in Community, so what they charge for is advanced identity sync, not SSO itself — that story sits in the retreats section below. Absence from this table is not an endorsement. It means I could not verify an SSO paywall from the primary source on build day.

What happened with Planka SSO

The case that made this page worth building deserves the neutral version.

On August 7, 2026, the PLANKA team posted issue #1754, announcing that OIDC/SSO would leave the Community edition with the next release. Their words were direct. “SSO was always meant to be a Pro/enterprise feature on our side.” They also cited support load, over 100 SSO setup requests a month by their count. Version 2.2.0 shipped on August 9. The thread was closed and locked on August 10, at 86 thumbs-down out of 96 reactions.

The mechanics are the sharp edge. Updating to 2.2.0 deactivates every SSO-based user, because those accounts have no password. An admin has to set passwords and reactivate them one by one. If the admin account itself was SSO-based, that person is locked out unless they create a new admin through the documented script first. The team’s own warning says to plan the migration before updating.

The fair-side ledger, stated plainly. Nothing is disabled remotely, and 2.1.1 keeps working for as long as you accept running without updates. The same release moved TOTP two-factor along with auto-logout and trusted devices from Pro into Community, so account security in the free tier went up while identity federation went out. Pro costs €36 a month self-hosted, which is priced for teams, and their stated line is that account security stays free while enterprise identity is paid.

If you run PLANKA with SSO today, the realistic options are four. Pay for Pro. Convert users to password logins plus the newly free TOTP. Freeze on 2.1.1 and accept the security trade of no updates. Or migrate boards to Vikunja, which speaks OIDC free. I have not tested a PLANKA-to-Vikunja migration, so check Vikunja’s importers against your data before committing to that path.

Self-hosted apps where SSO stays free

The counterexamples are the strongest argument that free SSO is viable. Same verification date, same receipt discipline.

AppFree identity support (verified 2026-08-25)Receipt
Zulip (team chat)Email, LDAP/AD, SAML, OIDC, social (Google, GitHub, GitLab, Discord, Apple), JWT — no plan restrictions in the auth docsAuth methods
BookStack (wiki)OIDC “as a primary method of authentication,” SAML 2.0 and LDAP alongsideOIDC docs
Paperless-ngx (documents)OIDC and social auth via django-allauth since v2.5.0, plus remote-userAdvanced usage
Vikunja (kanban/tasks)OIDC against “Authentik, Keycloak or similar”OpenID docs
Vaultwarden (passwords)OIDC SSO with per-provider guides; a master password is still requiredWiki
Nextcloud (files+)Official “SSO & SAML” app maintained by Nextcloud GmbH, installable from the app storeApp store

Zulip is the row I would show a vendor. A team chat server competing in the same category as Mattermost above ships SAML and OIDC free in every self-hosted deployment, LDAP too. It can be done.

We run several of these ourselves. Our Paperless-ngx setup guide and Nextcloud AIO walkthrough cover two of the six, and the self-hosted starter list puts them in context.

Your escape hatches

Run your own identity provider. Keycloak speaks OIDC free, and so do Authelia and Authentik. Our Authelia vs Authentik comparison picks between the two for a homelab, with the Authentik setup tutorial as the follow-through. Every app in the free-side table plugs into any of them.

Forward-auth for the rest, with honesty about its limits. Authelia or Authentik in front of your reverse proxy will challenge visitors before any backend sees traffic. For a single-user homelab that is often all the SSO you need. What it cannot do is put per-user identity inside an app whose native SSO is paywalled. The app still sees its own local accounts. One login at the door, separate accounts behind it. That is the honest limit, and any guide promising otherwise is selling something.

Pick apps by the auth column before you deploy. The cheapest time to avoid the SSO tax is before your data lives in the app. That is the real use of this tracker, and it pairs with our break-even calculator when the alternative is paying for the hosted product instead.

Three events, 2021 through 2026, belong in the same memory even though none is an SSO paywall. Different classes, labeled as such.

ProjectWhat happenedClassReceipt
Rocket.Chat (team chat)Advanced identity sync (role mapping, extended attribute sync, background sync) moved to paid plans in a late-September 2021 release; the announcement kept “all the basic functionalities of LDAP, SAML, Social Logins and Custom OAuth” in Community, and the current plan matrix still lists them thereAdvanced-tier migration2021 announcement · plan matrix
MinIO (object storage)Admin features stripped from the community web console between the 2025-04-22 and 2025-05-24 releases; management moved to the mc CLI or the paid AIStor productFeature removalDiscussion #21316 · Blocks & Files
Cal.com (scheduling)Announced on April 14, 2026 that the production codebase was going closed source, citing AI-assisted vulnerability discovery; a version of the codebase released to the community as Cal.diy under MITLicense retreatCal.com blog

Four dated incidents on this page span 2021 through 2026. The common thread is that the sharp edge sits in the migration path, wherever the announcement lands. Watch changelogs, and treat identity features as the canary.

The maintainer’s side

This page is not an argument that maintainers owe anyone free SSO, because building and then supporting SAML against every corporate identity provider that ever shipped a quirky metadata file is genuinely expensive work that someone has to fund. PLANKA’s hundred-requests-a-month figure is their own number, and I believe the shape of it. Enterprise identity is the classic open-core line because the buyers are enterprises, and a project that funds development by charging them is behaving better than one that quietly abandons its free edition.

Paying is sometimes the right call. If a team of 30 depends on OpenProject with Okta, €10.95 per user per month is a rounding error against migration cost. What this tracker exists to catch is narrower — removals from deployed free editions and upgrade paths that deactivate users, plus security features priced behind quote walls. Those are choices, and the first table records who made them.

How this page is maintained

Each row carries the date it was verified and a link to the source that backs it. When an app changes its tiers, the row gets re-verified against that same source and the update log at the bottom of this page records the change. New incidents get a dated row when a primary source exists, and the lastmod stamp above reflects the latest pass.

Corrections are welcome, including from maintainers. If a row misstates your pricing or your history, use the contact route on our about page and it will be checked against your source and fixed. The table data is available under CC BY 4.0, the same license as our measured datasets. Cite the page, take the table.

Frequently asked questions

What is the SSO tax?
The SSO tax is the software industry practice of charging a premium for single sign-on, usually by locking SAML or OIDC login behind an enterprise tier. The term comes from sso.tax, the SaaS Wall of Shame whose vendor entries go back to 2018. This page tracks the same practice in self-hostable software, where the code runs on your hardware and the login method is still the feature you pay for.
Why do open-source apps charge for SSO?
Because SSO buyers are usually businesses, and identity features carry a real support burden. PLANKA’s maintainers said SSO generated over 100 setup requests a month when they moved it to their paid Pro tier in August 2026. Charging companies for enterprise identity is a defensible way to fund free software. The line this tracker draws is between gating a feature from day one and removing one that users already deployed.
Is Planka still free?
The Community edition remains free for password login, and version 2.2.0 moved TOTP two-factor authentication, auto-logout, and trusted devices into the free tier. OIDC single sign-on is no longer free. From v2.2.0 (August 9, 2026) it requires PLANKA Pro, which starts at 36 euros per month self-hosted. Older releases keep working and nothing is disabled remotely.
What happened with Planka SSO?
On August 7, 2026 the PLANKA team announced in GitHub issue #1754 that OIDC/SSO would leave the Community edition. Version 2.2.0 shipped the change on August 9. Updating deactivates all SSO-based users because they have no password login, and an SSO-based admin gets locked out unless a new admin is created first. The announcement thread was closed and locked within three days with 86 thumbs-down reactions.
What are free alternatives to apps that charge for SSO?
Verified on August 25, 2026: Vikunja offers free OIDC and covers the same kanban ground as PLANKA and Plane. Zulip ships SAML, OIDC, and LDAP free in self-hosted deployments, unlike Mattermost, whose production SAML sits on paid plans. Vaultwarden documents free OIDC where Bitwarden charges $6 per user per month, with the caveat that a master password is still required. Nextcloud publishes an official free SSO and SAML app, where Seafile gates SAML behind its Pro edition.
Can a reverse proxy like Authelia replace paid SSO?
Partially. Forward-auth through Authelia or Authentik protects the front door of any app behind your proxy, which is often enough for a single-user homelab. It cannot inject per-user identity, roles, or provisioning into an app whose native SAML or OIDC support sits behind a paywall. You get one login at the door, while in-app accounts stay separate.

Evidence ledger

Last updated
Methodology
This guide was written and edited by Lowell K. Wood IV in St. Louis County, MO. It draws on 32 cited sources, listed below, each checked against the original page on the date above. Full editorial standard: methodology. Tracker rows state only what the linked primary source said on the verification date. Rows that could not be verified against a primary source that day were dropped rather than published.
Sources
Update log
  • 2026-08-25 — First publication. All 11 paid-tier rows, 6 free-side rows, and 3 retreat entries verified against vendor pricing pages, docs, or repositories on 2026-08-25, then re-checked by an independent cold fact-check pass before publish; two draft rows (Portainer, Rocket.Chat) were removed when vendor docs contradicted the accusation. Full receipt log kept in the site’s ops tree; corrections route below.
Corrections
Spotted an error or a stale number? Email hello@techfuelhq.com. Confirmed corrections are added to the update log above.

About the author

Written by Lowell K. Wood IV, who builds and runs TechFuelHQ from St. Louis, Missouri.